<?xml version="1.0" encoding="UTF-8"?>
<oval xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval#redhat redhat-schema.xsd http://oval.mitre.org/XMLSchema/oval#windows windows-schema.xsd http://oval.mitre.org/XMLSchema/oval#hpux hpux-schema.xsd http://oval.mitre.org/XMLSchema/oval#unix unix-schema.xsd http://oval.mitre.org/XMLSchema/oval#independent independent-schema.xsd http://oval.mitre.org/XMLSchema/oval#solaris solaris-schema.xsd http://oval.mitre.org/XMLSchema/oval oval-schema.xsd" xmlns:oval="http://oval.mitre.org/XMLSchema/oval" xmlns="http://oval.mitre.org/XMLSchema/oval" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:redhat="http://oval.mitre.org/XMLSchema/oval#redhat" xmlns:windows="http://oval.mitre.org/XMLSchema/oval#windows" xmlns:solaris="http://oval.mitre.org/XMLSchema/oval#solaris" xmlns:hpux="http://oval.mitre.org/XMLSchema/oval#hpux">
  <generator>
    <schema_version>4.2</schema_version>
    <timestamp>20060503224300</timestamp>
  </generator>
  <definitions>
    <definition id="OVAL2" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Mutt</product>
      </affected>
      <dates>
        <submitted date="2003-08-18-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in Mutt 1.4.0 and possibly earlier versions, 1.5.x up to 1.5.3, and other programs that use Mutt code such as Balsa before 2.0.10, allows a remote malicious IMAP server to cause a denial of service (crash) and possibly execute arbitrary code via a crafted folder.</description>
      <reference source="CVE">CVE-2003-0140</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-201" comment="balsa version is less than 2.0.6-2" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-201" comment="/usr/bin/balsa is executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL3" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Exchange Server 2003</product>
      </affected>
      <dates>
        <submitted date="2005-06-06-12:00">
          <contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
        </submitted>
        <status_change date="2005-06-08-03:24">DRAFT</status_change>
        <status_change date="2005-06-29-06:49">INTERIM</status_change>
        <status_change date="2005-07-27-10:37">ACCEPTED</status_change>
      </dates>
      <description>'The Exchange 2003 Exadmin virtual directory uses only Integrated Windows Authentication.'</description>
      <reference source="MISC">2.1.6</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <notes>
        <note>Corresponds to item 2.1.6 in the Exchange 2003 Benchmark</note>
      </notes>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wat-1" comment="The exadmin HTTP virtual directory only allows Integrated Windows Authentication" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL6" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>CUPS</product>
      </affected>
      <dates>
        <submitted date="2003-08-19-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>CUPS before 1.1.19 allows remote attackers to cause a denial of service via a partial printing request to the IPP port (631), which does not time out.</description>
      <reference source="CVE">CVE-2003-0195</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-202" comment="cups version is less than 1.1.17-13.3" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="rlt-201" comment="cupsd listens on the network" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL7" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>kcms_configure</product>
      </affected>
      <dates>
        <submitted date="2002-09-17-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>kcms_configure as included with Solaris 7 and 8 allows a local attacker to gain additional privileges via a buffer overflow in a command line argument.</description>
      <reference source="CVE">CVE-2001-0594</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="uft-5" comment="File kcms_configure exists" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-202" comment="File kcms_configure executable and SUID or SGID" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL9" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>libnsl</product>
      </affected>
      <dates>
        <submitted date="2003-01-28-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC including dietlibc, allows remote attackers to execute arbitrary code by passing a large number of arguments to xdr_array through RPC services such as rpc.cmsd and dmispd.</description>
      <reference source="CVE">CVE-2002-0391</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="cmp-204" comment="rpc.cmsd or dmispd exist" negate="false"/>
          <criterion test_ref="cmp-205" comment="Patches 108827-30 and 108901-06" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-206" comment="rpc.cmsd enabled OR dmispd running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL10" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>xlock</product>
      </affected>
      <dates>
        <submitted date="2002-09-17-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Heap overflow in xlock in Solaris 2.6 through 8 allows local users to gain root privileges via a long (1) XFILESEARCHPATH or (2) XUSERFILESEARCHPATH environmental variable.</description>
      <reference source="CVE">CVE-2001-0652</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="uft-8" comment="File xlock exists" negate="false"/>
          <criterion test_ref="spt-203" comment="Patch 108652-38 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-209" comment="File xlock SUID and executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL11" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>snmpdx</product>
      </affected>
      <dates>
        <submitted date="2002-09-25-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Format string vulnerability in the logging component of snmpdx for Solaris 5.6 through 8 allows remote attackers to gain root privileges.</description>
      <reference source="CVE">CVE-2002-0796</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="uft-9" comment="File snmpdx exists" negate="false"/>
          <criterion test_ref="spt-204" comment="Patch 108869-16 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-6" comment="snmpdx running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL12" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Internet Explorer 5.5 Service Pack 2</product>
      </affected>
      <dates>
        <submitted date="2003-11-12-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Internet Explorer 5.5 and 6.0 allows remote attackers to bypass restrictions for executing scripts via an object that processes asynchronous events after the initial security checks have been made.</description>
      <reference source="CVE">CVE-2002-0026</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-53" comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false"/>
          <criterion test_ref="wft-201" comment="the version of mshtml.dll is less than 5.50.4913.1100" negate="false"/>
          <criterion test_ref="wrt-202" comment="the patch q316059 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-203" comment="the patch q319282 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-204" comment="the patch q321232 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-205" comment="the patch q323759 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-206" comment="the patch q328970 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-207" comment="the patch q324929 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-208" comment="the patch q810847 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-209" comment="the patch q813489 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-210" comment="the patch q818529 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-211" comment="the patch q822925 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-212" comment="the patch q828750 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-19" comment="the patch q824145 is installed (Installed Components key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL14" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>Xsun</product>
      </affected>
      <dates>
        <submitted date="2002-08-23-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in Xsun on Solaris 2.6 through 8 allows local users to gain root privileges via a long -co (color database) command line argument.</description>
      <reference source="CVE">CVE-2002-0158</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="uft-10" comment="File Xsun exists" negate="false"/>
          <criterion test_ref="spt-205" comment="Patch 108652-52 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-210" comment="File Xsun SGID and executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL15" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>CDE</product>
      </affected>
      <dates>
        <submitted date="2003-01-31-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>CDE ToolTalk database server (ttdbserver) allows remote attackers to overwrite arbitrary memory locations with a zero, and possibly gain privileges, via a file descriptor argument in an AUTH_UNIX procedure call, which is used as a table index by the _TT_ISCLOSE procedure.</description>
      <reference source="CVE">CVE-2002-0677</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="uft-11" comment="File rpc.ttdbserverd exists" negate="false"/>
          <criterion test_ref="spt-206" comment="Patch 110286-09 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-202" comment="inetd.conf contains rpc.ttdbserverd" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
          <criterion test_ref="cmp-211" comment="File rpc.ttdbserverd executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL16" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>Internet Information Server 4.0</product>
      </affected>
      <dates>
        <submitted date="2004-01-14-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <status_change date="2004-03-09-12:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the chunked encoding transfer mechanism in Internet Information Server (IIS) 4.0 and 5.0 Active Server Pages allows attackers to cause a denial of service or execute arbitrary code.</description>
      <reference source="CVE">CVE-2002-0079</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-214" comment="IIS 4.0 Major Version" negate="false"/>
          <criterion test_ref="wrt-215" comment="IIS minor version equals 0" negate="false"/>
          <criterion test_ref="wrt-43" comment="this is an NT Terminal Server" negate="true"/>
          <criterion test_ref="wft-202" comment="the version of w3svc.dll is less than 4.2.775.1" negate="false"/>
          <criterion test_ref="wrt-217" comment="Patch Q319733 Installed" negate="true"/>
          <criterion test_ref="wrt-218" comment="Patch Q327696 Installed" negate="true"/>
          <criterion test_ref="wrt-219" comment="Patch Q811114 Installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wmt-201" comment="asp.dll mapping exists" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL17" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Internet Explorer 6.0</product>
      </affected>
      <dates>
        <submitted date="2003-11-12-05:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
        <modified date="2005-09-20-04:00" comment="changed IE test to wrt-18">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-21-01:27">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to read arbitrary files via malformed requests to the GetObject function, which bypass some of GetObject's security checks.</description>
      <reference source="CVE">CVE-2002-0023</reference>
      <status>ACCEPTED</status>
      <version>4</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wft-203" comment="the version of mshtml.dll is less than 6.0.2713.1100" negate="false"/>
          <criterion test_ref="wrt-202" comment="the patch q316059 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-203" comment="the patch q319282 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-204" comment="the patch q321232 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-205" comment="the patch q323759 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-206" comment="the patch q328970 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-207" comment="the patch q324929 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-208" comment="the patch q810847 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-209" comment="the patch q813489 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-210" comment="the patch q818529 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-211" comment="the patch q822925 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-212" comment="the patch q828750 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-19" comment="the patch q824145 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-18" comment="Internet Explorer 6 is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL18" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>Windows Shell</product>
      </affected>
      <dates>
        <submitted date="2004-09-15-12:00">
          <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
        </submitted>
        <modified date="2004-09-16-12:00" comment="Completing an initial submission.">
          <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
        </modified>
        <status_change date="2004-09-29-02:40">DRAFT</status_change>
        <status_change date="2004-10-13-12:00">INTERIM</status_change>
        <modified date="2004-10-19-04:29" comment="done">
          <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
        </modified>
        <status_change date="2004-10-27-12:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in Windows Shell (used as the Windows Desktop) allows local and possibly remote attackers to execute arbitrary code via a custom URL handler that has not been removed for an application that has been improperly uninstalled.</description>
      <reference source="CVE">CVE-2002-0070</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" negate="false"/>
          <criterion test_ref="wft-490" comment="the version of shell32.dll is less than 4.0.1381.7116" negate="false"/>
          <criterion test_ref="wrt-288" comment="Patch Q313829 Installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL19" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Internet Explorer 6.0</product>
      </affected>
      <dates>
        <submitted date="2004-01-27-05:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <modified date="2005-09-20-04:00" comment="Changed IE registry test to wrt-18">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-21-01:27">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Cross-site scripting vulnerability in Internet Explorer 6.0 allows remote attackers to execute scripts in the Local Computer zone via a URL that exploits a local HTML resource file, aka the "Cross-Site Scripting in Local HTML Resource" vulnerability.</description>
      <reference source="CVE">CVE-2002-0189</reference>
      <status>ACCEPTED</status>
      <version>4</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wft-204" comment="the version of mshtml.dll is less than 6.0.2716.2200" negate="false"/>
          <criterion test_ref="wrt-204" comment="the patch q321232 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-205" comment="the patch q323759 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-206" comment="the patch q328970 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-207" comment="the patch q324929 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-208" comment="the patch q810847 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-209" comment="the patch q813489 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-210" comment="the patch q818529 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-211" comment="the patch q822925 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-212" comment="the patch q828750 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-19" comment="the patch q824145 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="cmp-212" comment="Windows 2000 Service Pack 4 (or later) is installed" negate="true"/>
          <criterion test_ref="wrt-18" comment="Internet Explorer 6 is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL20" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Distributed Component Object Model (DCOM) interface</product>
      </affected>
      <dates>
        <submitted date="2004-11-02-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2004-11-03-12:00">DRAFT</status_change>
        <status_change date="2004-12-09-12:00">INTERIM</status_change>
        <status_change date="2005-01-06-12:00">ACCEPTED</status_change>
        <modified date="2005-06-02-12:00" comment="Added product">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-06-08-03:17">INTERIM</status_change>
        <status_change date="2005-06-29-06:49">ACCEPTED</status_change>
      </dates>
      <description>Heap-based buffer overflow in the Distributed Component Object Model (DCOM) interface in the RPCSS Service allows remote attackers to execute arbitrary code via a malformed DCERPC DCOM object activation request packet with modified length fields, a different vulnerability than CVE-2003-0352 (Blaster/Nachi) and CVE-2003-0528.</description>
      <reference source="CVE">CVE-2003-0715</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
          <criterion test_ref="wft-568" comment="the version of rpcss.dll is less than 5.0.2195.6810" negate="false"/>
          <criterion test_ref="wrt-281" comment="the patch kb824146 is installed (Hotfix key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL22" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Internet Information Server 5.0</product>
      </affected>
      <dates>
        <submitted date="2004-01-14-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <status_change date="2004-03-09-12:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the ASP data transfer mechanism in Internet Information Server (IIS) 4.0, 5.0, and 5.1 allows remote attackers to cause a denial of service or execute code, aka "Microsoft-discovered variant of Chunked Encoding buffer overrun."</description>
      <reference source="CVE">CVE-2002-0147</reference>
      <status>ACCEPTED</status>
      <version>4</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-223" comment="IIS major version equals 5" negate="false"/>
          <criterion test_ref="wrt-215" comment="IIS minor version equals 0" negate="false"/>
          <criterion test_ref="wft-205" comment="the version of w3svc.dll is less than 5.0.2195.5269" negate="false"/>
          <criterion test_ref="wrt-217" comment="Patch Q319733 Installed" negate="true"/>
          <criterion test_ref="wrt-218" comment="Patch Q327696 Installed" negate="true"/>
          <criterion test_ref="wrt-219" comment="Patch Q811114 Installed" negate="true"/>
          <criterion test_ref="wrt-224" comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wmt-201" comment="asp.dll mapping exists" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL23" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Internet Explorer 5.5 or Internet Explorer 5.5 Service Pack 1</product>
      </affected>
      <dates>
        <submitted date="2003-11-12-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Internet Explorer 5.5 and 6.0 allows remote attackers to bypass restrictions for executing scripts via an object that processes asynchronous events after the initial security checks have been made.</description>
      <reference source="CVE">CVE-2002-0026</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-213" comment="Internet Explorer 5.5 Installed" negate="false"/>
          <criterion test_ref="wft-206" comment="the version of mshtml.dll is less than 5.50.4725.2100" negate="false"/>
          <criterion test_ref="wrt-202" comment="the patch q316059 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-203" comment="the patch q319282 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-204" comment="the patch q321232 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-205" comment="the patch q323759 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-212" comment="the patch q828750 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-19" comment="the patch q824145 is installed (Installed Components key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL24" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>FTP</product>
      </affected>
      <dates>
        <submitted date="2003-10-10-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
      </dates>
      <description>The FTP service in Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows attackers who have established an FTP session to cause a denial of service via a specially crafted status request containing glob characters.</description>
      <reference source="CVE">CVE-2002-0073</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-214" comment="IIS 4.0 Major Version" negate="false"/>
          <criterion test_ref="wrt-215" comment="IIS minor version equals 0" negate="false"/>
          <criterion test_ref="wft-202" comment="the version of w3svc.dll is less than 4.2.775.1" negate="false"/>
          <criterion test_ref="wrt-217" comment="Patch Q319733 Installed" negate="true"/>
          <criterion test_ref="wrt-218" comment="Patch Q327696 Installed" negate="true"/>
          <criterion test_ref="wrt-219" comment="Patch Q811114 Installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wmt-202" comment="FTP Enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL25" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Internet Information Server 5.0</product>
      </affected>
      <dates>
        <submitted date="2004-01-14-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <status_change date="2004-03-09-12:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the chunked encoding transfer mechanism in Internet Information Server (IIS) 4.0 and 5.0 Active Server Pages allows attackers to cause a denial of service or execute arbitrary code.</description>
      <reference source="CVE">CVE-2002-0079</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-223" comment="IIS major version equals 5" negate="false"/>
          <criterion test_ref="wrt-215" comment="IIS minor version equals 0" negate="false"/>
          <criterion test_ref="wft-205" comment="the version of w3svc.dll is less than 5.0.2195.5269" negate="false"/>
          <criterion test_ref="wrt-217" comment="Patch Q319733 Installed" negate="true"/>
          <criterion test_ref="wrt-218" comment="Patch Q327696 Installed" negate="true"/>
          <criterion test_ref="wrt-219" comment="Patch Q811114 Installed" negate="true"/>
          <criterion test_ref="wrt-224" comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wmt-201" comment="asp.dll mapping exists" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL26" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Network Connection Manager (NCM)</product>
      </affected>
      <dates>
        <submitted date="2003-10-10-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <modified date="2005-03-07-12:00" comment="modified wrt-222 - changed pattern match">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-03-09-07:55">INTERIM</status_change>
        <status_change date="2005-03-29-07:59">ACCEPTED</status_change>
      </dates>
      <description>A handler routine for the Network Connection Manager (NCM) in Windows 2000 allows local users to gain privileges via a complex attack that causes the handler to run in the LocalSystem context with user-specified code.</description>
      <reference source="CVE">CVE-2002-0720</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
          <criterion test_ref="wrt-222" comment="SP4 or later Installed" negate="true"/>
          <criterion test_ref="wft-207" comment="the version of netman.dll is less than 5.0.2195.5974" negate="false"/>
          <criterion test_ref="wrt-229" comment="Patch Q326886 Installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL27" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Internet Explorer 5.01</product>
      </affected>
      <dates>
        <submitted date="2004-01-27-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <modified date="2005-03-07-12:00" comment="modified wrt-222 - changed pattern match">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-03-09-07:55">INTERIM</status_change>
        <status_change date="2005-03-29-07:59">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Internet Explorer 5.01 and 6.0 allow remote attackers to execute arbitrary code via malformed Content-Disposition and Content-Type header fields that cause the application for the spoofed file type to pass the file back to the operating system for handling rather than raise an error message, aka the first variant of the "Content Disposition" vulnerability.</description>
      <reference source="CVE">CVE-2002-0193</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-214" comment="Internet Explorer 5.01 Installed" negate="false"/>
          <criterion test_ref="wft-208" comment="the version of mshtml.dll is less than 5.0.3504.2500" negate="false"/>
          <criterion test_ref="wrt-204" comment="the patch q321232 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-205" comment="the patch q323759 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-19" comment="the patch q824145 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="cmp-215" comment="Windows 2000 Service Pack 4 (or later) is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL28" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>skk</product>
      </affected>
      <dates>
        <submitted date="2003-09-04-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>skk (Simple Kana to Kanji conversion program) 12.1 and earlier, and the ddskk package which is based on skk, creates temporary files insecurely, which allows local users to overwrite arbitrary files.</description>
      <reference source="CVE">CVE-2003-0539</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="cmp-216" comment="Vulnerable config" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL29" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Internet Information Server 5.0</product>
      </affected>
      <dates>
        <submitted date="2004-01-14-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <status_change date="2004-03-09-12:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the chunked encoding transfer mechanism in IIS 4.0 and 5.0 allows attackers to execute arbitrary code via the processing of HTR request sessions, aka "Heap Overrun in HTR Chunked Encoding Could Enable Web Server Compromise."</description>
      <reference source="CVE">CVE-2002-0364</reference>
      <status>ACCEPTED</status>
      <version>4</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-223" comment="IIS major version equals 5" negate="false"/>
          <criterion test_ref="wrt-215" comment="IIS minor version equals 0" negate="false"/>
          <criterion test_ref="wft-209" comment="File %windir%\system32\inetsrv\ism.dll version is less than 5.0.2195.5671" negate="false"/>
          <criterion test_ref="wrt-238" comment="Patch Q321599 Installed" negate="true"/>
          <criterion test_ref="wrt-218" comment="Patch Q327696 Installed" negate="true"/>
          <criterion test_ref="wrt-219" comment="Patch Q811114 Installed" negate="true"/>
          <criterion test_ref="wrt-224" comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wmt-203" comment="ism.dll mapping exists" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL30" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>SMTP</product>
      </affected>
      <dates>
        <submitted date="2003-05-20-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <modified date="2004-03-30-12:00" comment="Changed the registry key in question for the SMTP enabled check to SMTPSVC from SMTP.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
      </dates>
      <description>SMTP service in Microsoft Windows 2000, Windows XP Professional, and Exchange 2000 to cause a denial of service via a command with a malformed data transfer (BDAT) request.</description>
      <reference source="CVE">CVE-2002-0055</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
          <criterion test_ref="wft-210" comment="File %windir%\system32\inetsrv\smtpsvc.dll version is less than 5.0.2195.4905" negate="false"/>
          <criterion test_ref="wrt-239" comment="Patch Q313450" negate="true"/>
          <criterion test_ref="wrt-224" comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-240" comment="SMTP Enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL31" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>cachefsd</product>
      </affected>
      <dates>
        <submitted date="2003-01-31-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
        <modified date="2005-01-28-12:00" comment="Updated to include Solaris 9 and Solaris 9 patch info">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </modified>
        <status_change date="2005-02-01-08:24">INTERIM</status_change>
        <status_change date="2005-02-16-12:00">ACCEPTED</status_change>
      </dates>
      <description>Heap-based buffer overflow in cfsd_calloc function of Solaris cachefsd allows remote attackers to execute arbitrary code via a request with a long directory and cache name.</description>
      <reference source="CVE">CVE-2002-0033</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uft-12" comment="File cachefsd exists" negate="false"/>
          <criterion test_ref="spt-207" comment="Patch 110896-02 or later installed" negate="true"/>
          <criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" negate="false"/>
          <criterion test_ref="spt-111" comment="Patch 114008-01 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-203" comment="inetd.conf contains cachefsd" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
          <criterion test_ref="cmp-217" comment="File cachefsd executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL32" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Internet Explorer 6.0</product>
      </affected>
      <dates>
        <submitted date="2003-11-12-05:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
        <modified date="2005-09-20-04:00" comment="Changed IE registry test to wrt-18">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-21-01:27">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 5.5 and 6.0 allows remote attackers to bypass restrictions for executing scripts via an object that processes asynchronous events after the initial security checks have been made.</description>
      <reference source="CVE">CVE-2002-0026</reference>
      <status>ACCEPTED</status>
      <version>4</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wft-203" comment="the version of mshtml.dll is less than 6.0.2713.1100" negate="false"/>
          <criterion test_ref="wrt-202" comment="the patch q316059 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-203" comment="the patch q319282 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-204" comment="the patch q321232 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-205" comment="the patch q323759 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-206" comment="the patch q328970 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-207" comment="the patch q324929 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-208" comment="the patch q810847 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-209" comment="the patch q813489 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-210" comment="the patch q818529 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-211" comment="the patch q822925 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-212" comment="the patch q828750 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-19" comment="the patch q824145 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-18" comment="Internet Explorer 6 is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL33" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>Xsun</product>
      </affected>
      <dates>
        <submitted date="2002-10-17-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in Xsun on Solaris 2.6 through 8 allows local users to gain root privileges via a long -co (color database) command line argument.</description>
      <reference source="CVE">CVE-2002-0158</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="uft-10" comment="File Xsun exists" negate="false"/>
          <criterion test_ref="spt-208" comment="Patch 108376-38 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-210" comment="File Xsun SGID and executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL34" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>whodo</product>
      </affected>
      <dates>
        <submitted date="2002-10-17-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in whodo in Solaris SunOS 5.5.1 through 5.8 allows local users to execute arbitrary code via a long (1) SOR or (2) CFIME environment variable.</description>
      <reference source="CVE">CVE-2001-1076</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="uft-13" comment="File whodo exists" negate="false"/>
          <criterion test_ref="spt-209" comment="Patch 111600-01 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-219" comment="File whodo SUID and executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL35" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>FTP</product>
      </affected>
      <dates>
        <submitted date="2003-10-10-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
      </dates>
      <description>The FTP service in Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows attackers who have established an FTP session to cause a denial of service via a specially crafted status request containing glob characters.</description>
      <reference source="CVE">CVE-2002-0073</reference>
      <status>ACCEPTED</status>
      <version>4</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-223" comment="IIS major version equals 5" negate="false"/>
          <criterion test_ref="wrt-215" comment="IIS minor version equals 0" negate="false"/>
          <criterion test_ref="wft-205" comment="the version of w3svc.dll is less than 5.0.2195.5269" negate="false"/>
          <criterion test_ref="wrt-217" comment="Patch Q319733 Installed" negate="true"/>
          <criterion test_ref="wrt-218" comment="Patch Q327696 Installed" negate="true"/>
          <criterion test_ref="wrt-219" comment="Patch Q811114 Installed" negate="true"/>
          <criterion test_ref="wrt-224" comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wmt-202" comment="FTP Enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL37" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>Internet Information Server 4.0</product>
      </affected>
      <dates>
        <submitted date="2003-10-10-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
      </dates>
      <description>Directory traversal vulnerability in IIS 5.0 and earlier allows remote attackers to execute arbitrary commands by encoding .. (dot dot) and "\" characters twice.</description>
      <reference source="CVE">CVE-2001-0333</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-214" comment="IIS 4.0 Major Version" negate="false"/>
          <criterion test_ref="wrt-215" comment="IIS minor version equals 0" negate="false"/>
          <criterion test_ref="wrt-43" comment="this is an NT Terminal Server" negate="true"/>
          <criterion test_ref="wft-211" comment="File %windir%\system32\inetsrv\ism.dll version is less than 4.2.764.1" negate="false"/>
          <criterion test_ref="wrt-241" comment="Patch Q295534 Installed" negate="true"/>
          <criterion test_ref="wrt-242" comment="Patch Q301625 Installed" negate="true"/>
          <criterion test_ref="wrt-217" comment="Patch Q319733 Installed" negate="true"/>
          <criterion test_ref="wrt-218" comment="Patch Q327696 Installed" negate="true"/>
          <criterion test_ref="wrt-219" comment="Patch Q811114 Installed" negate="true"/>
          <criterion test_ref="wrt-243" comment="Windows NT 4.0 Security Roll-up Package" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL38" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Windows 2000</product>
      </affected>
      <dates>
        <submitted date="2003-05-13-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <modified date="2005-09-26-10:55" comment="modified wft-212 - Changed comment to match test">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-28-01:04">INTERIM</status_change>
        <status_change date="2005-10-19-05:47">ACCEPTED</status_change>
      </dates>
      <description>Windows 2000 allows local users to prevent the application of new group policy settings by opening Group Policy files with exclusive-read access.</description>
      <reference source="CVE">CVE-2002-0051</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-220" comment="Windows 2000 (domain controller) is installed" negate="false"/>
          <criterion test_ref="wft-212" comment="the version of srvsvc.dll is less than 5.0.2195.4980" negate="false"/>
          <criterion test_ref="wrt-246" comment="Patch Q318593 Installed" negate="true"/>
          <criterion test_ref="wrt-224" comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL39" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Internet Information Server 5.0</product>
      </affected>
      <dates>
        <submitted date="2004-01-14-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <status_change date="2004-03-09-12:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in Internet Information Server (IIS) 4.0, 5.0, and 5.1 allows remote attackers to spoof the safety check for HTTP headers and cause a denial of service or execute arbitrary code via HTTP header field values.</description>
      <reference source="CVE">CVE-2002-0150</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-223" comment="IIS major version equals 5" negate="false"/>
          <criterion test_ref="wrt-215" comment="IIS minor version equals 0" negate="false"/>
          <criterion test_ref="wft-205" comment="the version of w3svc.dll is less than 5.0.2195.5269" negate="false"/>
          <criterion test_ref="wrt-217" comment="Patch Q319733 Installed" negate="true"/>
          <criterion test_ref="wrt-218" comment="Patch Q327696 Installed" negate="true"/>
          <criterion test_ref="wrt-219" comment="Patch Q811114 Installed" negate="true"/>
          <criterion test_ref="wrt-224" comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wmt-201" comment="asp.dll mapping exists" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL40" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Internet Explorer 5.5 Service Pack 2</product>
      </affected>
      <dates>
        <submitted date="2003-11-12-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to read arbitrary files via malformed requests to the GetObject function, which bypass some of GetObject's security checks.</description>
      <reference source="CVE">CVE-2002-0023</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-53" comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false"/>
          <criterion test_ref="wft-201" comment="the version of mshtml.dll is less than 5.50.4913.1100" negate="false"/>
          <criterion test_ref="wrt-202" comment="the patch q316059 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-203" comment="the patch q319282 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-204" comment="the patch q321232 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-205" comment="the patch q323759 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-206" comment="the patch q328970 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-207" comment="the patch q324929 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-208" comment="the patch q810847 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-209" comment="the patch q813489 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-210" comment="the patch q818529 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-211" comment="the patch q822925 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-212" comment="the patch q828750 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-19" comment="the patch q824145 is installed (Installed Components key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL41" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>rpc.rwalld</product>
      </affected>
      <dates>
        <submitted date="2003-01-30-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Format string vulnerability in RPC wall daemon (rpc.rwalld) for Solaris 2.5.1 through 8 allows remote attackers to execute arbitrary code via format strings in a message that is not properly provided to the syslog function when the wall command cannot be executed.</description>
      <reference source="CVE">CVE-2002-0573</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="uft-14" comment="File rpc.rwalld exists" negate="false"/>
          <criterion test_ref="spt-210" comment="Patch 112899-01 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-204" comment="inetd.conf contains rpc.rwalld" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
          <criterion test_ref="cmp-221" comment="File rpc.rwalld executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL42" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>libnsl</product>
      </affected>
      <dates>
        <submitted date="2003-01-02-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC including dietlibc, allows remote attackers to execute arbitrary code by passing a large number of arguments to xdr_array through RPC services such as rpc.cmsd and dmispd.</description>
      <reference source="CVE">CVE-2002-0391</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="cmp-204" comment="rpc.cmsd or dmispd exist" negate="false"/>
          <criterion test_ref="cmp-223" comment="Patches 106942-22 and 108451-06" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-206" comment="rpc.cmsd enabled OR dmispd running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL43" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>cachefsd</product>
      </affected>
      <dates>
        <submitted date="2002-10-17-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
        <modified date="2005-01-28-12:00" comment="Updated to add patch test">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </modified>
        <status_change date="2005-02-01-08:25">INTERIM</status_change>
        <status_change date="2005-02-16-12:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the fscache_setup function of cachefsd in Solaris 2.6, 7, and 8 allows local users to gain root privileges via a long mount argument.</description>
      <reference source="CVE">CVE-2002-0084</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="uft-12" comment="File cachefsd exists" negate="false"/>
          <criterion test_ref="spt-109" comment="Patch 108800-02 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-203" comment="inetd.conf contains cachefsd" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
          <criterion test_ref="cmp-217" comment="File cachefsd executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL44" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Internet Information Server 5.0</product>
      </affected>
      <dates>
        <submitted date="2003-10-10-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
      </dates>
      <description>IIS 4.0 and 5.0 allows remote attackers to read documents outside of the web root, and possibly execute arbitrary commands, via malformed URLs that contain UNICODE encoded characters, aka the "Web Server Folder Traversal" vulnerability.</description>
      <reference source="CVE">CVE-2000-0884</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-223" comment="IIS major version equals 5" negate="false"/>
          <criterion test_ref="wrt-215" comment="IIS minor version equals 0" negate="false"/>
          <criterion test_ref="wft-213" comment="File %windir%\system32\inetsrv\w3svc.dll version is less than 5.0.2195.2103" negate="false"/>
          <criterion test_ref="wrt-247" comment="Patch Q269862 Installed" negate="true"/>
          <criterion test_ref="wrt-248" comment="Patch Q277873 Installed" negate="true"/>
          <criterion test_ref="wrt-249" comment="Patch Q293826 Installed" negate="true"/>
          <criterion test_ref="wrt-242" comment="Patch Q301625 Installed" negate="true"/>
          <criterion test_ref="wrt-217" comment="Patch Q319733 Installed" negate="true"/>
          <criterion test_ref="wrt-218" comment="Patch Q327696 Installed" negate="true"/>
          <criterion test_ref="wrt-219" comment="Patch Q811114 Installed" negate="true"/>
          <criterion test_ref="wrt-250" comment="Win2K/XP/2003 service pack 2 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL45" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>Internet Information Server 4.0</product>
      </affected>
      <dates>
        <submitted date="2004-01-14-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <status_change date="2004-03-09-12:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the ism.dll ISAPI extension that implements HTR scripting in Internet Information Server (IIS) 4.0 and 5.0 allows attackers to cause a denial of service or execute arbitrary code via HTR requests with long variable names.</description>
      <reference source="CVE">CVE-2002-0071</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-214" comment="IIS 4.0 Major Version" negate="false"/>
          <criterion test_ref="wrt-215" comment="IIS minor version equals 0" negate="false"/>
          <criterion test_ref="wrt-43" comment="this is an NT Terminal Server" negate="true"/>
          <criterion test_ref="wft-202" comment="the version of w3svc.dll is less than 4.2.775.1" negate="false"/>
          <criterion test_ref="wrt-217" comment="Patch Q319733 Installed" negate="true"/>
          <criterion test_ref="wrt-218" comment="Patch Q327696 Installed" negate="true"/>
          <criterion test_ref="wrt-219" comment="Patch Q811114 Installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wmt-203" comment="ism.dll mapping exists" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL46" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Internet Information Server 5.0</product>
      </affected>
      <dates>
        <submitted date="2003-10-10-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
      </dates>
      <description>Cross-site scripting vulnerability in Help File search facility for Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows remote attackers to embed scripts into another user's session.</description>
      <reference source="CVE">CVE-2002-0074</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-223" comment="IIS major version equals 5" negate="false"/>
          <criterion test_ref="wrt-215" comment="IIS minor version equals 0" negate="false"/>
          <criterion test_ref="wft-205" comment="the version of w3svc.dll is less than 5.0.2195.5269" negate="false"/>
          <criterion test_ref="wrt-217" comment="Patch Q319733 Installed" negate="true"/>
          <criterion test_ref="wrt-218" comment="Patch Q327696 Installed" negate="true"/>
          <criterion test_ref="wrt-219" comment="Patch Q811114 Installed" negate="true"/>
          <criterion test_ref="wrt-224" comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL47" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>whodo</product>
      </affected>
      <dates>
        <submitted date="2002-09-17-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in whodo in Solaris SunOS 5.5.1 through 5.8 allows local users to execute arbitrary code via a long (1) SOR or (2) CFIME environment variable.</description>
      <reference source="CVE">CVE-2001-1076</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="uft-13" comment="File whodo exists" negate="false"/>
          <criterion test_ref="spt-213" comment="Patch 111826-01 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-219" comment="File whodo SUID and executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL48" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>admintool</product>
      </affected>
      <dates>
        <submitted date="2002-10-17-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in admintool in Solaris 2.6, 7, and 8 allows local users to gain root privileges via a long media installation path.</description>
      <reference source="CVE">CVE-2002-0088</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="uft-15" comment="File admintool exists" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-229" comment="File admintool SUID and executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL49" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Internet Explorer 5.01</product>
      </affected>
      <dates>
        <submitted date="2003-11-12-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Microsoft Internet Explorer 5.5 and 6.0 allows remote attackers to bypass the cross-domain security model to run malicious script or arbitrary programs via dialog boxes, aka "Improper Cross Domain Security Validation with dialog box."</description>
      <reference source="CVE">CVE-2003-1326</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-230" comment="Internet Explorer 5.01 Installed" negate="false"/>
          <criterion test_ref="wft-214" comment="File %windir%\system32\mshtml.dll version is less than 5.0.3513.900" negate="false"/>
          <criterion test_ref="wrt-208" comment="the patch q810847 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-252" comment="the patch q813489 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-210" comment="the patch q818529 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-211" comment="the patch q822925 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-212" comment="the patch q828750 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-19" comment="the patch q824145 is installed (Installed Components key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL50" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Internet Explorer 5.01, Internet Explorer 5.01 Service Pack 1, or Internet Explorer 5.01 Service Pack 2</product>
      </affected>
      <dates>
        <submitted date="2003-11-12-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to read arbitrary files via malformed requests to the GetObject function, which bypass some of GetObject's security checks.</description>
      <reference source="CVE">CVE-2002-0023</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-214" comment="Internet Explorer 5.01 Installed" negate="false"/>
          <criterion test_ref="wft-215" comment="the version of mshtml.dll is less than 5.0.3502.4856" negate="false"/>
          <criterion test_ref="wrt-202" comment="the patch q316059 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-203" comment="the patch q319282 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-204" comment="the patch q321232 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-205" comment="the patch q323759 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-19" comment="the patch q824145 is installed (Installed Components key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL52" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>EOG</product>
      </affected>
      <dates>
        <submitted date="2003-08-14-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Format string vulnerability in Eye Of Gnome (EOG) allows attackers to execute arbitrary code via format string specifiers in a command line argument for the file to display.</description>
      <reference source="CVE">CVE-2003-0165</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-205" comment="eog version is less than 2.2.0-2" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-232" comment="eog is executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL54" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Ethereal</product>
      </affected>
      <dates>
        <submitted date="2003-08-17-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Format string vulnerability in packet-socks.c of the SOCKS dissector for Ethereal 0.8.7 through 0.9.9 allows remote attackers to execute arbitrary code via SOCKS packets containing format string specifiers.</description>
      <reference source="CVE">CVE-2003-0081</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-206" comment="ethereal version is less than 0.9.11-0.90.1" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL55" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Ethereal</product>
      </affected>
      <dates>
        <submitted date="2003-08-17-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Heap-based buffer overflow in the NTLMSSP code for Ethereal 0.9.9 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code.</description>
      <reference source="CVE">CVE-2003-0159</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-206" comment="ethereal version is less than 0.9.11-0.90.1" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL56" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>rpc.yppasswdd</product>
      </affected>
      <dates>
        <submitted date="2002-08-30-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in rpc.yppasswdd (yppasswd server) in Solaris 2.6, 7 and 8 allows remote attackers to gain root access via a long username.</description>
      <reference source="CVE">CVE-2001-0779</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="uft-16" comment="File rpc.yppasswdd exists" negate="false"/>
          <criterion test_ref="spt-214" comment="Patch 111596-02 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-7" comment="rpc.yppasswdd running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL57" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Internet Explorer 6.0</product>
      </affected>
      <dates>
        <submitted date="2003-11-12-05:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
        <modified date="2005-09-20-04:00" comment="Changed IE registry test to wrt-18">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-21-01:27">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>The showHelp() function in Microsoft Internet Explorer 5.01, 5.5, and 6.0 supports certain types of pluggable protocols that allow remote attackers to bypass the cross-domain security model and execute arbitrary code, aka "Improper Cross Domain Security Validation with ShowHelp functionality."</description>
      <reference source="CVE">CVE-2003-1328</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wft-216" comment="the version of mshtml.dll is less than 6.0.2723.2500" negate="false"/>
          <criterion test_ref="wrt-208" comment="the patch q810847 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-209" comment="the patch q813489 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-210" comment="the patch q818529 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-211" comment="the patch q822925 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-212" comment="the patch q828750 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-19" comment="the patch q824145 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-18" comment="Internet Explorer 6 is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL58" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>Internet Information Server 4.0</product>
      </affected>
      <dates>
        <submitted date="2003-08-20-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
      </dates>
      <description>Cross-site scripting vulnerability for Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows remote attackers to execute arbitrary script as other web users via the error message used in a URL redirect (""302 Object Moved") message.</description>
      <reference source="CVE">CVE-2002-0075</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-214" comment="IIS 4.0 Major Version" negate="false"/>
          <criterion test_ref="wrt-215" comment="IIS minor version equals 0" negate="false"/>
          <criterion test_ref="wrt-43" comment="this is an NT Terminal Server" negate="true"/>
          <criterion test_ref="wft-202" comment="the version of w3svc.dll is less than 4.2.775.1" negate="false"/>
          <criterion test_ref="wrt-217" comment="Patch Q319733 Installed" negate="true"/>
          <criterion test_ref="wrt-218" comment="Patch Q327696 Installed" negate="true"/>
          <criterion test_ref="wrt-219" comment="Patch Q811114 Installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL59" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Remote Procedure Call (RPC)</product>
      </affected>
      <dates>
        <submitted date="2003-10-10-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <modified date="2005-03-07-12:00" comment="modified wrt-222 - changed pattern match">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-03-09-07:55">INTERIM</status_change>
        <status_change date="2005-03-29-07:59">ACCEPTED</status_change>
      </dates>
      <description>The RPC component in Windows 2000, Windows NT 4.0, and Windows XP allows remote attackers to cause a denial of service (disabled RPC service) via a malformed packet to the RPC Endpoint Mapper at TCP port 135, which triggers a null pointer dereference.</description>
      <reference source="CVE">CVE-2002-1561</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
          <criterion test_ref="wft-217" comment="File %windir%\system32\rpcrt4.dll version is less than 5.0.2195.6106" negate="false"/>
          <criterion test_ref="wrt-253" comment="Patch Q331953_W2K_SP4_X86_EN.exe Installed" negate="true"/>
          <criterion test_ref="wrt-254" comment="Patch Windows2000-KB823980-x86-ENU.exe Installed" negate="true"/>
          <criterion test_ref="wrt-222" comment="SP4 or later Installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL60" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>admintool</product>
      </affected>
      <dates>
        <submitted date="2002-09-17-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in admintool in Solaris 2.6, 7, and 8 allows local users to gain root privileges via a long media installation path.</description>
      <reference source="CVE">CVE-2002-0088</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="uft-15" comment="File admintool exists" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-229" comment="File admintool SUID and executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL61" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>Remote Access Service (RAS)</product>
      </affected>
      <dates>
        <submitted date="2003-04-04-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in Remote Access Service (RAS) phonebook for Windows NT 4.0, 2000, XP, and Routing and Remote Access Server (RRAS) allows local users to execute arbitrary code by modifying the rasphone.pbk file to use a long dial-up entry.</description>
      <reference source="CVE">CVE-2002-0366</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" negate="false"/>
          <criterion test_ref="wrt-43" comment="this is an NT Terminal Server" negate="true"/>
          <criterion test_ref="wrt-256" comment="RAS Phonebook" negate="false"/>
          <criterion test_ref="wft-218" comment="File %windir%\system32\rasapi32.dll version is less than 4.0.1381.7140" negate="false"/>
          <criterion test_ref="wrt-257" comment="Patch Q318138 Installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-258" comment="RAS Enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL62" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>mibiisa</product>
      </affected>
      <dates>
        <submitted date="2002-10-17-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in the MIB parsing component of mibiisa for Solaris 5.6 through 8 allows remote attackers to gain root privileges.</description>
      <reference source="CVE">CVE-2002-0797</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="uft-17" comment="File mibiisa exists" negate="false"/>
          <criterion test_ref="spt-215" comment="Patch 107709-19 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-8" comment="mibiisa running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL63" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Remote Access Service (RAS)</product>
      </affected>
      <dates>
        <submitted date="2003-04-04-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in Remote Access Service (RAS) phonebook for Windows NT 4.0, 2000, XP, and Routing and Remote Access Server (RRAS) allows local users to execute arbitrary code by modifying the rasphone.pbk file to use a long dial-up entry.</description>
      <reference source="CVE">CVE-2002-0366</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
          <criterion test_ref="wrt-256" comment="RAS Phonebook" negate="false"/>
          <criterion test_ref="wft-219" comment="File %windir%\system32\rasman.dll version is less than 5.0.2195.4983" negate="false"/>
          <criterion test_ref="wrt-257" comment="Patch Q318138 Installed" negate="true"/>
          <criterion test_ref="wrt-224" comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-258" comment="RAS Enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL64" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Windows 2000</product>
      </affected>
      <dates>
        <submitted date="2003-05-13-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <modified date="2004-08-04-12:00" comment="Modifed without comment">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </modified>
        <status_change date="2004-08-25-12:00">ACCEPTED</status_change>
        <status_change date="2004-08-26-12:00">INTERIM</status_change>
        <status_change date="2004-09-09-12:00">ACCEPTED</status_change>
        <modified date="2005-09-26-10:56" comment="modified wft-220 - Changed comment to match test">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-28-01:04">INTERIM</status_change>
        <status_change date="2005-10-19-05:47">ACCEPTED</status_change>
      </dates>
      <description>In Microsoft Windows NT and Windows 2000, a trusting domain that receives authorization information from a trusted domain does not verify that the trusted domain is authoritative for all listed SIDs, which could allows remote attackers to gain Domain Administrator privileges on the trusting domain by injecting SIDs from untrusted domains into the authorization data that comes from from the trusted domain.</description>
      <reference source="CVE">CVE-2002-0018</reference>
      <status>ACCEPTED</status>
      <version>4</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
          <criterion test_ref="wft-220" comment="File %windir%\system32\netlogon.dll version is less than 5.0.893.1105" negate="false"/>
          <criterion test_ref="wrt-259" comment="Windows 2000 Security Roll-up 1 Installed" negate="true"/>
          <criterion test_ref="wrt-217" comment="Patch Q319733 Installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL65" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>kcms_configure</product>
      </affected>
      <dates>
        <submitted date="2002-09-17-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>kcms_configure as included with Solaris 7 and 8 allows a local attacker to gain additional privileges via a buffer overflow in a command line argument.</description>
      <reference source="CVE">CVE-2001-0594</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="uft-5" comment="File kcms_configure exists" negate="false"/>
          <criterion test_ref="spt-216" comment="Patch 107337-02 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-202" comment="File kcms_configure executable and SUID or SGID" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL66" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Internet Information Server 5.0</product>
      </affected>
      <dates>
        <submitted date="2003-10-10-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
        <modified date="2005-03-07-12:00" comment="modified wrt-222 - changed pattern match">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-03-09-07:55">INTERIM</status_change>
        <status_change date="2005-03-29-07:59">ACCEPTED</status_change>
      </dates>
      <description>Cross-site scripting vulnerability (XSS) in the ASP function responsible for redirection in Microsoft Internet Information Server (IIS) 4.0, 5.0, and 5.1 allows remote attackers to embed a URL containing script in a redirection message.</description>
      <reference source="CVE">CVE-2003-0223</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-223" comment="IIS major version equals 5" negate="false"/>
          <criterion test_ref="wrt-215" comment="IIS minor version equals 0" negate="false"/>
          <criterion test_ref="wft-221" comment="File %windir%\system32\inetsrv\asp.dll version is less than 5.0.2195.6672" negate="false"/>
          <criterion test_ref="wrt-219" comment="Patch Q811114 Installed" negate="true"/>
          <criterion test_ref="wrt-222" comment="SP4 or later Installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL67" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>admintool</product>
      </affected>
      <dates>
        <submitted date="2002-09-17-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in admintool in Solaris 2.5 through 8 allows local users to gain root privileges via long arguments to (1) the -d command line option, or (2) the PRODVERS argument in the .cdtoc file.</description>
      <reference source="CVE">CVE-2002-0089</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="uft-15" comment="File admintool exists" negate="false"/>
          <criterion test_ref="spt-217" comment="Patch 110453-01 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-229" comment="File admintool SUID and executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL68" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>admintool</product>
      </affected>
      <dates>
        <submitted date="2002-10-17-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in admintool in Solaris 2.5 through 8 allows local users to gain root privileges via long arguments to (1) the -d command line option, or (2) the PRODVERS argument in the .cdtoc file.</description>
      <reference source="CVE">CVE-2002-0089</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="uft-15" comment="File admintool exists" negate="false"/>
          <criterion test_ref="spt-218" comment="Patch 108721-02 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-229" comment="File admintool SUID and executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL69" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Ethereal</product>
      </affected>
      <dates>
        <submitted date="2003-08-29-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Multiple off-by-one vulnerabilities in Ethereal 0.9.11 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) AIM, (2) GIOP Gryphon, (3) OSPF, (4) PPTP, (5) Quake, (6) Quake2, (7) Quake3, (8) Rsync, (9) SMB, (10) SMPP, and (11) TSP dissectors, which do not properly use the tvb_get_nstringz and tvb_get_nstringz0 functions.</description>
      <reference source="CVE">CVE-2003-0356</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="cmp-238" comment="Vulnerable Config" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL70" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>dtspcd</product>
      </affected>
      <dates>
        <submitted date="2002-08-23-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in the client connection routine of libDtSvc.so.1 in CDE Subprocess Control Service (dtspcd) allows remote attackers to execute arbitrary commands</description>
      <reference source="CVE">CVE-2001-0803</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="uft-18" comment="File dtspcd exists" negate="false"/>
          <criterion test_ref="spt-219" comment="Patch 108949-07 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-205" comment="inetd.conf contains dtspcd" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
          <criterion test_ref="cmp-239" comment="File dtspcd executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL71" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft SQL Server 2000</product>
      </affected>
      <dates>
        <submitted date="2003-06-24-12:00">
          <contributor organization="The MITRE Corporation">Yi-Fang Koh</contributor>
        </submitted>
        <status_change date="2004-03-09-12:00">ACCEPTED</status_change>
        <modified date="2005-04-07-12:00" comment="modified wft-222 - corrected literal component of file path. It was missing the leading '\'">
          <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
        </modified>
        <modified date="2005-04-07-09:25" comment="modified wft-222 - Corrected comment">
          <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
        </modified>
        <status_change date="2005-04-11-08:48">INTERIM</status_change>
        <status_change date="2005-04-27-12:07">ACCEPTED</status_change>
      </dates>
      <description>An SQL query method in Microsoft SQL Server 2000 Gold and 7.0 using Mixed Mode allows local database users to gain privileges by reusing a cached connection of the sa administrator account.</description>
      <reference source="CVE">CVE-2001-0344</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-260" comment="SQL Server 2000 is installed" negate="false"/>
          <criterion test_ref="wft-222" comment="the version of sqlservr.exe is less than 2000.80.296.0" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-261" comment="Mixed Mode Enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL72" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>Internet Information Server 4.0</product>
      </affected>
      <dates>
        <submitted date="2004-01-14-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <status_change date="2004-03-09-12:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the ASP data transfer mechanism in Internet Information Server (IIS) 4.0, 5.0, and 5.1 allows remote attackers to cause a denial of service or execute code, aka "Microsoft-discovered variant of Chunked Encoding buffer overrun."</description>
      <reference source="CVE">CVE-2002-0147</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-214" comment="IIS 4.0 Major Version" negate="false"/>
          <criterion test_ref="wrt-215" comment="IIS minor version equals 0" negate="false"/>
          <criterion test_ref="wrt-43" comment="this is an NT Terminal Server" negate="true"/>
          <criterion test_ref="wft-202" comment="the version of w3svc.dll is less than 4.2.775.1" negate="false"/>
          <criterion test_ref="wrt-217" comment="Patch Q319733 Installed" negate="true"/>
          <criterion test_ref="wrt-218" comment="Patch Q327696 Installed" negate="true"/>
          <criterion test_ref="wrt-219" comment="Patch Q811114 Installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wmt-201" comment="asp.dll mapping exists" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL73" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Ethereal</product>
      </affected>
      <dates>
        <submitted date="2003-08-29-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Multiple integer overflow vulnerabilities in Ethereal 0.9.11 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) Mount and (2) PPP dissectors.</description>
      <reference source="CVE">CVE-2003-0357</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="cmp-238" comment="Vulnerable Config" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL74" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>dtspcd</product>
      </affected>
      <dates>
        <submitted date="2002-10-17-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in the client connection routine of libDtSvc.so.1 in CDE Subprocess Control Service (dtspcd) allows remote attackers to execute arbitrary commands</description>
      <reference source="CVE">CVE-2001-0803</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="uft-18" comment="File dtspcd exists" negate="false"/>
          <criterion test_ref="spt-220" comment="Patch 106934-04 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-205" comment="inetd.conf contains dtspcd" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
          <criterion test_ref="cmp-239" comment="File dtspcd executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL75" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Ethereal</product>
      </affected>
      <dates>
        <submitted date="2003-08-29-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Unknown vulnerability in the DCERPC (DCE/RPC) dissector in Ethereal 0.9.12 and earlier allows remote attackers to cause a denial of service (memory consumption) via a certain NDR string.</description>
      <reference source="CVE">CVE-2003-0428</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="cmp-238" comment="Vulnerable Config" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL76" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Windows 2000</product>
      </affected>
      <dates>
        <submitted date="2003-04-04-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
      </dates>
      <description>smss.exe debugging subsystem in Windows NT and Windows 2000 does not properly authenticate programs that connect to other programs, which allows local users to gain administrator or SYSTEM privileges by duplicating a handle to a privileged process, as demonstrated by DebPloit.</description>
      <reference source="CVE">CVE-2002-0367</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
          <criterion test_ref="wft-223" comment="File %windir%\system32\smss.exe version is less than 5.0.2195.5695" negate="false"/>
          <criterion test_ref="wrt-262" comment="Patch Q320206 Installed" negate="true"/>
          <criterion test_ref="wrt-224" comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL77" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Internet Explorer 5.5 or Internet Explorer 5.5 Service Pack 1</product>
      </affected>
      <dates>
        <submitted date="2003-11-12-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to read arbitrary files via malformed requests to the GetObject function, which bypass some of GetObject's security checks.</description>
      <reference source="CVE">CVE-2002-0023</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-213" comment="Internet Explorer 5.5 Installed" negate="false"/>
          <criterion test_ref="wft-206" comment="the version of mshtml.dll is less than 5.50.4725.2100" negate="false"/>
          <criterion test_ref="wrt-202" comment="the patch q316059 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-203" comment="the patch q319282 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-204" comment="the patch q321232 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-205" comment="the patch q323759 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-212" comment="the patch q828750 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-19" comment="the patch q824145 is installed (Installed Components key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL78" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Internet Information Server 5.0</product>
      </affected>
      <dates>
        <submitted date="2003-10-10-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <modified date="2004-08-04-12:00" comment="Modifed without comment">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </modified>
        <status_change date="2004-08-25-12:00">ACCEPTED</status_change>
        <status_change date="2004-08-26-12:00">INTERIM</status_change>
        <status_change date="2004-09-09-12:00">ACCEPTED</status_change>
      </dates>
      <description>Directory traversal vulnerability in IIS 5.0 and earlier allows remote attackers to execute arbitrary commands by encoding .. (dot dot) and "\" characters twice.</description>
      <reference source="CVE">CVE-2001-0333</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-223" comment="IIS major version equals 5" negate="false"/>
          <criterion test_ref="wrt-215" comment="IIS minor version equals 0" negate="false"/>
          <criterion test_ref="wft-224" comment="File %windir%\system32\inetsrv\ism.dll version is less than 5.0.2195.3407" negate="false"/>
          <criterion test_ref="wrt-249" comment="Patch Q293826 Installed" negate="true"/>
          <criterion test_ref="wrt-242" comment="Patch Q301625 Installed" negate="true"/>
          <criterion test_ref="wrt-217" comment="Patch Q319733 Installed" negate="true"/>
          <criterion test_ref="wrt-218" comment="Patch Q327696 Installed" negate="true"/>
          <criterion test_ref="wrt-219" comment="Patch Q811114 Installed" negate="true"/>
          <criterion test_ref="wrt-259" comment="Windows 2000 Security Roll-up 1 Installed" negate="true"/>
          <criterion test_ref="wrt-224" comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL79" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>rpc.rwalld</product>
      </affected>
      <dates>
        <submitted date="2003-01-30-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Format string vulnerability in RPC wall daemon (rpc.rwalld) for Solaris 2.5.1 through 8 allows remote attackers to execute arbitrary code via format strings in a message that is not properly provided to the syslog function when the wall command cannot be executed.</description>
      <reference source="CVE">CVE-2002-0573</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="uft-14" comment="File rpc.rwalld exists" negate="false"/>
          <criterion test_ref="spt-221" comment="Patch 112846-01 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-204" comment="inetd.conf contains rpc.rwalld" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
          <criterion test_ref="cmp-221" comment="File rpc.rwalld executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL80" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>CDE</product>
      </affected>
      <dates>
        <submitted date="2003-01-29-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>CDE ToolTalk database server (ttdbserver) allows local users to overwrite arbitrary files via a symlink attack on the transaction log file used by the _TT_TRANSACTION RPC procedure.</description>
      <reference source="CVE">CVE-2002-0678</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="uft-11" comment="File rpc.ttdbserverd exists" negate="false"/>
          <criterion test_ref="spt-222" comment="Patch 107893-19 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-202" comment="inetd.conf contains rpc.ttdbserverd" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
          <criterion test_ref="cmp-211" comment="File rpc.ttdbserverd executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL81" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>Internet Information Server 4.0</product>
      </affected>
      <dates>
        <submitted date="2003-08-20-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
      </dates>
      <description>Cross-site scripting vulnerability in Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows remote attackers to execute arbitrary script as other users via an HTTP error page.</description>
      <reference source="CVE">CVE-2002-0148</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-214" comment="IIS 4.0 Major Version" negate="false"/>
          <criterion test_ref="wrt-215" comment="IIS minor version equals 0" negate="false"/>
          <criterion test_ref="wrt-43" comment="this is an NT Terminal Server" negate="true"/>
          <criterion test_ref="wft-202" comment="the version of w3svc.dll is less than 4.2.775.1" negate="false"/>
          <criterion test_ref="wrt-217" comment="Patch Q319733 Installed" negate="true"/>
          <criterion test_ref="wrt-218" comment="Patch Q327696 Installed" negate="true"/>
          <criterion test_ref="wrt-219" comment="Patch Q811114 Installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL82" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft SQL Server 2000</product>
      </affected>
      <dates>
        <submitted date="2003-08-27-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <modified date="2005-04-07-12:00" comment="modified wft-225 - correct literal component in file path. Added '\' to the start of the literal string.">
          <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
        </modified>
        <status_change date="2005-04-11-12:00">INTERIM</status_change>
        <modified date="2005-04-12-12:00" comment="modified wft-89 - wft-89 corrected literal string">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <status_change date="2005-04-27-12:07">ACCEPTED</status_change>
        <modified date="2005-09-27-01:26" comment="modified wft-89 - Changed comment to match test">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-28-01:04">INTERIM</status_change>
        <status_change date="2005-10-19-05:47">ACCEPTED</status_change>
      </dates>
      <description>Vulnerabilities in RPC servers in (1) Microsoft Exchange Server 2000 and earlier, (2) Microsoft SQL Server 2000 and earlier, (3) Windows NT 4.0, and (4) Windows 2000 allow remote attackers to cause a denial of service via malformed inputs.</description>
      <reference source="CVE">CVE-2001-0509</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-260" comment="SQL Server 2000 is installed" negate="false"/>
          <criterion test_ref="wft-225" comment="the version of ssmsrp70.dll is less than 2000.80.213.0" negate="false"/>
          <criterion test_ref="wft-59" comment="the version of dbmsrpcn.dll is less than 2000.80.213.0" negate="false"/>
          <criterion test_ref="wft-89" comment="File sqlservr.exe version3 greater than or equal to 2000.80.384.0" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL83" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft SQL Server</product>
      </affected>
      <dates>
        <submitted date="2003-10-10-12:00">
          <contributor organization="The MITRE Corporation">Yi-Fang Koh</contributor>
        </submitted>
        <modified date="2005-04-08-12:00" comment="modified wft-227 - corrected literal string">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <status_change date="2005-04-11-08:48">INTERIM</status_change>
        <status_change date="2005-04-27-12:07">ACCEPTED</status_change>
        <modified date="2005-09-26-10:57" comment="modified wft-227 - Changed comment to match test">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-28-01:04">INTERIM</status_change>
        <status_change date="2005-10-19-05:47">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflows in Microsoft SQL Server 7.0 and 2000 allow attackers with access to SQL Server to execute arbitrary code through the functions (1) raiserror, (2) formatmessage, or (3) xp_sprintf.  NOTE: the C runtime format string vulnerability reported in MS01-060 is identified by CVE-2001-0879.</description>
      <reference source="CVE">CVE-2001-0542</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-260" comment="SQL Server 2000 is installed" negate="false"/>
          <criterion test_ref="wft-227" comment="File sqlservr.exe version3 less than 2000.80.428.0" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL84" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Ethereal</product>
      </affected>
      <dates>
        <submitted date="2003-08-29-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>The OSI dissector in Ethereal 0.9.12 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via invalid IPv4 or IPv6 prefix lengths, possibly triggering a buffer overflow.</description>
      <reference source="CVE">CVE-2003-0429</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="cmp-238" comment="Vulnerable Config" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL86" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>lbxproxy</product>
      </affected>
      <dates>
        <submitted date="2002-08-30-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in Low BandWidth X proxy (lbxproxy) in Solaris 8 allows local users to execute arbitrary code via a long display command line option.</description>
      <reference source="CVE">CVE-2002-0090</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="uft-19" comment="File lbxproxy exists" negate="false"/>
          <criterion test_ref="spt-223" comment="Patch 108652-51 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-247" comment="File lbxproxy SGID and executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL87" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>Simple Network Management Protocol (SNMP)</product>
      </affected>
      <dates>
        <submitted date="2003-10-10-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
      </dates>
      <description>Vulnerabilities in the SNMPv1 request handling of a large number of SNMP implementations allow remote attackers to cause a denial of service or gain privileges via (1) GetRequest, (2) GetNextRequest, and (3) SetRequest messages, as demonstrated by the PROTOS c06-SNMPv1 test suite.  NOTE: It is highly likely that this candidate will be SPLIT into multiple candidates, one or more for each vendor.  This and other SNMP-related candidates will be updated when more accurate information is available.</description>
      <reference source="CVE">CVE-2002-0013</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" negate="false"/>
          <criterion test_ref="wrt-43" comment="this is an NT Terminal Server" negate="true"/>
          <criterion test_ref="wft-228" comment="the version of snmp.exe is less than 4.0.1381.7134" negate="false"/>
          <criterion test_ref="wrt-263" comment="Patch Q314147 Installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-264" comment="the SNMP service is enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL88" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Ethereal</product>
      </affected>
      <dates>
        <submitted date="2003-08-29-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>The SPNEGO dissector in Ethereal 0.9.12 and earlier allows remote attackers to cause a denial of service (crash) via an invalid ASN.1 value.</description>
      <reference source="CVE">CVE-2003-0430</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="cmp-238" comment="Vulnerable Config" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL89" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Multiple UNC Provider (MUP)</product>
      </affected>
      <dates>
        <submitted date="2003-05-13-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in Multiple UNC Provider (MUP) in Microsoft Windows operating systems allows local users to cause a denial of service or possibly gain SYSTEM privileges via a long UNC request.</description>
      <reference source="CVE">CVE-2002-0151</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
          <criterion test_ref="wft-229" comment="File %windir%\system32\drivers\mup.sys version is less than 5.0.2195.5080" negate="false"/>
          <criterion test_ref="wrt-265" comment="Patch Q311967 Installed" negate="true"/>
          <criterion test_ref="wrt-224" comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL90" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Internet Information Server 5.0</product>
      </affected>
      <dates>
        <submitted date="2003-10-10-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <status_change date="2004-10-20-12:00">INTERIM</status_change>
        <modified date="2004-10-20-10:07" comment="corrected configuration criterion">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <status_change date="2004-11-03-12:00">ACCEPTED</status_change>
      </dates>
      <description>IIS 5.0 allows remote attackers to cause a denial of service via a series of malformed WebDAV requests.</description>
      <reference source="CVE">CVE-2001-0151</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-223" comment="IIS major version equals 5" negate="false"/>
          <criterion test_ref="wrt-215" comment="IIS minor version equals 0" negate="false"/>
          <criterion test_ref="wft-230" comment="File %windir%\system32\inetsrv\httpext.dll version is less than 0.9.3940.20" negate="false"/>
          <criterion test_ref="wrt-266" comment="Patch Q291845 Installed" negate="true"/>
          <criterion test_ref="wrt-249" comment="Patch Q293826 Installed" negate="true"/>
          <criterion test_ref="wrt-242" comment="Patch Q301625 Installed" negate="true"/>
          <criterion test_ref="wrt-217" comment="Patch Q319733 Installed" negate="true"/>
          <criterion test_ref="wrt-218" comment="Patch Q327696 Installed" negate="true"/>
          <criterion test_ref="wrt-219" comment="Patch Q811114 Installed" negate="true"/>
          <criterion test_ref="wrt-250" comment="Win2K/XP/2003 service pack 2 is installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-541" comment="WebDav is disabled(for iis 5.0)" negate="true"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL91" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>CDE</product>
      </affected>
      <dates>
        <submitted date="2003-01-31-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>CDE ToolTalk database server (ttdbserver) allows remote attackers to overwrite arbitrary memory locations with a zero, and possibly gain privileges, via a file descriptor argument in an AUTH_UNIX procedure call, which is used as a table index by the _TT_ISCLOSE procedure.</description>
      <reference source="CVE">CVE-2002-0677</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="uft-11" comment="File rpc.ttdbserverd exists" negate="false"/>
          <criterion test_ref="spt-222" comment="Patch 107893-19 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-202" comment="inetd.conf contains rpc.ttdbserverd" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
          <criterion test_ref="cmp-211" comment="File rpc.ttdbserverd executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL92" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Internet Information Server 5.0</product>
      </affected>
      <dates>
        <submitted date="2003-10-10-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
      </dates>
      <description>Cross-site scripting vulnerability in Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows remote attackers to execute arbitrary script as other users via an HTTP error page.</description>
      <reference source="CVE">CVE-2002-0148</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-223" comment="IIS major version equals 5" negate="false"/>
          <criterion test_ref="wrt-215" comment="IIS minor version equals 0" negate="false"/>
          <criterion test_ref="wft-205" comment="the version of w3svc.dll is less than 5.0.2195.5269" negate="false"/>
          <criterion test_ref="wrt-217" comment="Patch Q319733 Installed" negate="true"/>
          <criterion test_ref="wrt-218" comment="Patch Q327696 Installed" negate="true"/>
          <criterion test_ref="wrt-219" comment="Patch Q811114 Installed" negate="true"/>
          <criterion test_ref="wrt-224" comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL94" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>mibiisa</product>
      </affected>
      <dates>
        <submitted date="2002-09-25-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in the MIB parsing component of mibiisa for Solaris 5.6 through 8 allows remote attackers to gain root privileges.</description>
      <reference source="CVE">CVE-2002-0797</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="uft-17" comment="File mibiisa exists" negate="false"/>
          <criterion test_ref="spt-204" comment="Patch 108869-16 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-8" comment="mibiisa running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL95" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Internet Information Server 5.0</product>
      </affected>
      <dates>
        <submitted date="2004-01-14-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <status_change date="2004-03-09-12:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in ASP Server-Side Include Function in IIS 4.0, 5.0 and 5.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via long file names.</description>
      <reference source="CVE">CVE-2002-0149</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-223" comment="IIS major version equals 5" negate="false"/>
          <criterion test_ref="wrt-215" comment="IIS minor version equals 0" negate="false"/>
          <criterion test_ref="wft-205" comment="the version of w3svc.dll is less than 5.0.2195.5269" negate="false"/>
          <criterion test_ref="wrt-217" comment="Patch Q319733 Installed" negate="true"/>
          <criterion test_ref="wrt-218" comment="Patch Q327696 Installed" negate="true"/>
          <criterion test_ref="wrt-219" comment="Patch Q811114 Installed" negate="true"/>
          <criterion test_ref="wrt-224" comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wmt-201" comment="asp.dll mapping exists" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL96" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Internet Explorer 6.0</product>
      </affected>
      <dates>
        <submitted date="2003-11-12-05:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <modified date="2004-03-04-05:00" comment="Added the configuration check to see if cookies are enabled by the current user when local machine settings are not in use.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <status_change date="2004-03-09-05:00">INTERIM</status_change>
        <status_change date="2004-03-25-05:00">ACCEPTED</status_change>
        <modified date="2005-09-20-04:00" comment="modified wrt-18 - Changed value element to include pattern match">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-21-01:27">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>The zone determination function in Microsoft Internet Explorer 5.5 and 6.0 allows remote attackers to run scripts in the Local Computer zone by embedding the script in a cookie, aka the "Cookie-based Script Execution" vulnerability.</description>
      <reference source="CVE">CVE-2002-0078</reference>
      <status>ACCEPTED</status>
      <version>5</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-18" comment="Internet Explorer 6 is installed" negate="false"/>
          <criterion test_ref="wft-231" comment="the version of mshtml.dll is less than 6.0.2715.400" negate="false"/>
          <criterion test_ref="wrt-203" comment="the patch q319282 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-204" comment="the patch q321232 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-205" comment="the patch q323759 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-206" comment="the patch q328970 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-207" comment="the patch q324929 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-208" comment="the patch q810847 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-209" comment="the patch q813489 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-210" comment="the patch q818529 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-211" comment="the patch q822925 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-212" comment="the patch q828750 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-19" comment="the patch q824145 is installed (Installed Components key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-250" comment="cookies are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL97" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>cachefsd</product>
      </affected>
      <dates>
        <submitted date="2002-09-17-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
        <modified date="2005-01-27-12:00" comment="Updated to add patch test">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </modified>
        <modified date="2005-01-28-12:00" comment="Added Solaris 9 and Solaris 9 patch test to the definition">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </modified>
        <status_change date="2005-02-01-08:28">INTERIM</status_change>
        <status_change date="2005-02-16-12:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the fscache_setup function of cachefsd in Solaris 2.6, 7, and 8 allows local users to gain root privileges via a long mount argument.</description>
      <reference source="CVE">CVE-2002-0084</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uft-12" comment="File cachefsd exists" negate="false"/>
          <criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" negate="false"/>
          <criterion test_ref="spt-110" comment="Patch 110896-02 or later installed" negate="true"/>
          <criterion test_ref="spt-111" comment="Patch 114008-01 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-203" comment="inetd.conf contains cachefsd" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
          <criterion test_ref="cmp-217" comment="File cachefsd executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL98" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Internet Explorer 6.0</product>
      </affected>
      <dates>
        <submitted date="2003-11-12-05:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
        <modified date="2005-09-20-04:00" comment="Changed IE registry test to wrt-18">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-21-01:27">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in gopher client for Microsoft Internet Explorer 5.1 through 6.0, Proxy Server 2.0, or ISA Server 2000 allows remote attackers to execute arbitrary code via a gopher:// URL that redirects the user to a real or simulated gopher server that sends a long response.</description>
      <reference source="CVE">CVE-2002-0371</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wft-232" comment="File %windir%\system32\mshtml.dll version is less than 6.0.2719.2200" negate="false"/>
          <criterion test_ref="wrt-205" comment="the patch q323759 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-206" comment="the patch q328970 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-207" comment="the patch q324929 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-208" comment="the patch q810847 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-209" comment="the patch q813489 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-210" comment="the patch q818529 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-211" comment="the patch q822925 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-212" comment="the patch q828750 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-19" comment="the patch q824145 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-18" comment="Internet Explorer 6 is installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-271" comment="Gopher Enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL99" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Internet Explorer 6.0</product>
      </affected>
      <dates>
        <submitted date="2004-01-27-05:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <modified date="2005-03-07-05:00" comment="modified wrt-222 - changed pattern match">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-03-09-05:00">INTERIM</status_change>
        <status_change date="2005-03-29-05:00">ACCEPTED</status_change>
        <modified date="2005-09-20-04:00" comment="Changed IE registry test to wrt-18">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-21-01:27">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Internet Explorer 5.01 and 6.0 allow remote attackers to execute arbitrary code via malformed Content-Disposition and Content-Type header fields that cause the application for the spoofed file type to pass the file back to the operating system for handling rather than raise an error message, aka the first variant of the "Content Disposition" vulnerability.</description>
      <reference source="CVE">CVE-2002-0193</reference>
      <status>ACCEPTED</status>
      <version>5</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wft-204" comment="the version of mshtml.dll is less than 6.0.2716.2200" negate="false"/>
          <criterion test_ref="wrt-204" comment="the patch q321232 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-205" comment="the patch q323759 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-206" comment="the patch q328970 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-207" comment="the patch q324929 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-208" comment="the patch q810847 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-209" comment="the patch q813489 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-210" comment="the patch q818529 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-211" comment="the patch q822925 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-212" comment="the patch q828750 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-19" comment="the patch q824145 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="cmp-215" comment="Windows 2000 Service Pack 4 (or later) is installed" negate="true"/>
          <criterion test_ref="wrt-18" comment="Internet Explorer 6 is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL101" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Ethereal</product>
      </affected>
      <dates>
        <submitted date="2003-08-29-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>The tvb_get_nstringz0 function in Ethereal 0.9.12 and earlier does not properly handle a zero-length buffer size, with unknown consequences.</description>
      <reference source="CVE">CVE-2003-0431</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="cmp-238" comment="Vulnerable Config" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL102" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>rpc.yppasswdd</product>
      </affected>
      <dates>
        <submitted date="2002-10-17-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in rpc.yppasswdd (yppasswd server) in Solaris 2.6, 7 and 8 allows remote attackers to gain root access via a long username.</description>
      <reference source="CVE">CVE-2001-0779</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="uft-16" comment="File rpc.yppasswdd exists" negate="false"/>
          <criterion test_ref="spt-224" comment="Patch 111590-02 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-7" comment="rpc.yppasswdd running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL103" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>Locator service</product>
      </affected>
      <dates>
        <submitted date="2003-08-27-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in the RPC Locator service for Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows local users to execute arbitrary code via an RPC call to the service containing certain parameter information.</description>
      <reference source="CVE">CVE-2003-0003</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" negate="false"/>
          <criterion test_ref="wrt-43" comment="this is an NT Terminal Server" negate="true"/>
          <criterion test_ref="wft-233" comment="the version of locator.exe is less than 4.0.1381.7202" negate="false"/>
          <criterion test_ref="wrt-272" comment="Patch Q810833 Installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-273" comment="Locator Enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL106" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Ethereal</product>
      </affected>
      <dates>
        <submitted date="2003-08-29-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Ethereal 0.9.12 and earlier does not handle certain strings properly, with unknown consequences, in the (1) BGP, (2) WTP, (3) DNS, (4) 802.11, (5) ISAKMP, (6) WSP, (7) CLNP, (8) ISIS, and (9) RMI dissectors.</description>
      <reference source="CVE">CVE-2003-0432</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="cmp-238" comment="Vulnerable Config" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL107" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Ximian Evolution</product>
      </affected>
      <dates>
        <submitted date="2003-08-11-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>The try_uudecoding function in mail-format.c for Ximian Evolution Mail User Agent 1.2.2 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a malicious uuencoded (UUE) header, possibly triggering a heap-based buffer overflow.</description>
      <reference source="CVE">CVE-2003-0128</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-209" comment="evolution version is less than 1.2.2-5" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL108" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Ximian Evolution</product>
      </affected>
      <dates>
        <submitted date="2003-08-11-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Ximian Evolution Mail User Agent 1.2.2 and earlier allows remote attackers to cause a denial of service (memory consumption) via a mail message that is uuencoded multiple times.</description>
      <reference source="CVE">CVE-2003-0129</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-209" comment="evolution version is less than 1.2.2-5" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL109" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Windows 2000</product>
      </affected>
      <dates>
        <submitted date="2003-10-10-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in ntdll.dll on Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows remote attackers to execute arbitrary code, as demonstrated via a WebDAV request to IIS 5.0.</description>
      <reference source="CVE">CVE-2003-0109</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-65" comment="Windows 2000 (sp3 or earlier) is installed" negate="false"/>
          <criterion test_ref="wft-234" comment="the version of ntdll.dll is less than 5.0.2195.6685" negate="false"/>
          <criterion test_ref="wrt-274" comment="the patch q815021 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL111" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Ximian Evolution</product>
      </affected>
      <dates>
        <submitted date="2003-08-11-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>The handle_image function in mail-format.c for Ximian Evolution Mail User Agent 1.2.2 and earlier does not properly escape HTML characters, which allows remote attackers inject arbitrary data and HTML via a MIME Content-ID header in a MIME-encoded image.</description>
      <reference source="CVE">CVE-2003-0130</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-209" comment="evolution version is less than 1.2.2-5" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL112" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>GDM</product>
      </affected>
      <dates>
        <submitted date="2003-09-04-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <status_change date="2004-05-05-12:00">ACCEPTED</status_change>
      </dates>
      <description>GDM before 2.4.1.6, when using the "examine session errors" feature, allows local users to read arbitrary files via a symlink attack on the ~/.xsession-errors file.</description>
      <reference source="CVE">CVE-2003-0547</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-210" comment="gdm version is less than 2.4.1.3-5.1" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL113" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>GDM</product>
      </affected>
      <dates>
        <submitted date="2003-09-04-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <status_change date="2004-05-05-12:00">ACCEPTED</status_change>
      </dates>
      <description>The X Display Manager Control Protocol (XDMCP) support for GDM before 2.4.1.6 allows attackers to cause a denial of service (daemon crash) when a chosen host expires, a different issue than CVE-2003-0549.</description>
      <reference source="CVE">CVE-2003-0548</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-210" comment="gdm version is less than 2.4.1.3-5.1" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL114" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>snmpdx</product>
      </affected>
      <dates>
        <submitted date="2002-10-17-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Format string vulnerability in the logging component of snmpdx for Solaris 5.6 through 8 allows remote attackers to gain root privileges.</description>
      <reference source="CVE">CVE-2002-0796</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="uft-9" comment="File snmpdx exists" negate="false"/>
          <criterion test_ref="spt-215" comment="Patch 107709-19 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-6" comment="snmpdx running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL117" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>ISA Server 2000</product>
      </affected>
      <dates>
        <submitted date="2003-10-03-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <status_change date="2004-03-09-12:00">ACCEPTED</status_change>
      </dates>
      <description>Cross-site scripting (XSS) vulnerability in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to inject arbitrary web script via a URL containing the script in the domain name portion, which is not properly cleansed in the default error pages (1) 500.htm for "500 Internal Server error" or (2) 404.htm for "404 Not Found."</description>
      <reference source="CVE">CVE-2003-0526</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-105" comment="ISA Server 2000 is installed" negate="false"/>
          <criterion test_ref="wrt-276" comment="ISA2000-KB816456-x86.exe" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL118" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>SMB (Server Message Block)</product>
      </affected>
      <dates>
        <submitted date="2003-09-08-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <status_change date="2004-03-09-12:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the SMB capability for Microsoft Windows XP, 2000, and NT allows remote attackers to cause a denial of service and possibly execute arbitrary code via an SMB packet that specifies a smaller buffer length than is required.</description>
      <reference source="CVE">CVE-2003-0345</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-65" comment="Windows 2000 (sp3 or earlier) is installed" negate="false"/>
          <criterion test_ref="wft-235" comment="File %windir%\system32\Drivers\SRV.SYS is less than 5.0.2195.6699" negate="false"/>
          <criterion test_ref="wrt-277" comment="Patch Windows2000-KB817606-x86-ENU.exe Installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL120" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>kcms_server</product>
      </affected>
      <dates>
        <submitted date="2003-01-30-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Directory traversal vulnerability in Sun Kodak Color Management System (KCMS) library service daemon (kcms_server) allows remote attackers to read arbitrary files via the KCS_OPEN_PROFILE procedure.</description>
      <reference source="CVE">CVE-2003-0027</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="uft-20" comment="File kcms_server exists" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-206" comment="inetd.conf contains kcms_server" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
          <criterion test_ref="cmp-255" comment="File kcms_server executable and SUID or SGID" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL121" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>SQL Server 2000</product>
      </affected>
      <dates>
        <submitted date="2003-10-10-12:00">
          <contributor organization="The MITRE Corporation">Yi-Fang Koh</contributor>
        </submitted>
        <modified date="2005-04-08-10:31" comment="modified wft-237 - literal string corrected">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <modified date="2005-04-08-10:31" comment="modified wft-236 - corrected literal string">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <modified date="2005-04-08-10:31" comment="modified wft-65 - Corrected literal string">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <modified date="2005-04-08-10:31" comment="modified wft-66 - corrected literal string">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <modified date="2005-04-08-10:31" comment="modified wft-67 - Corrected literal string">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <modified date="2005-04-08-10:32" comment="modified wft-68 - Corrected literal string">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <modified date="2005-04-08-10:33" comment="modified wft-69 - corrected literal string">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <status_change date="2005-04-11-08:48">INTERIM</status_change>
        <status_change date="2005-04-27-12:07">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflows in extended stored procedures for Microsoft SQL Server 7.0 and 2000 allow remote attackers to cause a denial of service or execute arbitrary code via a database query with certain long arguments.</description>
      <reference source="CVE">CVE-2002-0154</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-260" comment="SQL Server 2000 is installed" negate="false"/>
          <criterion test_ref="wft-236" comment="the version of sqlservr.exe is less than 2000.80.608.0" negate="false"/>
          <criterion test_ref="wft-237" comment="the version of odsole70.dll is less than 2000.80.606.0" negate="false"/>
          <criterion test_ref="wft-65" comment="the version of xpqueue.dll is less than 2000.80.606.0" negate="false"/>
          <criterion test_ref="wft-66" comment="the version of xprepl.dll is less than 2000.80.606.0" negate="false"/>
          <criterion test_ref="wft-67" comment="the version of xplog70.dll is less than 2000.80.606.0" negate="false"/>
          <criterion test_ref="wft-68" comment="the version of xpweb70.dll is less than 2000.80.606.0" negate="false"/>
          <criterion test_ref="wft-69" comment="the version of xpstar.dll is less than 2000.80.628.0" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL123" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Windows 2000</product>
      </affected>
      <dates>
        <submitted date="2003-11-12-05:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <modified date="2004-03-04-05:00" comment="Added the configuration check to see if ActiveX controls are enabled by the current user when local machine settings are not in use.">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </modified>
        <status_change date="2004-03-25-05:00">ACCEPTED</status_change>
        <modified date="2005-09-20-04:00" comment="modified wrt-18 - Changed value element to include pattern match">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-21-01:27">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 5.01 through 6.0 does not properly handle object tags returned from a Web server during XML data binding, which allows remote attackers to execute arbitrary code via an HTML e-mail message or web page.</description>
      <reference source="CVE">CVE-2003-0809</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-256" comment="Internet Explorer 6.0 or IE 6.0 SP1 is installed" negate="false"/>
          <criterion test_ref="wft-238" comment="the version of mshtml.dll is less than 6.0.2800.1264" negate="false"/>
          <criterion test_ref="wrt-212" comment="the patch q828750 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-19" comment="the patch q824145 is installed (Installed Components key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-75" comment="ActiveX controls are enabled" negate="false"/>
          <criterion test_ref="wrt-280" comment=".hta applications are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL124" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>cachefsd</product>
      </affected>
      <dates>
        <submitted date="2002-10-17-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
        <modified date="2005-01-28-12:00" comment="Added patch test">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </modified>
        <status_change date="2005-02-01-08:29">INTERIM</status_change>
        <status_change date="2005-02-16-12:00">ACCEPTED</status_change>
      </dates>
      <description>Heap-based buffer overflow in cfsd_calloc function of Solaris cachefsd allows remote attackers to execute arbitrary code via a request with a long directory and cache name.</description>
      <reference source="CVE">CVE-2002-0033</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="uft-12" comment="File cachefsd exists" negate="false"/>
          <criterion test_ref="spt-109" comment="Patch 108800-02 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-203" comment="inetd.conf contains cachefsd" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
          <criterion test_ref="cmp-217" comment="File cachefsd executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL126" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Internet Explorer 6.0</product>
      </affected>
      <dates>
        <submitted date="2004-01-27-05:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <modified date="2005-09-20-04:00" comment="Changed IE registry test to wrt-18">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-21-01:27">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Internet Explorer 5.5 and 6.0 allows remote attackers to bypass the cross-domain security model to run malicious script or arbitrary programs via dialog boxes, aka "Improper Cross Domain Security Validation with dialog box."</description>
      <reference source="CVE">CVE-2003-1326</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wft-216" comment="the version of mshtml.dll is less than 6.0.2723.2500" negate="false"/>
          <criterion test_ref="wrt-208" comment="the patch q810847 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-209" comment="the patch q813489 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-210" comment="the patch q818529 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-211" comment="the patch q822925 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-212" comment="the patch q828750 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-19" comment="the patch q824145 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-18" comment="Internet Explorer 6 is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL127" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Remote Procedure Call (RPC)</product>
      </affected>
      <dates>
        <submitted date="2003-09-15-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <status_change date="2004-03-09-12:00">ACCEPTED</status_change>
      </dates>
      <description>Heap-based buffer overflow in the Distributed Component Object Model (DCOM) interface in the RPCSS Service allows remote attackers to execute arbitrary code via a malformed RPC request with a long filename parameter, a different vulnerability than CVE-2003-0352 (Blaster/Nachi) and CVE-2003-0715.</description>
      <reference source="CVE">CVE-2003-0528</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
          <criterion test_ref="wft-239" comment="the version of rpcrt4.dll is less than 5.0.2195.6802" negate="false"/>
          <criterion test_ref="wrt-281" comment="the patch kb824146 is installed (Hotfix key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-7" comment="DCOM is enabled on systems with SP3 or later" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL129" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>GDM</product>
      </affected>
      <dates>
        <submitted date="2003-09-04-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <status_change date="2004-05-05-12:00">ACCEPTED</status_change>
      </dates>
      <description>The X Display Manager Control Protocol (XDMCP) support for GDM before 2.4.1.6 allows attackers to cause a denial of service (daemon crash) via a short authorization key name.</description>
      <reference source="CVE">CVE-2003-0549</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-210" comment="gdm version is less than 2.4.1.3-5.1" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL130" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Internet Information Server 5.0</product>
      </affected>
      <dates>
        <submitted date="2004-01-14-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <status_change date="2004-03-09-12:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the ism.dll ISAPI extension that implements HTR scripting in Internet Information Server (IIS) 4.0 and 5.0 allows attackers to cause a denial of service or execute arbitrary code via HTR requests with long variable names.</description>
      <reference source="CVE">CVE-2002-0071</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-223" comment="IIS major version equals 5" negate="false"/>
          <criterion test_ref="wrt-215" comment="IIS minor version equals 0" negate="false"/>
          <criterion test_ref="wft-205" comment="the version of w3svc.dll is less than 5.0.2195.5269" negate="false"/>
          <criterion test_ref="wrt-217" comment="Patch Q319733 Installed" negate="true"/>
          <criterion test_ref="wrt-218" comment="Patch Q327696 Installed" negate="true"/>
          <criterion test_ref="wrt-219" comment="Patch Q811114 Installed" negate="true"/>
          <criterion test_ref="wrt-224" comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wmt-203" comment="ism.dll mapping exists" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL131" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>xlock</product>
      </affected>
      <dates>
        <submitted date="2002-10-17-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Heap overflow in xlock in Solaris 2.6 through 8 allows local users to gain root privileges via a long (1) XFILESEARCHPATH or (2) XUSERFILESEARCHPATH environmental variable.</description>
      <reference source="CVE">CVE-2001-0652</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="uft-8" comment="File xlock exists" negate="false"/>
          <criterion test_ref="spt-225" comment="Patch 108376-30 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-209" comment="File xlock SUID and executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL132" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>Internet Information Server 4.0</product>
      </affected>
      <dates>
        <submitted date="2004-01-14-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <status_change date="2004-03-09-12:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in ASP Server-Side Include Function in IIS 4.0, 5.0 and 5.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via long file names.</description>
      <reference source="CVE">CVE-2002-0149</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-214" comment="IIS 4.0 Major Version" negate="false"/>
          <criterion test_ref="wrt-215" comment="IIS minor version equals 0" negate="false"/>
          <criterion test_ref="wrt-43" comment="this is an NT Terminal Server" negate="true"/>
          <criterion test_ref="wft-202" comment="the version of w3svc.dll is less than 4.2.775.1" negate="false"/>
          <criterion test_ref="wrt-217" comment="Patch Q319733 Installed" negate="true"/>
          <criterion test_ref="wrt-218" comment="Patch Q327696 Installed" negate="true"/>
          <criterion test_ref="wrt-219" comment="Patch Q811114 Installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wmt-201" comment="asp.dll mapping exists" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL133" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>GNU Ghostscript</product>
      </affected>
      <dates>
        <submitted date="2003-08-20-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Unknown vulnerability in GNU Ghostscript before 7.07 allows attackers to execute arbitrary commands, even when -dSAFER is enabled, via a PostScript file that causes the commands to be executed from a malicious print job.</description>
      <reference source="CVE">CVE-2003-0354</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-211" comment="ghostscript version is less than 7.05-32.1" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-262" comment="/usr/bin/gs is executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL134" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Windows Script Engine for Jscript</product>
      </affected>
      <dates>
        <submitted date="2004-11-02-12:00"/>
        <status_change date="2004-11-03-12:00">DRAFT</status_change>
        <status_change date="2004-12-09-12:00">INTERIM</status_change>
        <status_change date="2005-01-06-12:00">ACCEPTED</status_change>
        <modified date="2005-06-02-12:00" comment="Added product">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-06-08-03:17">INTERIM</status_change>
        <status_change date="2005-06-29-06:49">ACCEPTED</status_change>
      </dates>
      <description>Integer overflow in JsArrayFunctionHeapSort function used by Windows Script Engine for JScript (JScript.dll) on various Windows operating system allows remote attackers to execute arbitrary code via a malicious web page or HTML e-mail that uses a large array index value that enables a heap-based buffer overflow attack.</description>
      <reference source="CVE">CVE-2003-0010</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1157" comment="jscript.dll version is 5.1, 5.5, or 5.6 " negate="false"/>
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
          <criterion test_ref="cmp-1156" comment="The patch js56nen.exe is installed for version 5.1, 5.5, or 5.6" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL135" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>GnuPG</product>
      </affected>
      <dates>
        <submitted date="2003-08-19-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>The key validation code in GnuPG before 1.2.2 does not properly determine the validity of keys with multiple user IDs and assigns the greatest validity of the most valid user ID, which prevents GnuPG from warning the encrypting user when a user ID does not have a trusted path.</description>
      <reference source="CVE">CVE-2003-0255</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-212" comment="gnupg version is less than 1.2.1-4" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-263" comment="/usr/bin/gnupg is executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL136" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 98</windows:platform>
        <windows:platform>Microsoft Windows ME</windows:platform>
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Virtual Machine (VM)</product>
      </affected>
      <dates>
        <submitted date="2004-04-30-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <status_change date="2004-05-25-12:00">INTERIM</status_change>
        <status_change date="2004-06-16-12:00">ACCEPTED</status_change>
      </dates>
      <description>The ByteCode Verifier component of Microsoft Virtual Machine (VM) build 5.0.3809 and earlier, as used in Windows and Internet Explorer, allows remote attackers to bypass security checks and execute arbitrary code via a malicious Java applet, aka "Flaw in Microsoft VM Could Enable System Compromise."</description>
      <reference source="CVE">CVE-2003-0111</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wft-301" comment="the version of msjava.dll is less than 5.0.3810.0" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL137" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>Internet Information Server 4.0</product>
      </affected>
      <dates>
        <submitted date="2004-01-14-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <status_change date="2004-03-09-12:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in Internet Information Server (IIS) 4.0, 5.0, and 5.1 allows remote attackers to spoof the safety check for HTTP headers and cause a denial of service or execute arbitrary code via HTTP header field values.</description>
      <reference source="CVE">CVE-2002-0150</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-214" comment="IIS 4.0 Major Version" negate="false"/>
          <criterion test_ref="wrt-215" comment="IIS minor version equals 0" negate="false"/>
          <criterion test_ref="wrt-43" comment="this is an NT Terminal Server" negate="true"/>
          <criterion test_ref="wft-202" comment="the version of w3svc.dll is less than 4.2.775.1" negate="false"/>
          <criterion test_ref="wrt-217" comment="Patch Q319733 Installed" negate="true"/>
          <criterion test_ref="wrt-218" comment="Patch Q327696 Installed" negate="true"/>
          <criterion test_ref="wrt-219" comment="Patch Q811114 Installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wmt-201" comment="asp.dll mapping exists" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL138" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>GtkHTML</product>
      </affected>
      <dates>
        <submitted date="2003-09-02-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <status_change date="2004-05-05-12:00">ACCEPTED</status_change>
      </dates>
      <description>GtkHTML, as included in Evolution before 1.2.4, allows remote attackers to cause a denial of service (crash) via certain malformed messages.</description>
      <reference source="CVE">CVE-2003-0133</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-213" comment="gtkhtml version is less than 1.1.9-0.9" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL139" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>Simple Network Management Protocol (SNMP)</product>
      </affected>
      <dates>
        <submitted date="2004-06-08-12:00">
          <contributor organization="The MITRE Corporation">Matt Busby</contributor>
        </submitted>
        <status_change date="2004-06-30-12:00">INTERIM</status_change>
        <status_change date="2004-07-12-12:00">ACCEPTED</status_change>
      </dates>
      <description>The default permissions for the SNMP Parameters registry key in Windows NT 4.0 allows remote attackers to read and possibly modify the SNMP community strings to obtain sensitive information or modify network configuration, aka one of the "Registry Permissions" vulnerabilities.</description>
      <reference source="CVE">CVE-2001-0046</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" negate="false"/>
          <criterion test_ref="cmp-1011" comment="For Windows NT 4.0 Workstation, Server and Enterprise Edition" negate="false"/>
          <criterion test_ref="cmp-1012" comment="For Terminal Server" negate="false"/>
          <criterion test_ref="wrt-454" comment="Patch Q265714 Installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-264" comment="the SNMP service is enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL140" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>Microsoft Transaction Server (MTS)</product>
      </affected>
      <dates>
        <submitted date="2004-06-08-12:00">
          <contributor organization="The MITRE Corporation">Matt Busby</contributor>
        </submitted>
        <status_change date="2004-06-30-12:00">INTERIM</status_change>
        <status_change date="2004-07-12-12:00">ACCEPTED</status_change>
      </dates>
      <description>The default permissions for the MTS Package Administration registry key in Windows NT 4.0 allows local users to install or modify arbitrary Microsoft Transaction Server (MTS) packages and gain privileges, aka one of the "Registry Permissions" vulnerabilities.</description>
      <reference source="CVE">CVE-2001-0047</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" negate="false"/>
          <criterion test_ref="cmp-1011" comment="For Windows NT 4.0 Workstation, Server and Enterprise Edition" negate="false"/>
          <criterion test_ref="cmp-1012" comment="For Terminal Server" negate="false"/>
          <criterion test_ref="wrt-454" comment="Patch Q265714 Installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-455" comment="MTS Enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL141" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Internet Explorer 5.01, Internet Explorer 5.01 Service Pack 1</product>
      </affected>
      <dates>
        <submitted date="2003-07-18-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <modified date="2004-03-04-12:00" comment="Added the configuration check to see if file downloads are enabled by the current user when local machine settings are not in use.  Changed the status from ACCEPTED to INTERIM">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <status_change date="2004-03-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>HTML e-mail feature in Internet Explorer 5.5 and earlier allows attackers to execute attachments by setting an unusual MIME type for the attachment, which Internet Explorer does not process correctly.</description>
      <reference source="CVE">CVE-2001-0154</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-264" comment="Internet Explorer 5.01 Installed" negate="false"/>
          <criterion test_ref="wft-240" comment="File %windir%\system32\shdocvw.dll version is less than 5.0.3214.2000" negate="false"/>
          <criterion test_ref="wrt-284" comment="the patch q290108 is installed" negate="true"/>
          <criterion test_ref="wrt-285" comment="the patch q295106 is installed" negate="true"/>
          <criterion test_ref="wrt-250" comment="Win2K/XP/2003 service pack 2 is installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-265" comment="file downloads are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL142" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>Windows kernel</product>
      </affected>
      <dates>
        <submitted date="2004-11-02-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2004-11-03-12:00">DRAFT</status_change>
        <status_change date="2004-12-09-12:00">INTERIM</status_change>
        <status_change date="2005-01-06-12:00">ACCEPTED</status_change>
        <modified date="2005-06-02-12:00" comment="Added product">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-06-08-03:17">INTERIM</status_change>
        <status_change date="2005-06-29-06:49">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in Windows Kernel allows local users to gain privileges by causing certain error messages to be passed to a debugger.</description>
      <reference source="CVE">CVE-2003-0112</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" negate="false"/>
          <criterion test_ref="wrt-536" comment="Windows NT Service Pack 6a is installed" negate="true"/>
          <criterion test_ref="wft-436" comment="The version of Ntoskrnl.exe is less than 4.0.1381.7203" negate="false"/>
          <criterion test_ref="wrt-478" comment="the patch Q811493 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL143" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Internet Explorer 6.0</product>
      </affected>
      <dates>
        <submitted date="2004-01-27-05:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <modified date="2005-09-20-04:00" comment="Changed IE registry test to wrt-18">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-21-01:27">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 5.01 through 6.0 does not properly perform security checks on certain encoded characters within a URL, which allows a remote attacker to steal potentially sensitive information from a user by redirecting the user to another site that has that information, aka "Encoded Characters Information Disclosure."</description>
      <reference source="CVE">CVE-2002-1186</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wft-241" comment="the version of mshtml.dll is less than 6.0.2722.900" negate="false"/>
          <criterion test_ref="wrt-206" comment="the patch q328970 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-207" comment="the patch q324929 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-208" comment="the patch q810847 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-209" comment="the patch q813489 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-210" comment="the patch q818529 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-211" comment="the patch q822925 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-212" comment="the patch q828750 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-19" comment="the patch q824145 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-18" comment="Internet Explorer 6 is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL144" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Simple Network Management Protocol (SNMP)</product>
      </affected>
      <dates>
        <submitted date="2003-10-10-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
      </dates>
      <description>Vulnerabilities in a large number of SNMP implementations allow remote attackers to cause a denial of service or gain privileges via SNMPv1 trap handling, as demonstrated by the PROTOS c06-SNMPv1 test suite.  NOTE: It is highly likely that this candidate will be SPLIT into multiple candidates, one or more for each vendor.  This and other SNMP-related candidates will be updated when more accurate information is available.</description>
      <reference source="CVE">CVE-2002-0012</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-65" comment="Windows 2000 (sp3 or earlier) is installed" negate="false"/>
          <criterion test_ref="wft-242" comment="the version of snmp.exe is less than 5.0.2195.4919" negate="false"/>
          <criterion test_ref="wrt-263" comment="Patch Q314147 Installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-264" comment="the SNMP service is enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL145" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>Multiple UNC Provider (MUP)</product>
      </affected>
      <dates>
        <submitted date="2003-05-13-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in Multiple UNC Provider (MUP) in Microsoft Windows operating systems allows local users to cause a denial of service or possibly gain SYSTEM privileges via a long UNC request.</description>
      <reference source="CVE">CVE-2002-0151</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" negate="false"/>
          <criterion test_ref="wrt-43" comment="this is an NT Terminal Server" negate="true"/>
          <criterion test_ref="wft-243" comment="the version of mup.sys is less than 4.0.1381.7125" negate="false"/>
          <criterion test_ref="wrt-287" comment="Patch Q312895 Installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL146" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>SMB (Server Message Block)</product>
      </affected>
      <dates>
        <submitted date="2004-11-02-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2004-11-03-12:00">DRAFT</status_change>
        <status_change date="2004-12-09-12:00">INTERIM</status_change>
        <status_change date="2005-01-06-12:00">ACCEPTED</status_change>
        <modified date="2005-06-02-12:00" comment="Added product">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-06-08-03:17">INTERIM</status_change>
        <status_change date="2005-06-29-06:49">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the SMB capability for Microsoft Windows XP, 2000, and NT allows remote attackers to cause a denial of service and possibly execute arbitrary code via an SMB packet that specifies a smaller buffer length than is required.</description>
      <reference source="CVE">CVE-2003-0345</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-569" comment="Patch Q817606 Installed" negate="true"/>
          <criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" negate="false"/>
          <criterion test_ref="wft-566" comment="The version of srv.sys is less than 4.0.1381.7214" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL147" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Windows Shell</product>
      </affected>
      <dates>
        <submitted date="2003-10-10-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <modified date="2005-09-26-10:58" comment="modified wft-244 - Changed comment to match test">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-28-01:04">INTERIM</status_change>
        <status_change date="2005-10-19-05:47">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in Windows Shell (used as the Windows Desktop) allows local and possibly remote attackers to execute arbitrary code via a custom URL handler that has not been removed for an application that has been improperly uninstalled.</description>
      <reference source="CVE">CVE-2002-0070</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-65" comment="Windows 2000 (sp3 or earlier) is installed" negate="false"/>
          <criterion test_ref="wft-244" comment="the version of shell32.dll is less than 5.0.3502.4718" negate="false"/>
          <criterion test_ref="wrt-288" comment="Patch Q313829 Installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL148" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>GtkHTML</product>
      </affected>
      <dates>
        <submitted date="2003-09-10-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>gtkhtml before 1.1.10, as used in Evolution, allows remote attackers to cause a denial of service (crash) via a malformed message that causes a null pointer dereference.</description>
      <reference source="CVE">CVE-2003-0541</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-214" comment="gtkhtml version is less than 1.1.9-0.9.1" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-266" comment="/usr/bin/evolution is executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL149" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>fs.auto, xfs</product>
      </affected>
      <dates>
        <submitted date="2003-09-08-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in Dispatch() routine for XFS font server (fs.auto) on Solaris 2.5.1 through 9 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a certain XFS query.</description>
      <reference source="CVE">CVE-2002-1317</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="uft-21" comment="File fs.auto exists" negate="false"/>
          <criterion test_ref="uft-22" comment="File xfs exists" negate="false"/>
          <criterion test_ref="spt-226" comment="Patch 109862-03 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-207" comment="inetd.conf contains fs.auto" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
          <criterion test_ref="cmp-267" comment="File xfs executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL150" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Apache</product>
      </affected>
      <dates>
        <submitted date="2003-08-17-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Apache does not filter terminal escape sequences from its error logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related to escape sequences.</description>
      <reference source="CVE">CVE-2003-0020</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-215" comment="httpd version is less than 2.0.40-21.1" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="rlt-202" comment="httpd listening on the network" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL151" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Apache</product>
      </affected>
      <dates>
        <submitted date="2003-08-17-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Apache 1.3 before 1.3.25 and Apache 2.0 before version 2.0.46 does not filter terminal escape sequences from its access logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related to escape sequences, a different vulnerability than CVE-2003-0020.</description>
      <reference source="CVE">CVE-2003-0083</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-215" comment="httpd version is less than 2.0.40-21.1" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="rlt-202" comment="httpd listening on the network" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL152" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>fs.auto, xfs</product>
      </affected>
      <dates>
        <submitted date="2003-09-08-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in Dispatch() routine for XFS font server (fs.auto) on Solaris 2.5.1 through 9 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a certain XFS query.</description>
      <reference source="CVE">CVE-2002-1317</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="uft-21" comment="File fs.auto exists" negate="false"/>
          <criterion test_ref="uft-22" comment="File xfs exists" negate="false"/>
          <criterion test_ref="spt-227" comment="Patch 108117-06 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-207" comment="inetd.conf contains fs.auto" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
          <criterion test_ref="cmp-267" comment="File xfs executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL156" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Apache</product>
      </affected>
      <dates>
        <submitted date="2003-08-17-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>A memory leak in Apache 2.0 through 2.0.44 allows remote attackers to cause a denial of service (memory consumption) via large chunks of linefeed characters, which causes Apache to allocate 80 bytes for each linefeed.</description>
      <reference source="CVE">CVE-2003-0132</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-215" comment="httpd version is less than 2.0.40-21.1" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="rlt-202" comment="httpd listening on the network" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL158" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>Windows NT 4.0</product>
      </affected>
      <dates>
        <submitted date="2003-04-04-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
      </dates>
      <description>smss.exe debugging subsystem in Windows NT and Windows 2000 does not properly authenticate programs that connect to other programs, which allows local users to gain administrator or SYSTEM privileges by duplicating a handle to a privileged process, as demonstrated by DebPloit.</description>
      <reference source="CVE">CVE-2002-0367</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" negate="false"/>
          <criterion test_ref="wrt-43" comment="this is an NT Terminal Server" negate="true"/>
          <criterion test_ref="wft-245" comment="the version of smss.exe is less than 4.0.1381.7152" negate="false"/>
          <criterion test_ref="wrt-262" comment="Patch Q320206 Installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL159" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>Windows NT 4.0</product>
      </affected>
      <dates>
        <submitted date="2003-05-13-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
      </dates>
      <description>In Microsoft Windows NT and Windows 2000, a trusting domain that receives authorization information from a trusted domain does not verify that the trusted domain is authoritative for all listed SIDs, which could allows remote attackers to gain Domain Administrator privileges on the trusting domain by injecting SIDs from untrusted domains into the authorization data that comes from from the trusted domain.</description>
      <reference source="CVE">CVE-2002-0018</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" negate="false"/>
          <criterion test_ref="wrt-43" comment="this is an NT Terminal Server" negate="true"/>
          <criterion test_ref="wft-246" comment="the version of netlogon.dll is less than 4.0.1381.7092" negate="false"/>
          <criterion test_ref="wrt-243" comment="Windows NT 4.0 Security Roll-up Package" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL161" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>Simple Network Management Protocol (SNMP)</product>
      </affected>
      <dates>
        <submitted date="2003-10-10-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
      </dates>
      <description>Vulnerabilities in a large number of SNMP implementations allow remote attackers to cause a denial of service or gain privileges via SNMPv1 trap handling, as demonstrated by the PROTOS c06-SNMPv1 test suite.  NOTE: It is highly likely that this candidate will be SPLIT into multiple candidates, one or more for each vendor.  This and other SNMP-related candidates will be updated when more accurate information is available.</description>
      <reference source="CVE">CVE-2002-0012</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" negate="false"/>
          <criterion test_ref="wrt-43" comment="this is an NT Terminal Server" negate="true"/>
          <criterion test_ref="wft-228" comment="the version of snmp.exe is less than 4.0.1381.7134" negate="false"/>
          <criterion test_ref="wrt-263" comment="Patch Q314147 Installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-264" comment="the SNMP service is enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL164" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>OpenSSL</product>
      </affected>
      <dates>
        <submitted date="2005-06-14-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2005-06-15-09:48">DRAFT</status_change>
        <status_change date="2005-07-27-10:37">INTERIM</status_change>
        <status_change date="2005-08-18-07:37">ACCEPTED</status_change>
      </dates>
      <description>The der_chop script in the openssl package in Trustix Secure Linux 1.5 through 2.1 and other operating systems allows local users to overwrite files via a symlink attack on temporary files.</description>
      <reference source="CVE">CVE-2004-0975</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="cmp-22" comment="openssl, openssl-devel, OR openssl-perl older than 0.9.7a-33.15 or openssl096b older than 0.9.6b-16.22.3" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="upt-1" comment="/tmp is writable by everyone" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL167" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Outlook Express</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-04:00">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </submitted>
        <status_change date="2005-08-19-10:05">DRAFT</status_change>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Stack-based buffer overflow in the news reader for Microsoft Outlook Express (MSOE.DLL) 5.5 SP2, 6, and 6 SP1 allows remote malicious NNTP servers to execute arbitrary code via a LIST response with a long second field.</description>
      <reference source="CVE">CVE-2005-1213</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-172" comment="Outlook Express 6 for Windows 2003 is installed" negate="false"/>
          <criterion test_ref="wft-83" comment="the version of inetcomm.dll is less than 6.0.3790.326" negate="false"/>
          <criterion test_ref="wrt-58" comment="Patch KB897715 Installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL169" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Apache</product>
      </affected>
      <dates>
        <submitted date="2003-09-05-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Apache 2 before 2.0.47, and certain versions of mod_ssl for Apache 1.3, do not properly handle "certain sequences of per-directory renegotiations and the SSLCipherSuite directive being used to upgrade from a weak ciphersuite to a strong one," which could cause Apache to use the weak ciphersuite.</description>
      <reference source="CVE">CVE-2003-0192</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-216" comment="httpd version is less than 2.0.40-21.5" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="rlt-203" comment="httpd.worker is listening on the network" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL173" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Apache</product>
      </affected>
      <dates>
        <submitted date="2003-09-05-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>The prefork MPM in Apache 2 before 2.0.47 does not properly handle certain errors from accept, which could lead to a denial of service.</description>
      <reference source="CVE">CVE-2003-0253</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-216" comment="httpd version is less than 2.0.40-21.5" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="rlt-202" comment="httpd listening on the network" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL175" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>CDE</product>
      </affected>
      <dates>
        <submitted date="2003-01-29-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>CDE ToolTalk database server (ttdbserver) allows local users to overwrite arbitrary files via a symlink attack on the transaction log file used by the _TT_TRANSACTION RPC procedure.</description>
      <reference source="CVE">CVE-2002-0678</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="uft-11" comment="File rpc.ttdbserverd exists" negate="false"/>
          <criterion test_ref="spt-206" comment="Patch 110286-09 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-202" comment="inetd.conf contains rpc.ttdbserverd" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
          <criterion test_ref="cmp-211" comment="File rpc.ttdbserverd executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL177" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>CDE</product>
      </affected>
      <dates>
        <submitted date="2003-01-29-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in Common Desktop Environment (CDE) ToolTalk RPC database server (rpc.ttdbserverd) allows remote attackers to execute arbitrary code via an argument to the _TT_CREATE_FILE procedure.</description>
      <reference source="CVE">CVE-2002-0679</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="uft-11" comment="File rpc.ttdbserverd exists" negate="false"/>
          <criterion test_ref="spt-228" comment="Patch 107893-20 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-202" comment="inetd.conf contains rpc.ttdbserverd" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
          <criterion test_ref="cmp-211" comment="File rpc.ttdbserverd executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL178" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Internet Explorer 5.5</product>
      </affected>
      <dates>
        <submitted date="2004-01-27-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
      </dates>
      <description>Microsoft Internet Explorer 5.5 and 6.0 allows remote attackers to bypass the cross-domain security model to run malicious script or arbitrary programs via dialog boxes, aka "Improper Cross Domain Security Validation with dialog box."</description>
      <reference source="CVE">CVE-2003-1326</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-271" comment="Internet Explorer 5.5 Installed" negate="false"/>
          <criterion test_ref="wft-247" comment="the version of mshtml.dll is less than 5.50.4923.2500" negate="false"/>
          <criterion test_ref="wrt-208" comment="the patch q810847 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-252" comment="the patch q813489 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-210" comment="the patch q818529 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-211" comment="the patch q822925 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-212" comment="the patch q828750 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-19" comment="the patch q824145 is installed (Installed Components key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL179" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>lbxproxy</product>
      </affected>
      <dates>
        <submitted date="2002-10-17-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in Low BandWidth X proxy (lbxproxy) in Solaris 8 allows local users to execute arbitrary code via a long display command line option.</description>
      <reference source="CVE">CVE-2002-0090</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="uft-19" comment="File lbxproxy exists" negate="false"/>
          <criterion test_ref="spt-229" comment="Patch 107654-10 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-247" comment="File lbxproxy SGID and executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL182" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>Internet Information Server 4.0</product>
      </affected>
      <dates>
        <submitted date="2004-01-14-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <status_change date="2004-03-09-12:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the chunked encoding transfer mechanism in IIS 4.0 and 5.0 allows attackers to execute arbitrary code via the processing of HTR request sessions, aka "Heap Overrun in HTR Chunked Encoding Could Enable Web Server Compromise."</description>
      <reference source="CVE">CVE-2002-0364</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-214" comment="IIS 4.0 Major Version" negate="false"/>
          <criterion test_ref="wrt-215" comment="IIS minor version equals 0" negate="false"/>
          <criterion test_ref="wft-248" comment="File %windir%\system32\inetsrv\ism.dll version is less than 4.2.776.1" negate="false"/>
          <criterion test_ref="wrt-289" comment="Patch Q321599 Installed" negate="true"/>
          <criterion test_ref="wrt-218" comment="Patch Q327696 Installed" negate="true"/>
          <criterion test_ref="wrt-219" comment="Patch Q811114 Installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wmt-203" comment="ism.dll mapping exists" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL183" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Apache</product>
      </affected>
      <dates>
        <submitted date="2003-09-05-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Apache 2 before 2.0.47, when running on an IPv6 host, allows attackers to cause a denial of service (CPU consumption by infinite loop) when the FTP proxy server fails to create an IPv6 socket.</description>
      <reference source="CVE">CVE-2003-0254</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-216" comment="httpd version is less than 2.0.40-21.5" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="rlt-202" comment="httpd listening on the network" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL185" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Authenticode</product>
      </affected>
      <dates>
        <submitted date="2003-10-29-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <modified date="2004-03-04-12:00" comment="Added the configuration check to see if downloading of signed ActiveX controls are enabled by the current user when local machine settings are not in use.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <modified date="2004-03-05-12:00" comment="Fixed the logic that checks for one version of the file if no sp is installed and a different version if sp1 is installed.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <status_change date="2004-03-25-12:00">ACCEPTED</status_change>
        <modified date="2004-09-13-10:18" comment="The compound test that includes SP1 or earlier has been added">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <modified date="2004-09-13-10:18" comment="">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2004-09-15-12:00">INTERIM</status_change>
        <status_change date="2004-09-29-12:00">ACCEPTED</status_change>
      </dates>
      <description>The Authenticode capability in Microsoft Windows NT through Server 2003 does not prompt the user to download and install ActiveX controls when the system is low on memory, which could allow remote attackers execute arbitrary code without user approval.</description>
      <reference source="CVE">CVE-2003-0660</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-273" comment="a vulnerable version of cryptui.dll exists" negate="false"/>
          <criterion test_ref="wrt-293" comment="Patch WindowsXP-KB823182-x86-ENU Installed" negate="true"/>
          <criterion test_ref="cmp-66" comment="Windows XP (sp1 or earlier) is installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-275" comment="downloading of signed ActiveX controls is enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL188" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Word 2000</product>
      </affected>
      <dates>
        <submitted date="2004-08-25-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <modified date="2004-08-25-10:31" comment="Added word 2000 and winword.exe information">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <modified date="2004-08-25-10:31" comment="changed to word 2000">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2004-08-25-12:00">DRAFT</status_change>
        <status_change date="2004-09-09-12:00">INTERIM</status_change>
        <status_change date="2004-09-29-12:00">ACCEPTED</status_change>
        <modified date="2005-04-11-12:00" comment="modified wft-470 - wft-470 corrected literal string">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <status_change date="2005-04-11-08:48">INTERIM</status_change>
        <status_change date="2005-04-27-12:07">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Word 2002, 2000, 97, and 98(J) does not properly check certain properties of a document, which allows attackers to bypass the macro security model and automatically execute arbitrary macros via a malicious document.</description>
      <reference source="CVE">CVE-2003-0664</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-132" comment="Word 2000 is installed" negate="false"/>
          <criterion test_ref="wft-470" comment="the version of winword.exe is less than 9.0.0.7924" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL189" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>SMB (Server Message Block)</product>
      </affected>
      <dates>
        <submitted date="2003-10-10-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <modified date="2005-03-07-12:00" comment="modified wrt-222 - changed pattern match">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-03-09-07:55">INTERIM</status_change>
        <status_change date="2005-03-29-07:59">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in SMB (Server Message Block) protocol in Microsoft Windows NT, Windows 2000, and Windows XP allows attackers to cause a denial of service (crash) via a SMB_COM_TRANSACTION packet with a request for the (1) NetShareEnum, (2) NetServerEnum2, or (3) NetServerEnum3, aka "Unchecked Buffer in Network Share Provider Can Lead to Denial of Service".</description>
      <reference source="CVE">CVE-2002-0724</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
          <criterion test_ref="wft-251" comment="the version of xactsrv.dll is less than 5.0.2195.5971" negate="false"/>
          <criterion test_ref="wrt-295" comment="Patch Q326830 Installed" negate="true"/>
          <criterion test_ref="wrt-222" comment="SP4 or later Installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-296" comment="Lanman enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL190" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Certificate Enrollment Control</product>
      </affected>
      <dates>
        <submitted date="2003-10-10-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2004-03-09-12:00">ACCEPTED</status_change>
        <modified date="2005-03-07-12:00" comment="modified wrt-222 - changed pattern match">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-03-09-07:55">INTERIM</status_change>
        <status_change date="2005-03-29-07:59">ACCEPTED</status_change>
      </dates>
      <description>Unknown vulnerability in the Certificate Enrollment ActiveX Control in Microsoft Windows 98, Windows 98 Second Edition, Windows Millennium, Windows NT 4.0, Windows 2000, and Windows XP allow remote attackers to delete digital certificates on a user's system via HTML.</description>
      <reference source="CVE">CVE-2002-0699</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
          <criterion test_ref="wft-252" comment="the version of xenroll.dll is less than 5.131.3659.0" negate="false"/>
          <criterion test_ref="wrt-297" comment="Patch Q323172 Installed" negate="true"/>
          <criterion test_ref="wrt-222" comment="SP4 or later Installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-276" comment="ActiveX Enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL191" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Internet Information Server 5.0</product>
      </affected>
      <dates>
        <submitted date="2003-10-10-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
      </dates>
      <description>IIS 5.0 allows remote attackers to execute arbitrary commands via a malformed request for an executable file whose name is appended with operating system commands, aka the "Web Server File Request Parsing" vulnerability.</description>
      <reference source="CVE">CVE-2000-0886</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-223" comment="IIS major version equals 5" negate="false"/>
          <criterion test_ref="wrt-215" comment="IIS minor version equals 0" negate="false"/>
          <criterion test_ref="wft-253" comment="File %windir%\system32\inetsrv\w3svc.dll version is less than 5.0.2195.2784" negate="false"/>
          <criterion test_ref="wrt-248" comment="Patch Q277873 Installed" negate="true"/>
          <criterion test_ref="wrt-249" comment="Patch Q293826 Installed" negate="true"/>
          <criterion test_ref="wrt-242" comment="Patch Q301625 Installed" negate="true"/>
          <criterion test_ref="wrt-217" comment="Patch Q319733 Installed" negate="true"/>
          <criterion test_ref="wrt-218" comment="Patch Q327696 Installed" negate="true"/>
          <criterion test_ref="wrt-219" comment="Patch Q811114 Installed" negate="true"/>
          <criterion test_ref="wrt-250" comment="Win2K/XP/2003 service pack 2 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL192" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>CDE</product>
      </affected>
      <dates>
        <submitted date="2003-01-29-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in Common Desktop Environment (CDE) ToolTalk RPC database server (rpc.ttdbserverd) allows remote attackers to execute arbitrary code via an argument to the _TT_CREATE_FILE procedure.</description>
      <reference source="CVE">CVE-2002-0679</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="uft-11" comment="File rpc.ttdbserverd exists" negate="false"/>
          <criterion test_ref="spt-230" comment="Patch 110286-10 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-202" comment="inetd.conf contains rpc.ttdbserverd" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
          <criterion test_ref="cmp-211" comment="File rpc.ttdbserverd executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL193" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>KDM</product>
      </affected>
      <dates>
        <submitted date="2003-09-21-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <status_change date="2004-05-05-12:00">ACCEPTED</status_change>
      </dates>
      <description>KDM in KDE 3.1.3 and earlier does not verify whether the pam_setcred function call succeeds, which may allow attackers to gain root privileges by triggering error conditions within PAM modules, as demonstrated in certain configurations of the MIT pam_krb5 module.</description>
      <reference source="CVE">CVE-2003-0690</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-217" comment="kdebase version is less than 3.1-15" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-278" comment="/usr/bin/kdm is executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL194" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>Remote Procedure Call (RPC)</product>
      </affected>
      <dates>
        <submitted date="2004-11-02-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2004-11-03-12:00">DRAFT</status_change>
        <status_change date="2004-12-09-12:00">INTERIM</status_change>
        <status_change date="2005-01-06-12:00">ACCEPTED</status_change>
        <modified date="2005-06-02-12:00" comment="Added product">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-06-08-03:17">INTERIM</status_change>
        <status_change date="2005-06-29-06:49">ACCEPTED</status_change>
        <modified date="2005-09-27-10:53" comment="modified wft-567 - Changed comment to match test">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-28-01:04">INTERIM</status_change>
        <status_change date="2005-10-19-05:47">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in a certain DCOM interface for RPC in Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary code via a malformed message, as exploited by the Blaster/MSblast/LovSAN and Nachi/Welchia worms.</description>
      <reference source="CVE">CVE-2003-0352</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-570" comment="Patch Q823980 Installed" negate="true"/>
          <criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" negate="false"/>
          <criterion test_ref="wft-567" comment="the version of rpcss.dll is less than 4.0.1381.7224" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL195" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>kcms_server</product>
      </affected>
      <dates>
        <submitted date="2003-01-24-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Directory traversal vulnerability in Sun Kodak Color Management System (KCMS) library service daemon (kcms_server) allows remote attackers to read arbitrary files via the KCS_OPEN_PROFILE procedure.</description>
      <reference source="CVE">CVE-2003-0027</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="uft-20" comment="File kcms_server exists" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-206" comment="inetd.conf contains kcms_server" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
          <criterion test_ref="cmp-255" comment="File kcms_server executable and SUID or SGID" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL197" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Internet Information Server 5.0</product>
      </affected>
      <dates>
        <submitted date="2004-01-14-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <modified date="2004-08-04-12:00" comment="Modifed without comment">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </modified>
        <status_change date="2004-08-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in ISAPI extension (idq.dll) in Index Server 2.0 and Indexing Service 2000 in IIS 6.0 beta and earlier allows remote attackers to execute arbitrary commands via a long argument to Internet Data Administration (.ida) and Internet Data Query (.idq) files such as default.ida, as commonly exploited by Code Red.</description>
      <reference source="CVE">CVE-2001-0500</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-223" comment="IIS major version equals 5" negate="false"/>
          <criterion test_ref="wrt-215" comment="IIS minor version equals 0" negate="false"/>
          <criterion test_ref="wft-254" comment="File %windir%\system32\idq.dll version is less than 5.0.2195.3645" negate="false"/>
          <criterion test_ref="wrt-299" comment="Patch Q300972 Installed" negate="true"/>
          <criterion test_ref="wrt-242" comment="Patch Q301625 Installed" negate="true"/>
          <criterion test_ref="wrt-217" comment="Patch Q319733 Installed" negate="true"/>
          <criterion test_ref="wrt-218" comment="Patch Q327696 Installed" negate="true"/>
          <criterion test_ref="wrt-219" comment="Patch Q811114 Installed" negate="true"/>
          <criterion test_ref="wrt-259" comment="Windows 2000 Security Roll-up 1 Installed" negate="true"/>
          <criterion test_ref="wrt-224" comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wmt-205" comment="idq.dll mapping exists" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL198" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Windows 2000</product>
      </affected>
      <dates>
        <submitted date="2003-10-16-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <modified date="2004-03-04-12:00" comment="Added the configuration check to see if downloading of signed ActiveX controls are enabled by the current user when local machine settings are not in use.">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </modified>
        <status_change date="2004-03-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>The Authenticode capability in Microsoft Windows NT through Server 2003 does not prompt the user to download and install ActiveX controls when the system is low on memory, which could allow remote attackers execute arbitrary code without user approval.</description>
      <reference source="CVE">CVE-2003-0660</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
          <criterion test_ref="wft-255" comment="File %windir%\system32\cryptui.dll version is less than 5.131.2195.6758" negate="false"/>
          <criterion test_ref="wrt-293" comment="Patch WindowsXP-KB823182-x86-ENU Installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-275" comment="downloading of signed ActiveX controls is enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL199" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Remote Data Protocol (RDP)</product>
      </affected>
      <dates>
        <submitted date="2003-10-10-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <modified date="2005-03-07-12:00" comment="modified wrt-222 - changed pattern match">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-03-09-07:55">INTERIM</status_change>
        <status_change date="2005-03-29-07:59">ACCEPTED</status_change>
      </dates>
      <description>Remote Data Protocol (RDP) version 5.0 in Microsoft Windows 2000 and RDP 5.1 in Windows XP does not encrypt the checksums of plaintext session data, which could allow a remote attacker to determine the contents of encrypted sessions via sniffing, aka "Weak Encryption in RDP Protocol."</description>
      <reference source="CVE">CVE-2002-0863</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-300" comment="Terminal Server Version" negate="false"/>
          <criterion test_ref="wft-256" comment="File %windir%\system32\drivers\rdpwd.sys version is less than 5.0.2195.5880" negate="false"/>
          <criterion test_ref="wrt-301" comment="Patch Q324380 installed" negate="true"/>
          <criterion test_ref="wrt-222" comment="SP4 or later Installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-302" comment="RDP Enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL200" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 98</windows:platform>
        <windows:platform>Microsoft Windows ME</windows:platform>
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Windows Script Engine for JScript v5.6</product>
      </affected>
      <dates>
        <submitted date="2003-08-27-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <modified date="2004-03-03-12:00" comment="Corrected to reflect the unification of the Windows Schema">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </modified>
        <modified date="2004-03-04-12:00" comment="Added the configuration check to see if active scripting is enabled by the current user when local machine settings are not in use.">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </modified>
        <status_change date="2004-03-25-12:00">ACCEPTED</status_change>
        <modified date="2004-08-24-10:58" comment="Added Patch to Definition">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <modified date="2004-08-24-10:58" comment="negated patch">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2004-08-26-12:00">INTERIM</status_change>
        <status_change date="2004-09-09-12:00">ACCEPTED</status_change>
      </dates>
      <description>Integer overflow in JsArrayFunctionHeapSort function used by Windows Script Engine for JScript (JScript.dll) on various Windows operating system allows remote attackers to execute arbitrary code via a malicious web page or HTML e-mail that uses a large array index value that enables a heap-based buffer overflow attack.</description>
      <reference source="CVE">CVE-2003-0010</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wft-257" comment="the version of jscript.dll is less than 5.6.0.8513" negate="false"/>
          <criterion test_ref="cmp-212" comment="Windows 2000 Service Pack 4 (or later) is installed" negate="true"/>
          <criterion test_ref="wrt-499" comment="the patch js56nen.exe (5.6.0.8513 version) is installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-76" comment="active scripting is enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL201" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Windows XP</product>
      </affected>
      <dates>
        <submitted date="2003-10-28-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <modified date="2004-03-05-12:00" comment="Fixed the logic that checks for one version of the file if no sp is installed and a different version if sp1 is installed.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <status_change date="2004-03-25-12:00">ACCEPTED</status_change>
        <modified date="2004-09-13-12:00" comment="The compound test that includes a check for SP1 or earlier has been added">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2004-09-15-12:00">INTERIM</status_change>
        <status_change date="2004-09-29-12:00">ACCEPTED</status_change>
        <modified date="2005-01-27-12:00" comment="Added patch KB891711 (from MS05-002) which supercedes the previous patch">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-01-28-09:27">INTERIM</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-02-16-07:32">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in a function in User32.dll on Windows NT through Server 2003 allows local users to execute arbitrary code via long (1) LB_DIR messages to ListBox or (2) CB_DIR messages to ComboBox controls in a privileged application.</description>
      <reference source="CVE">CVE-2003-0659</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-282" comment="a vulnerable version of user32.dll exists" negate="false"/>
          <criterion test_ref="wrt-304" comment="the patch kb824141 is installed (Hotfix key)" negate="true"/>
          <criterion test_ref="cmp-66" comment="Windows XP (sp1 or earlier) is installed" negate="false"/>
          <criterion test_ref="wrt-68" comment="the patch kb891711 is installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-305" comment="the utility manager Service is enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL202" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Word 2000</product>
      </affected>
      <dates>
        <submitted date="2004-08-24-12:00">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </submitted>
        <status_change date="2004-08-25-12:00">DRAFT</status_change>
        <status_change date="2004-09-09-12:00">INTERIM</status_change>
        <status_change date="2004-09-29-12:00">ACCEPTED</status_change>
        <modified date="2005-04-11-12:00" comment="modified wft-478 - wft-478 corrected literal string">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <status_change date="2005-04-11-08:48">INTERIM</status_change>
        <status_change date="2005-04-27-12:07">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Word and Excel allow remote attackers to steal sensitive information via certain field codes that insert the information when the document is returned to the attacker, as demonstrated in Word using (1) INCLUDETEXT or (2) INCLUDEPICTURE, aka "Flaw in Word Fields and Excel External Updates Could Lead to Information Disclosure."</description>
      <reference source="CVE">CVE-2002-1143</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
          <criterion test_ref="wrt-132" comment="Word 2000 is installed" negate="false"/>
          <criterion test_ref="wft-478" comment="the version of winword.exe is less than 9.0.0.6926" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL203" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Internet Explorer 6.0</product>
      </affected>
      <dates>
        <submitted date="2004-01-27-05:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2004-03-09-05:00">ACCEPTED</status_change>
        <modified date="2005-09-20-04:00" comment="Changed IE registry test to wrt-18">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-21-01:27">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Cross-site scripting vulnerability (XSS) in Internet Explorer 5.01 through 6.0 allows remote attackers to read and execute files on the local system via web pages using the &lt;frame> or &lt;iframe> element and javascript, aka "Frames Cross Site Scripting," as demonstrated using the PrivacyPolicy.dlg resource.</description>
      <reference source="CVE">CVE-2002-1187</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wft-241" comment="the version of mshtml.dll is less than 6.0.2722.900" negate="false"/>
          <criterion test_ref="wrt-206" comment="the patch q328970 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-207" comment="the patch q324929 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-208" comment="the patch q810847 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-209" comment="the patch q813489 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-210" comment="the patch q818529 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-211" comment="the patch q822925 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-212" comment="the patch q828750 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-19" comment="the patch q824145 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-18" comment="Internet Explorer 6 is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL204" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Windows 2000</product>
      </affected>
      <dates>
        <submitted date="2003-11-12-05:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <modified date="2004-03-04-05:00" comment="Added the configuration check to see if ActiveX controls are enabled by the current user when local machine settings are not in use.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <status_change date="2004-03-25-05:00">ACCEPTED</status_change>
        <modified date="2005-09-20-04:00" comment="modified wrt-18 - Changed value element to include pattern match">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-21-01:27">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer allows remote attackers to bypass zone restrictions to inject and execute arbitrary programs by creating a popup window and inserting ActiveX object code with a "data" tag pointing to the malicious code, which Internet Explorer treats as HTML or Javascript, but later executes as an HTA application, a different vulnerability than CVE-2003-0532, and as exploited using the QHosts Trojan horse (aka Trojan.Qhosts, QHosts-1, VBS.QHOSTS, or aolfix.exe).</description>
      <reference source="CVE">CVE-2003-0838</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-256" comment="Internet Explorer 6.0 or IE 6.0 SP1 is installed" negate="false"/>
          <criterion test_ref="wft-238" comment="the version of mshtml.dll is less than 6.0.2800.1264" negate="false"/>
          <criterion test_ref="wrt-212" comment="the patch q828750 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-19" comment="the patch q824145 is installed (Installed Components key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-75" comment="ActiveX controls are enabled" negate="false"/>
          <criterion test_ref="wrt-280" comment=".hta applications are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL205" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Word 2000</product>
      </affected>
      <dates>
        <submitted date="2004-09-06-12:00">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </submitted>
        <modified date="2004-09-07-12:00" comment="made into a real definition">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <status_change date="2004-09-08-12:00">DRAFT</status_change>
        <status_change date="2004-09-22-12:00">INTERIM</status_change>
        <status_change date="2004-10-06-12:00">ACCEPTED</status_change>
        <modified date="2005-04-11-12:00" comment="modified wft-486 - wft-486 corrected literal string">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <status_change date="2005-04-11-08:48">INTERIM</status_change>
        <status_change date="2005-04-27-12:07">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Outlook 2000 and 2002, when configured to use Microsoft Word as the email editor, does not block scripts that are used while editing email messages in HTML or Rich Text Format (RTF), which could allow remote attackers to execute arbitrary scripts via an email that the user forwards or replies to.</description>
      <reference source="CVE">CVE-2002-1056</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-132" comment="Word 2000 is installed" negate="false"/>
          <criterion test_ref="wft-486" comment="the version of winword.exe is less than 9.0.0.6328" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL206" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Internet Explorer 5.01 Service Pack 2</product>
      </affected>
      <dates>
        <submitted date="2004-07-30-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <status_change date="2004-08-02-12:00">DRAFT</status_change>
        <status_change date="2004-08-25-12:00">INTERIM</status_change>
        <status_change date="2004-09-09-12:00">ACCEPTED</status_change>
      </dates>
      <description>Double-free vulnerability in mshtml.dll for certain versions of Internet Explorer 6.x allows remote attackers to cause a denial of service (application crash) via a malformed GIF image.</description>
      <reference source="CVE">CVE-2003-1048</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-56" comment="Internet Explorer 5.01 Service Pack 2 is installed" negate="false"/>
          <criterion test_ref="wft-270" comment="the version of mshtml.dll is less than 5.0.3532.300" negate="false"/>
          <criterion test_ref="wrt-245" comment="the patch kb832894 is installed (Installed Components key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL207" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Internet Explorer 6 Service Pack 1 for Windows Server 2003</product>
      </affected>
      <dates>
        <submitted date="2004-07-30-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <status_change date="2004-08-02-12:00">DRAFT</status_change>
        <status_change date="2004-08-25-12:00">INTERIM</status_change>
        <status_change date="2004-09-09-12:00">ACCEPTED</status_change>
        <modified date="2005-05-10-12:00" comment="modified wrt-51 - Comment updated to indicate IE 6.">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </modified>
        <status_change date="2005-05-11-05:33">INTERIM</status_change>
        <status_change date="2005-06-01-03:30">ACCEPTED</status_change>
        <modified date="2005-09-26-11:00" comment="modified wft-266 - Changed comment to match test">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-28-01:04">INTERIM</status_change>
        <status_change date="2005-10-19-05:47">ACCEPTED</status_change>
      </dates>
      <description>The WebBrowser ActiveX control, or the Internet Explorer HTML rendering engine (MSHTML), as used in Internet Explorer 6, allows remote attackers to execute arbitrary code in the Local Security context by using the showModalDialog method and modifying the location to execute code such as Javascript, as demonstrated using (1) delayed HTTP redirect operations, and an HTTP response with a Location: header containing a "URL:" prepended to a "ms-its" protocol URI, or (2) modifying the location attribute of the window, as exploited by the Download.ject (aka Scob aka Toofer) using the ADODB.Stream object.</description>
      <reference source="CVE">CVE-2004-0549</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-51" comment="Internet Explorer 6  for Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wft-266" comment="the version of mshtml.dll is less than 6.0.3790.191" negate="false"/>
          <criterion test_ref="wrt-237" comment="the patch kb867801 is installed (Hotfix key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL209" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Simple Network Management Protocol (SNMP)</product>
      </affected>
      <dates>
        <submitted date="2003-12-03-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in SNMP agent service in Windows 95/98/98SE, Windows NT 4.0, Windows 2000, and Windows XP allows remote attackers to cause a denial of service or execute arbitrary code via a malformed management request.  NOTE: this candidate may be split or merged with other candidates.  This and other PROTOS-related candidates, especially CVE-2002-0012 and CVE-2002-0013, will be updated when more accurate information is available.</description>
      <reference source="CVE">CVE-2002-0053</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
          <criterion test_ref="wft-242" comment="the version of snmp.exe is less than 5.0.2195.4919" negate="false"/>
          <criterion test_ref="wrt-263" comment="Patch Q314147 Installed" negate="true"/>
          <criterion test_ref="wrt-224" comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-264" comment="the SNMP service is enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL210" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Internet Information Server 5.0</product>
      </affected>
      <dates>
        <submitted date="2003-10-10-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
      </dates>
      <description>Cross-site scripting vulnerability for Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows remote attackers to execute arbitrary script as other web users via the error message used in a URL redirect (""302 Object Moved") message.</description>
      <reference source="CVE">CVE-2002-0075</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-223" comment="IIS major version equals 5" negate="false"/>
          <criterion test_ref="wrt-215" comment="IIS minor version equals 0" negate="false"/>
          <criterion test_ref="wft-205" comment="the version of w3svc.dll is less than 5.0.2195.5269" negate="false"/>
          <criterion test_ref="wrt-217" comment="Patch Q319733 Installed" negate="true"/>
          <criterion test_ref="wrt-218" comment="Patch Q327696 Installed" negate="true"/>
          <criterion test_ref="wrt-219" comment="Patch Q811114 Installed" negate="true"/>
          <criterion test_ref="wrt-224" comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL212" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Internet Explorer 5.01 Service Pack 3</product>
      </affected>
      <dates>
        <submitted date="2004-07-30-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <status_change date="2004-08-02-12:00">DRAFT</status_change>
        <status_change date="2004-08-25-12:00">INTERIM</status_change>
        <status_change date="2004-09-09-12:00">ACCEPTED</status_change>
      </dates>
      <description>Double-free vulnerability in mshtml.dll for certain versions of Internet Explorer 6.x allows remote attackers to cause a denial of service (application crash) via a malformed GIF image.</description>
      <reference source="CVE">CVE-2003-1048</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-55" comment="Internet Explorer 5.01 Service Pack 3 is installed" negate="false"/>
          <criterion test_ref="wft-270" comment="the version of mshtml.dll is less than 5.0.3532.300" negate="false"/>
          <criterion test_ref="wrt-245" comment="the patch kb832894 is installed (Installed Components key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL213" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Messenger Service</product>
      </affected>
      <dates>
        <submitted date="2003-10-16-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2004-03-09-12:00">ACCEPTED</status_change>
        <modified date="2004-03-29-12:00" comment="Fixed an error in the configuration section, now correctly testing that messenger service is enabled.  Before it was testing that HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Messenger\Start=2, now it is testing that it does not equal 4.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <status_change date="2004-05-05-12:00">ACCEPTED</status_change>
      </dates>
      <description>The Messenger Service for Windows NT through Server 2003 does not properly verify the length of the message, which allows remote attackers to execute arbitrary code via a buffer overflow attack.</description>
      <reference source="CVE">CVE-2003-0717</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
          <criterion test_ref="wft-122" comment="the version of msgsvc.dll is less than 5.0.2195.6861" negate="false"/>
          <criterion test_ref="wft-260" comment="the version of wkssvc.dll is less than 5.0.2195.6861" negate="false"/>
          <criterion test_ref="wrt-83" comment="the patch q828035 is installed (Hotfix key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-307" comment="the messenger service is enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL215" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>KDM</product>
      </affected>
      <dates>
        <submitted date="2003-09-21-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <status_change date="2004-05-05-12:00">ACCEPTED</status_change>
      </dates>
      <description>KDM in KDE 3.1.3 and earlier uses a weak session cookie generation algorithm that does not provide 128 bits of entropy, which allows attackers to guess session cookies via brute force methods and gain access to the user session.</description>
      <reference source="CVE">CVE-2003-0692</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-217" comment="kdebase version is less than 3.1-15" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-278" comment="/usr/bin/kdm is executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL216" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Internet Explorer 5.01 Service Pack 4</product>
      </affected>
      <dates>
        <submitted date="2004-07-30-12:00">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </submitted>
        <status_change date="2004-08-02-12:00">DRAFT</status_change>
        <status_change date="2004-08-25-12:00">INTERIM</status_change>
        <status_change date="2004-09-09-12:00">ACCEPTED</status_change>
        <modified date="2005-09-26-12:21" comment="modified wft-279 - Changed comment to match test">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-28-01:04">INTERIM</status_change>
        <status_change date="2005-10-19-05:47">ACCEPTED</status_change>
      </dates>
      <description>Integer overflow in imgbmp.cxx for Windows 2000 allows remote attackers to execute arbitrary code via a BMP image with a large bfOffBits value.</description>
      <reference source="CVE">CVE-2004-0566</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-54" comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false"/>
          <criterion test_ref="wft-279" comment="the version of mshtml.dll is less than 5.0.3819.300" negate="false"/>
          <criterion test_ref="wrt-245" comment="the patch kb832894 is installed (Installed Components key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL217" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Help and Support Center (HSC)</product>
      </affected>
      <dates>
        <submitted date="2003-10-16-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2004-03-09-12:00">ACCEPTED</status_change>
        <modified date="2005-01-18-12:00" comment="Windows 2000 replaced by check for Windows 2000 SP4 or earlier">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-01-20-12:00">INTERIM</status_change>
        <status_change date="2005-02-16-12:00">ACCEPTED</status_change>
        <modified date="2005-06-17-12:00" comment="modified cmp-1106 - Replaced the test that checks for the service pack level, instead of checking for sp4 or ealier (did not check for GOLD edition) it is now negating the test that checks for sp5 for later.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <status_change date="2005-06-22-12:35">INTERIM</status_change>
        <status_change date="2005-07-27-10:37">ACCEPTED</status_change>
      </dates>
      <description>Stack-based buffer overflow in the PCHealth system in the Help and Support Center function in Windows XP and Windows Server 2003 allows remote attackers to execute arbitrary code via a long query in an HCP URL.</description>
      <reference source="CVE">CVE-2003-0711</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wft-261" comment="the version of itircl.dll is less than 5.2.3790.80" negate="false"/>
          <criterion test_ref="wrt-308" comment="Patch KB825119 Installed" negate="true"/>
          <criterion test_ref="cmp-1106" comment="Windows 2000 (sp4 or earlier) is installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-309" comment="HCP Protocol" negate="true"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL218" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>DirectX</product>
      </affected>
      <dates>
        <submitted date="2004-11-02-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2004-11-03-12:00">DRAFT</status_change>
        <status_change date="2004-12-09-12:00">INTERIM</status_change>
        <status_change date="2005-01-06-12:00">ACCEPTED</status_change>
        <modified date="2005-06-02-12:00" comment="Added product">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-06-08-03:17">INTERIM</status_change>
        <status_change date="2005-06-29-06:49">ACCEPTED</status_change>
      </dates>
      <description>Multiple integer overflows in a Microsoft Windows DirectX MIDI library (QUARTZ.DLL) allow remote attackers to execute arbitrary code via a MIDI (.mid) file with (1) large length for a Text or Copyright string, or (2) a large number of tracks, which leads to a heap-based buffer overflow.</description>
      <reference source="CVE">CVE-2003-0346</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" negate="false"/>
          <criterion test_ref="wft-569" comment="the version of quartz.dll is less than 6.1.5.132" negate="false"/>
          <criterion test_ref="wrt-571" comment="Patch Q19696 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL225" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Internet Explorer 5.5</product>
      </affected>
      <dates>
        <submitted date="2004-01-27-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2004-03-09-12:00">ACCEPTED</status_change>
      </dates>
      <description>Cross-site scripting vulnerability (XSS) in Internet Explorer 5.01 through 6.0 allows remote attackers to read and execute files on the local system via web pages using the &lt;frame> or &lt;iframe> element and javascript, aka "Frames Cross Site Scripting," as demonstrated using the PrivacyPolicy.dlg resource.</description>
      <reference source="CVE">CVE-2002-1187</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-271" comment="Internet Explorer 5.5 Installed" negate="false"/>
          <criterion test_ref="wft-262" comment="the version of mshtml.dll is less than 5.50.4922.900" negate="false"/>
          <criterion test_ref="wrt-206" comment="the patch q328970 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-207" comment="the patch q324929 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-208" comment="the patch q810847 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-209" comment="the patch q813489 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-210" comment="the patch q818529 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-211" comment="the patch q822925 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-212" comment="the patch q828750 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-19" comment="the patch q824145 is installed (Installed Components key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL230" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>krb5</product>
      </affected>
      <dates>
        <submitted date="2003-08-14-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived from SunRPC, including libnsl, libc, glibc, and dietlibc, allows remote attackers to execute arbitrary code via certain integer values in length fields, a different vulnerability than CVE-2002-0391.</description>
      <reference source="CVE">CVE-2003-0028</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-218" comment="krb5-server version is less than 1.2.7-14" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL231" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft SQL Server</product>
      </affected>
      <dates>
        <submitted date="2003-08-27-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <modified date="2005-04-08-05:25" comment="modified wft-85 - wft-85 corrected literal string">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <modified date="2005-04-08-05:28" comment="modified wft-86 - wft-86 corrected literal string">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <modified date="2005-04-08-05:35" comment="modified wft-87 - wft-87 corrected literal string">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <modified date="2005-04-08-05:55" comment="modified wft-88 - wft-88 corrected literal string">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <status_change date="2005-04-11-12:00">INTERIM</status_change>
        <modified date="2005-04-12-12:00" comment="modified wft-89 - wft-89 corrected literal string">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <status_change date="2005-04-27-12:07">ACCEPTED</status_change>
        <modified date="2005-09-26-12:48" comment="modified wft-85 - Changed comment to match match">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <modified date="2005-09-27-01:25" comment="modified wft-86 - Changed comment to match test">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <modified date="2005-09-27-01:26" comment="modified wft-87 - Changed comment to match test">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <modified date="2005-09-27-01:27" comment="modified wft-88 - Changed comment to match test">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <modified date="2005-09-27-01:28" comment="modified wft-89 - Changed comment to match test">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-28-01:04">INTERIM</status_change>
        <status_change date="2005-10-19-05:47">ACCEPTED</status_change>
      </dates>
      <description>The xp_displayparamstmt function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability.</description>
      <reference source="CVE">CVE-2000-1081</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-260" comment="SQL Server 2000 is installed" negate="false"/>
          <criterion test_ref="wft-85" comment="File odsole70.dll Version3 is less than 2000.80.223.0" negate="false"/>
          <criterion test_ref="wft-86" comment="File xpqueue.dll Version3 is less than 2000.80.223.0" negate="false"/>
          <criterion test_ref="wft-87" comment="File xprepl.dll Version3 is less than 2000.80.223.0" negate="false"/>
          <criterion test_ref="wft-88" comment="File xpstar.dll Version3 is less than 2000.80.223.0" negate="false"/>
          <criterion test_ref="wft-89" comment="File sqlservr.exe version3 greater than or equal to 2000.80.384.0" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL235" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>SQL Server 2000</product>
      </affected>
      <dates>
        <submitted date="2003-10-10-12:00">
          <contributor organization="The MITRE Corporation">Yi-Fang Koh</contributor>
        </submitted>
        <modified date="2005-01-14-12:00" comment="modified wft-62 - Added &quot;80&quot; to the registry component. So that new component value is HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Microsoft SQL Server\80\SharedCode. This key specifes the location of the  file that should be tested.">
          <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
        </modified>
        <status_change date="2005-01-20-12:00">INTERIM</status_change>
        <status_change date="2005-02-16-10:31">ACCEPTED</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <modified date="2005-04-08-10:31" comment="modified wft-70 - Corrected literal string">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <modified date="2005-04-08-10:32" comment="modified wft-73 - Corrected literal string">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <modified date="2005-04-08-10:33" comment="modified wft-78 - wft-78 corrected literal string">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <modified date="2005-04-08-10:34" comment="modified wft-79 - wft-79 corrected literal string">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <modified date="2005-04-08-10:35" comment="modified wft-51 - wft-51 corrected literal string">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <modified date="2005-04-08-10:36" comment="modified wft-52 - wft-52 corrected literal string">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <modified date="2005-04-08-10:37" comment="modified wft-53 - wft-53 corrected literal string">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <modified date="2005-04-08-10:38" comment="modified wft-54 - wft-54 corrected literal string">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <modified date="2005-04-08-10:39" comment="modified wft-60 - wft-60 corrected literal string">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <modified date="2005-04-08-10:45" comment="modified wft-61 - wft-61 corrected literal string">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <modified date="2005-04-08-10:56" comment="modified wft-63 - wft-63 corrected literal string">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <modified date="2005-04-08-11:52" comment="modified wft-64 - wft-64 corrected literal string">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <modified date="2005-04-08-12:00" comment="modified wft-72 - corrected literal string">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <status_change date="2005-04-11-08:48">INTERIM</status_change>
        <status_change date="2005-04-27-12:07">ACCEPTED</status_change>
        <modified date="2005-09-26-12:46" comment="modified wft-61 - Changed comment to match test">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <modified date="2005-09-27-01:21" comment="modified wft-63 - Changed comment to match test">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <modified date="2005-09-27-01:23" comment="modified wft-64 - Changed comment to match test">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <modified date="2005-09-27-01:26" comment="modified wft-73 - Changed comment to match test">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <modified date="2005-09-27-01:27" comment="modified wft-72 - Changed comment to match test">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <modified date="2005-09-27-01:28" comment="modified wft-70 - Changed comment to match test">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <modified date="2005-09-27-01:29" comment="modified wft-71 - Changed comment to match test">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-28-01:04">INTERIM</status_change>
        <status_change date="2005-10-19-05:47">ACCEPTED</status_change>
      </dates>
      <description>Microsoft SQL Server 7, 2000, and MSDE allows local users go gain privileges by hijacking a named pipe during the authentication of another user, aka the "Named Pipe Hijacking" vulnerability.</description>
      <reference source="CVE">CVE-2003-0230</reference>
      <status>ACCEPTED</status>
      <version>4</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-260" comment="SQL Server 2000 is installed" negate="false"/>
          <criterion test_ref="wft-70" comment="File console.exe version3 is less than 2000.80.818.0" negate="false"/>
          <criterion test_ref="wft-71" comment="File dbmslpcn.dll version3 is less than 2000.80.818.0" negate="false"/>
          <criterion test_ref="wft-72" comment="File sqlmap70.dll version3 is less than 2000.80.811.0" negate="false"/>
          <criterion test_ref="wft-73" comment="File sqlrepss.dll version3 is less than 2000.80.765.0" negate="false"/>
          <criterion test_ref="wft-51" comment="the version of sqlservr.exe is less than 2000.80.818.0" negate="false"/>
          <criterion test_ref="wft-52" comment="the version of ssmslpcn.dll is less than 2000.80.818.0" negate="false"/>
          <criterion test_ref="wft-53" comment="the version of ssnetlib.dll is less than 2000.80.818.0" negate="false"/>
          <criterion test_ref="wft-54" comment="the version of ssnmpn70.dll is less than 2000.80.818.0" negate="false"/>
          <criterion test_ref="wft-78" comment="the version of ums.dll is less than 2000.80.816.0" negate="false"/>
          <criterion test_ref="wft-79" comment="the version of odsole70.dll is less than 2000.80.800.0" negate="false"/>
          <criterion test_ref="wft-60" comment="the version of xpweb70.dll is less than 2000.80.778.0" negate="false"/>
          <criterion test_ref="wft-61" comment="File msgprox.dll version3 is less than 2000.80.765.0" negate="false"/>
          <criterion test_ref="wft-62" comment="the version of replprov.dll is less than 2000.80.798.0" negate="false"/>
          <criterion test_ref="wft-63" comment="File replrec.dll version3 is less than 2000.80.765.0" negate="false"/>
          <criterion test_ref="wft-64" comment="File sqlvdi.dll version3 is less than 2000.80.765.0" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL236" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows ME</windows:platform>
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Microsoft Internet Explorer 6 Service Pack 1</product>
      </affected>
      <dates>
        <submitted date="2004-07-30-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <status_change date="2004-08-02-12:00">DRAFT</status_change>
        <status_change date="2004-08-25-12:00">INTERIM</status_change>
        <status_change date="2004-09-09-12:00">ACCEPTED</status_change>
        <modified date="2005-09-26-11:01" comment="modified wft-267 - Changed comment to match test">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-28-01:04">INTERIM</status_change>
        <status_change date="2005-10-19-05:47">ACCEPTED</status_change>
      </dates>
      <description>Double-free vulnerability in mshtml.dll for certain versions of Internet Explorer 6.x allows remote attackers to cause a denial of service (application crash) via a malformed GIF image.</description>
      <reference source="CVE">CVE-2003-1048</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-50" comment="Internet Explorer 6 Service Pack 1 is installed" negate="false"/>
          <criterion test_ref="wft-267" comment="the version of mshtml.dll is less than 6.0.2800.1458" negate="false"/>
          <criterion test_ref="wrt-245" comment="the patch kb832894 is installed (Installed Components key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL237" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Windows 2000</product>
      </affected>
      <dates>
        <submitted date="2003-10-17-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <modified date="2004-03-04-12:00" comment="Added the configuration check to see if ActiveX controls are enabled by the current user when local machine settings are not in use.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <status_change date="2004-03-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in Troubleshooter ActiveX Control (Tshoot.ocx) in Microsoft Windows 2000 SP4 and earlier allows remote attackers to execute arbitrary code via an HTML document with a long argument to the RunQuery2 method.</description>
      <reference source="CVE">CVE-2003-0662</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
          <criterion test_ref="wft-271" comment="the version of tshoot.ocx is less than 1.0.1.2125" negate="false"/>
          <criterion test_ref="wrt-310" comment="the patch kb826232 is installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-75" comment="ActiveX controls are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL241" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows ME</windows:platform>
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Internet Explorer 5.5 Service Pack 2</product>
      </affected>
      <dates>
        <submitted date="2004-07-30-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <status_change date="2004-08-02-12:00">DRAFT</status_change>
        <status_change date="2004-08-25-12:00">INTERIM</status_change>
        <status_change date="2004-09-09-12:00">ACCEPTED</status_change>
      </dates>
      <description>The WebBrowser ActiveX control, or the Internet Explorer HTML rendering engine (MSHTML), as used in Internet Explorer 6, allows remote attackers to execute arbitrary code in the Local Security context by using the showModalDialog method and modifying the location to execute code such as Javascript, as demonstrated using (1) delayed HTTP redirect operations, and an HTTP response with a Location: header containing a "URL:" prepended to a "ms-its" protocol URI, or (2) modifying the location attribute of the window, as exploited by the Download.ject (aka Scob aka Toofer) using the ADODB.Stream object.</description>
      <reference source="CVE">CVE-2004-0549</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-53" comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false"/>
          <criterion test_ref="wft-269" comment="the version of mshtml.dll is less than 5.50.4943.400" negate="false"/>
          <criterion test_ref="wrt-245" comment="the patch kb832894 is installed (Installed Components key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL244" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>krb5</product>
      </affected>
      <dates>
        <submitted date="2003-08-14-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>The Key Distribution Center (KDC) in Kerberos 5 (krb5) 1.2.7 and earlier allows remote, authenticated attackers to cause a denial of service (crash) on KDCs within the same realm using a certain protocol request that causes the KDC to corrupt its heap (aka "buffer underrun").</description>
      <reference source="CVE">CVE-2003-0082</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-218" comment="krb5-server version is less than 1.2.7-14" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL246" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Network News Transport Protocol (NNTP)</product>
      </affected>
      <dates>
        <submitted date="2004-10-26-09:17">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2004-10-27-01:04">DRAFT</status_change>
        <status_change date="2004-11-17-10:00">INTERIM</status_change>
        <status_change date="2004-12-09-08:46">ACCEPTED</status_change>
      </dates>
      <description>The Network News Transfer Protocol (NNTP) component of Microsoft Windows NT Server 4.0, Windows 2000 Server, Windows Server 2003, Exchange 2000 Server, and Exchange Server 2003 allows remote attackers to execute arbitrary code via XPAT patterns, possibly related to improper length validation and an "unchecked buffer," leading to off-by-one and heap-based buffer overflows.</description>
      <reference source="CVE">CVE-2004-0574</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1153" comment="Exchange Server 2003 is installed on Windows Server 2003" negate="false"/>
          <criterion test_ref="wft-506" comment="the version of nntpsvc.dll is less than 6.0.3790.206" negate="false"/>
          <criterion test_ref="wrt-548" comment="the patch WindowsServer2003-KB883935-ia64-enu.exe is installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-326" comment="the NNTP service is enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL248" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>krb5</product>
      </affected>
      <dates>
        <submitted date="2003-08-14-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Version 4 of the Kerberos protocol (krb4), as used in Heimdal and other packages, allows an attacker to impersonate any principal in a realm via a chosen-plaintext attack.</description>
      <reference source="CVE">CVE-2003-0138</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-219" comment="krb5-libs version is less than 1.2.7-14" negate="false"/>
          <criterion test_ref="cmp-289" comment="krb5-server or krb5-workstation installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL250" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>krb5</product>
      </affected>
      <dates>
        <submitted date="2003-08-14-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Certain weaknesses in the implementation of version 4 of the Kerberos protocol (krb4) in the krb5 distribution, when triple-DES keys are used to key krb4 services, allow an attacker to create krb4 tickets for unauthorized principals using a cut-and-paste attack and "ticket splicing."</description>
      <reference source="CVE">CVE-2003-0139</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-219" comment="krb5-libs version is less than 1.2.7-14" negate="false"/>
          <criterion test_ref="cmp-289" comment="krb5-server or krb5-workstation installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL253" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Windows 2000</product>
      </affected>
      <dates>
        <submitted date="2003-10-10-12:00">
          <contributor organization="The MITRE Corporation">Yi-Fang Koh</contributor>
        </submitted>
      </dates>
      <description>Format string vulnerability in the C runtime functions in SQL Server 7.0 and 2000 allows attackers to cause a denial of service.</description>
      <reference source="CVE">CVE-2001-0879</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
          <criterion test_ref="wrt-312" comment="Patch Q305601 Installed" negate="true"/>
          <criterion test_ref="wrt-224" comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL254" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Linux kernel</product>
      </affected>
      <dates>
        <submitted date="2003-09-25-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>The kernel module loader in Linux kernel 2.2.x before 2.2.25, and 2.4.x before 2.4.21, allows local users to gain root privileges by using ptrace to attach to a child process that is spawned by the kernel.</description>
      <reference source="CVE">CVE-2003-0127</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rrt-202" comment="kernel version = 2.4.20-6" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uut-2" comment="kernel 2.4.20-6 or earlier is running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL258" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Internet Explorer 5.01 Service Pack 3</product>
      </affected>
      <dates>
        <submitted date="2005-06-22-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2005-06-22-06:22">DRAFT</status_change>
        <modified date="2005-06-24-12:00" comment="added description">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </modified>
        <status_change date="2005-07-27-10:37">INTERIM</status_change>
        <status_change date="2005-08-18-07:37">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the PNG image rendering component of Microsoft Internet Explorer allows remote attackers to execute arbitrary code via a crafted PNG file.</description>
      <reference source="CVE">CVE-2005-1211</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-55" comment="Internet Explorer 5.01 Service Pack 3 is installed" negate="false"/>
          <criterion test_ref="wft-115" comment="the version of mshtml.dll is less than 5.0.3541.2700" negate="false"/>
          <criterion test_ref="wrt-62" comment="the patch kb883939 is installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-59" comment="PNG image rendering enabled in Internet Explorer" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL259" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>SMB (Server Message Block)</product>
      </affected>
      <dates>
        <submitted date="2005-06-22-12:00">
          <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
        </submitted>
        <status_change date="2005-06-22-12:38">DRAFT</status_change>
        <status_change date="2005-07-27-10:37">INTERIM</status_change>
        <status_change date="2005-08-18-07:37">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the Server Message Block (SMB) functionality for Microsoft Windows 2000, XP SP1 and SP2, and Server 2003 and SP1 allows remote attackers to execute arbitrary code via unknown vectors, aka the "Server Message Block Vulnerability."</description>
      <reference source="CVE">CVE-2005-1206</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="cmp-231" comment="a vulnerable version of srv.sys exists" negate="false"/>
          <criterion test_ref="wrt-63" comment="the patch KB896422 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL260" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Netfilter</product>
      </affected>
      <dates>
        <submitted date="2003-09-25-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>The connection tracking core of Netfilter for Linux 2.4.20, with CONFIG_IP_NF_CONNTRACK enabled or the ip_conntrack module loaded, allows remote attackers to cause a denial of service (resource consumption) due to an inconsistency with Linux 2.4.20's support of linked lists, which causes Netfilter to fail to identify connections with an UNCONFIRMED status and use large timeouts.</description>
      <reference source="CVE">CVE-2003-0187</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-221" comment="kernel version is less than 2.4.20-13.9" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL261" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Netfilter</product>
      </affected>
      <dates>
        <submitted date="2003-09-25-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>The route cache implementation in Linux 2.4, and the Netfilter IP conntrack module, allows remote attackers to cause a denial of service (CPU consumption) via packets with forged source addresses that cause a large number of hash table collisions.</description>
      <reference source="CVE">CVE-2003-0244</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-221" comment="kernel version is less than 2.4.20-13.9" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL262" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Windows kernel</product>
      </affected>
      <dates>
        <submitted date="2004-11-02-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2004-11-03-12:00">DRAFT</status_change>
        <status_change date="2004-12-09-12:00">INTERIM</status_change>
        <status_change date="2005-01-06-12:00">ACCEPTED</status_change>
        <modified date="2005-06-02-12:00" comment="Added product">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-06-08-03:17">INTERIM</status_change>
        <status_change date="2005-06-29-06:49">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in Windows Kernel allows local users to gain privileges by causing certain error messages to be passed to a debugger.</description>
      <reference source="CVE">CVE-2003-0112</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
          <criterion test_ref="wft-570" comment="the version of kernel32.dll is less than 5.0.2195.6011" negate="false"/>
          <criterion test_ref="wrt-478" comment="the patch Q811493 is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL263" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>Gaim</product>
      </affected>
      <dates>
        <submitted date="2005-07-11-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2005-07-27-10:36">DRAFT</status_change>
        <status_change date="2005-08-18-07:37">INTERIM</status_change>
        <status_change date="2005-09-21-01:33">ACCEPTED</status_change>
      </dates>
      <description>Gaim before 1.3.1 allows remote attackers to cause a denial of service (crash) via a malformed MSN message that leads to a memory allocation of a large size, possibly due to an integer signedness error.</description>
      <reference source="CVE">CVE-2005-1934</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="rvt-21" comment="gaim RPM earlier than 1:1.3.1-0.el3" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="upt-56" comment="/usr/bin/gaim is executable by any user" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL264" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Windows 2000</product>
      </affected>
      <dates>
        <submitted date="2003-12-03-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <status_change date="2004-03-09-12:00">ACCEPTED</status_change>
      </dates>
      <description>Heap-based buffer overflow in the Distributed Component Object Model (DCOM) interface in the RPCSS Service allows remote attackers to execute arbitrary code via a malformed DCERPC DCOM object activation request packet with modified length fields, a different vulnerability than CVE-2003-0352 (Blaster/Nachi) and CVE-2003-0528.</description>
      <reference source="CVE">CVE-2003-0715</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
          <criterion test_ref="wft-239" comment="the version of rpcrt4.dll is less than 5.0.2195.6802" negate="false"/>
          <criterion test_ref="wrt-281" comment="the patch kb824146 is installed (Hotfix key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-7" comment="DCOM is enabled on systems with SP3 or later" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL266" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Client Server Runtime System (CSRSS)</product>
      </affected>
      <dates>
        <submitted date="2005-05-02-12:00">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </submitted>
        <status_change date="2005-05-04-12:00">DRAFT</status_change>
        <status_change date="2005-06-01-12:00">INTERIM</status_change>
        <modified date="2005-06-02-12:00" comment="Added product">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-06-22-12:38">ACCEPTED</status_change>
      </dates>
      <description>Stack-based buffer overflow in WINSRV.DLL in the Client Server Runtime System (CSRSS) process of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via a specially-designed application that provides console window information with a long FaceName value.</description>
      <reference source="CVE">CVE-2005-0551</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-35" comment="Windows XP 32 bit Service Pack 2" negate="false"/>
          <criterion test_ref="wft-581" comment="The version of Ntoskrnl.exe is less than 5.1.2600.2622" negate="false"/>
          <criterion test_ref="wrt-427" comment="the patch KB890859 is installed (Hotfix key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL268" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Windows XP</product>
      </affected>
      <dates>
        <submitted date="2003-10-28-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <modified date="2004-03-05-12:00" comment="Fixed the logic that checks for one version of the file if no sp is installed and a different version if sp1 is installed.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <status_change date="2004-03-25-12:00">ACCEPTED</status_change>
        <modified date="2004-09-13-10:21" comment="CMP-66 has been added">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2004-09-15-12:00">INTERIM</status_change>
        <status_change date="2004-09-29-12:00">ACCEPTED</status_change>
      </dates>
      <description>The Messenger Service for Windows NT through Server 2003 does not properly verify the length of the message, which allows remote attackers to execute arbitrary code via a buffer overflow attack.</description>
      <reference source="CVE">CVE-2003-0717</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-30" comment="a vulnerable version of wkssvc.dll exists" negate="false"/>
          <criterion test_ref="cmp-295" comment="a vulnerable version of msgsvc.dll exists" negate="false"/>
          <criterion test_ref="wrt-83" comment="the patch q828035 is installed (Hotfix key)" negate="true"/>
          <criterion test_ref="cmp-66" comment="Windows XP (sp1 or earlier) is installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-307" comment="the messenger service is enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL271" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft SQL Server 2000</product>
      </affected>
      <dates>
        <submitted date="2003-10-10-12:00">
          <contributor organization="The MITRE Corporation">Yi-Fang Koh</contributor>
        </submitted>
        <modified date="2005-04-08-10:31" comment="modified wft-275 - wft-275 corrected literal string">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <modified date="2005-04-08-12:00" comment="modified wft-274 - wft-274 corrected literal string">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <status_change date="2005-04-11-08:48">INTERIM</status_change>
        <status_change date="2005-04-27-12:07">ACCEPTED</status_change>
        <modified date="2005-09-26-12:20" comment="modified wft-274 - Changed comment to match test">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <modified date="2005-09-27-01:22" comment="modified wft-275 - Changed comment to match test">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-28-01:04">INTERIM</status_change>
        <status_change date="2005-10-19-05:47">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in SQL Server 7.0 and 2000 allows remote attackers to execute arbitrary code via a long OLE DB provider name to (1) OpenDataSource or (2) OpenRowset in an ad hoc connection.</description>
      <reference source="CVE">CVE-2002-0056</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-260" comment="SQL Server 2000 is installed" negate="false"/>
          <criterion test_ref="wft-274" comment="File sqlservr.exe version3 is less than 2000.80.578.0" negate="false"/>
          <criterion test_ref="wft-275" comment="File xpstar.dll version3 is less than 2000.80.561.0" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL272" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Internet Explorer 6.0</product>
      </affected>
      <dates>
        <submitted date="2004-01-27-05:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2004-03-09-05:00">ACCEPTED</status_change>
        <modified date="2005-09-20-04:00" comment="Changed IE registry test to wrt-18">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-21-01:27">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Cross-Frame scripting vulnerability in the WebBrowser control as used in Internet Explorer 5.5 and 6.0 allows remote attackers to execute arbitrary code, read arbitrary files, or conduct other unauthorized activities via script that accesses the Document property, which bypasses &lt;frame> and &lt;iframe> domain restrictions.</description>
      <reference source="CVE">CVE-2002-1217</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wft-241" comment="the version of mshtml.dll is less than 6.0.2722.900" negate="false"/>
          <criterion test_ref="wrt-206" comment="the patch q328970 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-207" comment="the patch q324929 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-208" comment="the patch q810847 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-209" comment="the patch q813489 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-210" comment="the patch q818529 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-211" comment="the patch q822925 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-212" comment="the patch q828750 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-19" comment="the patch q824145 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-18" comment="Internet Explorer 6 is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL277" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>SMB Signing (Server Message Block)</product>
      </affected>
      <dates>
        <submitted date="2003-09-16-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2004-03-09-12:00">ACCEPTED</status_change>
        <modified date="2005-09-27-11:09" comment="modified wft-276 - Changed test to match comment">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-28-01:04">INTERIM</status_change>
        <status_change date="2005-10-19-05:47">ACCEPTED</status_change>
      </dates>
      <description>The SMB signing capability in the Server Message Block (SMB) protocol in Microsoft Windows 2000 and Windows XP allows attackers to disable the digital signing settings in an SMB session to force the data to be sent unsigned, then inject data into the session without detection, e.g. by modifying group policy information sent from a domain controller.</description>
      <reference source="CVE">CVE-2002-1256</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
          <criterion test_ref="wft-276" comment="the version of srvsvc.dll is less than 5.0.2195.6110" negate="false"/>
          <criterion test_ref="wrt-314" comment="Patch Q329170 Installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-315" comment="SMB Signing enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL278" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Linux kernel</product>
      </affected>
      <dates>
        <submitted date="2003-09-25-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>The ioperm system call in Linux kernel 2.4.20 and earlier does not properly restrict privileges, which allows local users to gain read or write access to certain I/O ports.</description>
      <reference source="CVE">CVE-2003-0246</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-221" comment="kernel version is less than 2.4.20-13.9" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL281" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Windows Media Player for Windows XP</product>
      </affected>
      <dates>
        <submitted date="2003-11-26-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <status_change date="2004-03-09-12:00">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Windows Media Player versions 6.4 and 7.1 and Media Player for Windows XP allow remote attackers to bypass Internet Explorer's (IE) security mechanisms and run code via an executable .wma media file with a license installation requirement stored in the IE cache, aka the "Cache Path Disclosure via Windows Media Player".</description>
      <reference source="CVE">CVE-2002-0372</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-316" comment="Windows Media Player for Windows XP is installed" negate="false"/>
          <criterion test_ref="wft-277" comment="the version of dxmasf.dll is less than 6.4.9.1121" negate="false"/>
          <criterion test_ref="wft-140" comment="the version of msdxm.ocx is less than 6.4.9.1124" negate="false"/>
          <criterion test_ref="wft-141" comment="the version of wmpcore.dll is less than 8.0.0.4482" negate="false"/>
          <criterion test_ref="wft-142" comment="the version of wmplayer.exe is less than 8.0.0.4482" negate="false"/>
          <criterion test_ref="wrt-317" comment="Patch wm320920_8.exe Installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL284" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Linux kernel</product>
      </affected>
      <dates>
        <submitted date="2003-09-26-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Unknown vulnerability in the TTY layer of the Linux kernel 2.4 allows attackers to cause a denial of service ("kernel oops").</description>
      <reference source="CVE">CVE-2003-0247</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-222" comment="kernel version is less than 2.4.20-18.9" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL287" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Windows Media Player for Windows XP</product>
      </affected>
      <dates>
        <submitted date="2003-11-26-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <status_change date="2004-03-09-12:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in Microsoft Windows Media Player 6.4 allows remote attackers to execute arbitrary code via a malformed Advanced Streaming Format (ASF) file.</description>
      <reference source="CVE">CVE-2001-0719</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-316" comment="Windows Media Player for Windows XP is installed" negate="false"/>
          <criterion test_ref="wft-143" comment="the version of msdxm.ocx is less than 6.4.9.1121" negate="false"/>
          <criterion test_ref="wft-277" comment="the version of dxmasf.dll is less than 6.4.9.1121" negate="false"/>
          <criterion test_ref="wrt-318" comment="Patch wm308567 Installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL291" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>SQL Server 2000</product>
      </affected>
      <dates>
        <submitted date="2003-10-10-12:00">
          <contributor organization="The MITRE Corporation">Yi-Fang Koh</contributor>
        </submitted>
        <modified date="2005-04-08-10:31" comment="modified wft-237 - literal string corrected">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <modified date="2005-04-08-10:31" comment="modified wft-65 - Corrected literal string">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <modified date="2005-04-08-10:31" comment="modified wft-66 - corrected literal string">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <modified date="2005-04-08-10:31" comment="modified wft-67 - Corrected literal string">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <modified date="2005-04-08-10:31" comment="modified wft-68 - Corrected literal string">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <modified date="2005-04-08-10:32" comment="modified wft-69 - corrected literal string">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <modified date="2005-04-08-10:33" comment="modified wft-278 - wft-278 corrected literal string">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <status_change date="2005-04-11-08:48">INTERIM</status_change>
        <status_change date="2005-04-27-12:07">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the password encryption function of Microsoft SQL Server 2000, including Microsoft SQL Server Desktop Engine (MSDE) 2000, allows remote attackers to gain control of the database and execute arbitrary code via SQL Server Authentication, aka "Unchecked Buffer in Password Encryption Procedure."</description>
      <reference source="CVE">CVE-2002-0624</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-260" comment="SQL Server 2000 is installed" negate="false"/>
          <criterion test_ref="wft-278" comment="the version of sqlservr.exe is less than 2000.80.650.0" negate="false"/>
          <criterion test_ref="wft-237" comment="the version of odsole70.dll is less than 2000.80.606.0" negate="false"/>
          <criterion test_ref="wft-65" comment="the version of xpqueue.dll is less than 2000.80.606.0" negate="false"/>
          <criterion test_ref="wft-66" comment="the version of xprepl.dll is less than 2000.80.606.0" negate="false"/>
          <criterion test_ref="wft-67" comment="the version of xplog70.dll is less than 2000.80.606.0" negate="false"/>
          <criterion test_ref="wft-68" comment="the version of xpweb70.dll is less than 2000.80.606.0" negate="false"/>
          <criterion test_ref="wft-69" comment="the version of xpstar.dll is less than 2000.80.628.0" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-261" comment="Mixed Mode Enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL292" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Linux kernel</product>
      </affected>
      <dates>
        <submitted date="2003-09-26-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>The mxcsr code in Linux kernel 2.4 allows attackers to modify CPU state registers via a malformed address.</description>
      <reference source="CVE">CVE-2003-0248</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-222" comment="kernel version is less than 2.4.20-18.9" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL294" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 95</windows:platform>
        <windows:platform>Microsoft Windows 98</windows:platform>
        <windows:platform>Microsoft Windows ME</windows:platform>
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>MDAC 2.6</product>
      </affected>
      <dates>
        <submitted date="2004-08-24-12:00">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </submitted>
        <status_change date="2004-08-25-12:00">DRAFT</status_change>
        <status_change date="2004-09-09-12:00">INTERIM</status_change>
        <status_change date="2004-09-29-12:00">ACCEPTED</status_change>
        <modified date="2005-02-28-12:00" comment="removed the test for windows NT and added a test for MDAC 2.6 since this definition is dependent on the MDAC version and not the platform">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <status_change date="2005-03-02-08:52">INTERIM</status_change>
        <status_change date="2005-03-23-08:09">ACCEPTED</status_change>
      </dates>
      <description>Heap-based buffer overflow in the Remote Data Services (RDS) component of Microsoft Data Access Components (MDAC) 2.1 through 2.6, and Internet Explorer 5.01 through 6.0, allows remote attackers to execute code via a malformed HTTP request to the Data Stub.</description>
      <reference source="CVE">CVE-2002-1142</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-101" comment="MDAC 2.6 is installed" negate="false"/>
          <criterion test_ref="wft-481" comment="the version of msadco.dll is less than 2.62.9119.1" negate="false"/>
          <criterion test_ref="wrt-503" comment="Patch Q329414 Installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL295" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Linux kernel</product>
      </affected>
      <dates>
        <submitted date="2003-09-26-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>The TCP/IP fragment reassembly handling in the Linux kernel 2.4 allows remote attackers to cause a denial of service (CPU consumption) via certain packets that cause a large number of hash table collisions.</description>
      <reference source="CVE">CVE-2003-0364</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-222" comment="kernel version is less than 2.4.20-18.9" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL296" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Remote Procedure Call (RPC)</product>
      </affected>
      <dates>
        <submitted date="2003-12-03-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <status_change date="2004-03-09-12:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in a certain DCOM interface for RPC in Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary code via a malformed message, as exploited by the Blaster/MSblast/LovSAN and Nachi/Welchia worms.</description>
      <reference source="CVE">CVE-2003-0352</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
          <criterion test_ref="wft-280" comment="File %windir%\system32\rpcrt4.dll version is less than 5.0.2195.6753" negate="false"/>
          <criterion test_ref="wrt-254" comment="Patch Windows2000-KB823980-x86-ENU.exe Installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-7" comment="DCOM is enabled on systems with SP3 or later" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL298" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Simple Network Management Protocol (SNMP)</product>
      </affected>
      <dates>
        <submitted date="2003-10-10-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <modified date="2004-09-20-10:31" comment="Changed CAN-2002-0012 to CAN-2002-0013.">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </modified>
        <status_change date="2004-09-22-12:00">INTERIM</status_change>
        <status_change date="2004-10-06-12:00">ACCEPTED</status_change>
      </dates>
      <description>Vulnerabilities in the SNMPv1 request handling of a large number of SNMP implementations allow remote attackers to cause a denial of service or gain privileges via (1) GetRequest, (2) GetNextRequest, and (3) SetRequest messages, as demonstrated by the PROTOS c06-SNMPv1 test suite.  NOTE: It is highly likely that this candidate will be SPLIT into multiple candidates, one or more for each vendor.  This and other SNMP-related candidates will be updated when more accurate information is available.</description>
      <reference source="CVE">CVE-2002-0013</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
          <criterion test_ref="wrt-224" comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="true"/>
          <criterion test_ref="wft-242" comment="the version of snmp.exe is less than 5.0.2195.4919" negate="false"/>
          <criterion test_ref="wrt-263" comment="Patch Q314147 Installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-264" comment="the SNMP service is enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL299" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>SQL Server 2000</product>
      </affected>
      <dates>
        <submitted date="2003-10-10-12:00">
          <contributor organization="The MITRE Corporation">Yi-Fang Koh</contributor>
        </submitted>
        <modified date="2005-01-14-12:00" comment="modified wft-55 - Added &quot;80&quot; to the registry component. So that new component value is HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Microsoft SQL Server\80\SharedCode. This key specifes the location of the  file that should be tested. ">
          <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
        </modified>
        <status_change date="2005-01-20-12:00">INTERIM</status_change>
        <status_change date="2005-02-16-12:00">ACCEPTED</status_change>
        <modified date="2005-04-08-10:31" comment="modified wft-72 - corrected literal string">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <modified date="2005-04-08-10:32" comment="modified wft-70 - Corrected literal string">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <modified date="2005-04-08-10:33" comment="modified wft-73 - Corrected literal string">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <modified date="2005-04-08-10:34" comment="modified wft-78 - wft-78 corrected literal string">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <modified date="2005-04-08-10:35" comment="modified wft-79 - wft-79 corrected literal string">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <modified date="2005-04-08-10:36" comment="modified wft-51 - wft-51 corrected literal string">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <modified date="2005-04-08-10:37" comment="modified wft-52 - wft-52 corrected literal string">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <modified date="2005-04-08-10:38" comment="modified wft-53 - wft-53 corrected literal string">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <modified date="2005-04-08-10:39" comment="modified wft-54 - wft-54 corrected literal string">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <modified date="2005-04-08-10:40" comment="modified wft-60 - wft-60 corrected literal string">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <status_change date="2005-04-11-08:48">INTERIM</status_change>
        <status_change date="2005-04-27-12:07">ACCEPTED</status_change>
        <modified date="2005-09-27-01:23" comment="modified wft-70 - Changed comment to match test">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <modified date="2005-09-27-01:24" comment="modified wft-72 - Changed comment to match test">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <modified date="2005-09-27-01:25" comment="modified wft-73 - Changed comment to match test">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-28-01:04">INTERIM</status_change>
        <status_change date="2005-10-19-05:47">ACCEPTED</status_change>
      </dates>
      <description>Microsoft SQL Server 7, 2000, and MSDE allows local or remote authenticated users to cause a denial of service (crash or hang) via a long request to a named pipe.</description>
      <reference source="CVE">CVE-2003-0231</reference>
      <status>ACCEPTED</status>
      <version>4</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-260" comment="SQL Server 2000 is installed" negate="false"/>
          <criterion test_ref="wft-70" comment="File console.exe version3 is less than 2000.80.818.0" negate="false"/>
          <criterion test_ref="wft-50" comment="the version of dbmslpcn.dll is less than 2000.80.818.0" negate="false"/>
          <criterion test_ref="wft-72" comment="File sqlmap70.dll version3 is less than 2000.80.811.0" negate="false"/>
          <criterion test_ref="wft-73" comment="File sqlrepss.dll version3 is less than 2000.80.765.0" negate="false"/>
          <criterion test_ref="wft-51" comment="the version of sqlservr.exe is less than 2000.80.818.0" negate="false"/>
          <criterion test_ref="wft-52" comment="the version of ssmslpcn.dll is less than 2000.80.818.0" negate="false"/>
          <criterion test_ref="wft-53" comment="the version of ssnetlib.dll is less than 2000.80.818.0" negate="false"/>
          <criterion test_ref="wft-54" comment="the version of ssnmpn70.dll is less than 2000.80.818.0" negate="false"/>
          <criterion test_ref="wft-78" comment="the version of ums.dll is less than 2000.80.816.0" negate="false"/>
          <criterion test_ref="wft-79" comment="the version of odsole70.dll is less than 2000.80.800.0" negate="false"/>
          <criterion test_ref="wft-60" comment="the version of xpweb70.dll is less than 2000.80.778.0" negate="false"/>
          <criterion test_ref="wft-55" comment="the version of msgprox.dll is less than 2000.80.765.0" negate="false"/>
          <criterion test_ref="wft-62" comment="the version of replprov.dll is less than 2000.80.798.0" negate="false"/>
          <criterion test_ref="wft-56" comment="the version of replrec.dll is less than 2000.80.765.0" negate="false"/>
          <criterion test_ref="wft-57" comment="the version of sqlvdi.dll is less than 2000.80.765.0" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL303" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>SQL Server 2000</product>
      </affected>
      <dates>
        <submitted date="2003-10-10-12:00">
          <contributor organization="The MITRE Corporation">Yi-Fang Koh</contributor>
        </submitted>
        <modified date="2005-01-14-12:00" comment="modified wft-55 - Added &quot;80&quot; to the registry component. So that new component value is HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Microsoft SQL Server\80\SharedCode. This key specifes the location of the  file that should be tested. ">
          <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
        </modified>
        <status_change date="2005-01-20-12:00">INTERIM</status_change>
        <status_change date="2005-02-16-12:00">ACCEPTED</status_change>
        <modified date="2005-04-08-10:31" comment="modified wft-72 - corrected literal string">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <modified date="2005-04-08-10:32" comment="modified wft-70 - Corrected literal string">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <modified date="2005-04-08-10:41" comment="modified wft-73 - Corrected literal string">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <modified date="2005-04-08-10:51" comment="modified wft-78 - wft-78 corrected literal string">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <modified date="2005-04-08-11:01" comment="modified wft-79 - wft-79 corrected literal string">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <modified date="2005-04-08-11:31" comment="modified wft-51 - wft-51 corrected literal string">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <modified date="2005-04-08-11:32" comment="modified wft-52 - wft-52 corrected literal string">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <modified date="2005-04-08-11:33" comment="modified wft-53 - wft-53 corrected literal string">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <modified date="2005-04-08-11:34" comment="modified wft-54 - wft-54 corrected literal string">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <modified date="2005-04-08-11:51" comment="modified wft-60 - wft-60 corrected literal string">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <status_change date="2005-04-11-08:48">INTERIM</status_change>
        <status_change date="2005-04-27-12:07">ACCEPTED</status_change>
        <modified date="2005-09-27-01:23" comment="modified wft-70 - Changed comment to match test">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <modified date="2005-09-27-01:24" comment="modified wft-72 - Changed comment to match test">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <modified date="2005-09-27-01:25" comment="modified wft-73 - Changed comment to match test">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-28-01:04">INTERIM</status_change>
        <status_change date="2005-10-19-05:47">ACCEPTED</status_change>
      </dates>
      <description>Microsoft SQL Server 7, 2000, and MSDE allows local users to execute arbitrary code via a certain request to the Local Procedure Calls (LPC) port that leads to a buffer overflow.</description>
      <reference source="CVE">CVE-2003-0232</reference>
      <status>ACCEPTED</status>
      <version>4</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-260" comment="SQL Server 2000 is installed" negate="false"/>
          <criterion test_ref="wft-70" comment="File console.exe version3 is less than 2000.80.818.0" negate="false"/>
          <criterion test_ref="wft-50" comment="the version of dbmslpcn.dll is less than 2000.80.818.0" negate="false"/>
          <criterion test_ref="wft-72" comment="File sqlmap70.dll version3 is less than 2000.80.811.0" negate="false"/>
          <criterion test_ref="wft-73" comment="File sqlrepss.dll version3 is less than 2000.80.765.0" negate="false"/>
          <criterion test_ref="wft-51" comment="the version of sqlservr.exe is less than 2000.80.818.0" negate="false"/>
          <criterion test_ref="wft-52" comment="the version of ssmslpcn.dll is less than 2000.80.818.0" negate="false"/>
          <criterion test_ref="wft-53" comment="the version of ssnetlib.dll is less than 2000.80.818.0" negate="false"/>
          <criterion test_ref="wft-54" comment="the version of ssnmpn70.dll is less than 2000.80.818.0" negate="false"/>
          <criterion test_ref="wft-78" comment="the version of ums.dll is less than 2000.80.816.0" negate="false"/>
          <criterion test_ref="wft-79" comment="the version of odsole70.dll is less than 2000.80.800.0" negate="false"/>
          <criterion test_ref="wft-60" comment="the version of xpweb70.dll is less than 2000.80.778.0" negate="false"/>
          <criterion test_ref="wft-55" comment="the version of msgprox.dll is less than 2000.80.765.0" negate="false"/>
          <criterion test_ref="wft-62" comment="the version of replprov.dll is less than 2000.80.798.0" negate="false"/>
          <criterion test_ref="wft-56" comment="the version of replrec.dll is less than 2000.80.765.0" negate="false"/>
          <criterion test_ref="wft-57" comment="the version of sqlvdi.dll is less than 2000.80.765.0" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL304" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>/proc/tty/driver/serial</product>
      </affected>
      <dates>
        <submitted date="2003-09-26-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>/proc/tty/driver/serial in Linux 2.4.x reveals the exact number of characters used in serial links, which could allow local users to obtain potentially sensitive information such as the length of passwords.</description>
      <reference source="CVE">CVE-2003-0461</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-223" comment="kernel version is less than 2.4.20-19.9" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL306" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Internet Explorer 5.01 Service Pack 3</product>
      </affected>
      <dates>
        <submitted date="2004-07-30-12:00">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </submitted>
        <status_change date="2004-08-02-12:00">DRAFT</status_change>
        <status_change date="2004-08-25-12:00">INTERIM</status_change>
        <status_change date="2004-09-09-12:00">ACCEPTED</status_change>
      </dates>
      <description>Integer overflow in imgbmp.cxx for Windows 2000 allows remote attackers to execute arbitrary code via a BMP image with a large bfOffBits value.</description>
      <reference source="CVE">CVE-2004-0566</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-55" comment="Internet Explorer 5.01 Service Pack 3 is installed" negate="false"/>
          <criterion test_ref="wft-270" comment="the version of mshtml.dll is less than 5.0.3532.300" negate="false"/>
          <criterion test_ref="wrt-245" comment="the patch kb832894 is installed (Installed Components key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL308" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft FrontPage Server Extensions 2000</product>
      </affected>
      <dates>
        <submitted date="2003-12-09-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <modified date="2004-01-14-12:00" comment="Changed the definition to look at the file shtml.dll instead of fp4awel.dll.  It was determined that this is where the vulnerability (a buffer overflow) actually existed.  Also added the configuration test saying you are vulnerable if the SmartHTML interpreter is enabled.">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </modified>
        <status_change date="2004-03-09-12:00">INTERIM</status_change>
        <status_change date="2004-03-25-12:00">ACCEPTED</status_change>
        <modified date="2005-09-26-10:51" comment="modified wft-12 - Changed comment to match test">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-28-01:04">INTERIM</status_change>
        <status_change date="2005-10-19-05:47">ACCEPTED</status_change>
      </dates>
      <description>Unknown vulnerability in the SmartHTML interpreter (shtml.dll) in Microsoft FrontPage Server Extensions 2000 and 2002, and Microsoft SharePoint Team Services 2002, allows remote attackers to cause a denial of service (response failure) via a certain request.</description>
      <reference source="CVE">CVE-2003-0824</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-65" comment="Windows 2000 (sp3 or earlier) is installed" negate="false"/>
          <criterion test_ref="wft-12" comment="the version of shtml.dll is less than 4.00.02.7523" negate="false"/>
          <criterion test_ref="wrt-88" comment="the patch q810217 is installed (Hotfix key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-31" comment="FrontPage Server Extensions 2000 are enabled (2K, XP)" negate="false"/>
          <criterion test_ref="wmt-2" comment="SmartHTML interpreter is enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL309" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Linux kernel</product>
      </affected>
      <dates>
        <submitted date="2003-09-26-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>A race condition in the way env_start and env_end pointers are initialized in the execve system call and used in fs/proc/base.c on Linux 2.4 allows local users to cause a denial of service (crash).</description>
      <reference source="CVE">CVE-2003-0462</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-223" comment="kernel version is less than 2.4.20-19.9" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL311" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Linux kernel</product>
      </affected>
      <dates>
        <submitted date="2003-09-26-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>The RPC code in Linux kernel 2.4 sets the reuse flag when sockets are created, which could allow local users to bind to UDP ports that are used by privileged services such as nfsd.</description>
      <reference source="CVE">CVE-2003-0464</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-223" comment="kernel version is less than 2.4.20-19.9" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL316" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>SQL Server 2000</product>
      </affected>
      <dates>
        <submitted date="2003-10-10-12:00">
          <contributor organization="The MITRE Corporation">Yi-Fang Koh</contributor>
        </submitted>
        <modified date="2005-04-08-10:31" comment="modified wft-237 - literal string corrected">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <modified date="2005-04-08-10:31" comment="modified wft-65 - Corrected literal string">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <modified date="2005-04-08-10:31" comment="modified wft-66 - corrected literal string">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <modified date="2005-04-08-10:31" comment="modified wft-67 - Corrected literal string">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <modified date="2005-04-08-10:31" comment="modified wft-68 - Corrected literal string">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <modified date="2005-04-08-10:32" comment="modified wft-69 - corrected literal string">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <modified date="2005-04-08-10:33" comment="modified wft-278 - wft-278 corrected literal string">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <modified date="2005-04-08-10:34" comment="modified wft-58 - wft-58 corrected literal string">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <status_change date="2005-04-11-08:48">INTERIM</status_change>
        <status_change date="2005-04-27-12:07">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in bulk insert procedure of Microsoft SQL Server 2000, including Microsoft SQL Server Desktop Engine (MSDE) 2000, allows attackers with database administration privileges to execute arbitrary code via a long filename in the BULK INSERT query.</description>
      <reference source="CVE">CVE-2002-0641</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-260" comment="SQL Server 2000 is installed" negate="false"/>
          <criterion test_ref="wft-278" comment="the version of sqlservr.exe is less than 2000.80.650.0" negate="false"/>
          <criterion test_ref="wft-237" comment="the version of odsole70.dll is less than 2000.80.606.0" negate="false"/>
          <criterion test_ref="wft-65" comment="the version of xpqueue.dll is less than 2000.80.606.0" negate="false"/>
          <criterion test_ref="wft-66" comment="the version of xprepl.dll is less than 2000.80.606.0" negate="false"/>
          <criterion test_ref="wft-67" comment="the version of xplog70.dll is less than 2000.80.606.0" negate="false"/>
          <criterion test_ref="wft-68" comment="the version of xpweb70.dll is less than 2000.80.606.0" negate="false"/>
          <criterion test_ref="wft-69" comment="the version of xpstar.dll is less than 2000.80.628.0" negate="false"/>
          <criterion test_ref="wft-58" comment="the version of impprov.dll is less than 2000.80.650.0" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL319" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>Windows NT 4.0</product>
      </affected>
      <dates>
        <submitted date="2003-10-10-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <status_change date="2004-05-05-12:00">INTERIM</status_change>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>The getCanonicalPath function in Windows NT 4.0 may free memory that it does not own and cause heap corruption, which allows attackers to cause a denial of service (crash) via requests that cause a long file name to be passed to getCanonicalPath, as demonstrated on the IBM JVM using a long string to the java.io.getCanonicalPath Java method.</description>
      <reference source="CVE">CVE-2003-0525</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" negate="false"/>
          <criterion test_ref="wrt-40" comment="this is an NT Workstation" negate="true"/>
          <criterion test_ref="wrt-43" comment="this is an NT Terminal Server" negate="true"/>
          <criterion test_ref="wft-282" comment="the version of kernel32.dll is less than 4.0.1381.7224" negate="false"/>
          <criterion test_ref="wrt-323" comment="Patch Q823803 Installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL321" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Windows Media Player for Windows XP</product>
      </affected>
      <dates>
        <submitted date="2003-11-26-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <status_change date="2004-03-09-12:00">ACCEPTED</status_change>
      </dates>
      <description>Directory traversal vulnerability in Microsoft Windows Media Player 7.1 and Windows Media Player for Windows XP allows remote attackers to execute arbitrary code via a skins file with a URL containing hex-encoded backslash characters (%5C) that causes an executable to be placed in an arbitrary location.</description>
      <reference source="CVE">CVE-2003-0228</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-316" comment="Windows Media Player for Windows XP is installed" negate="false"/>
          <criterion test_ref="wft-144" comment="the version of wmplayer.exe is less than 8.0.0.4490" negate="false"/>
          <criterion test_ref="wrt-324" comment="Patch WindowsMedia8-KB817787-x86-ENU.exe Installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL322" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows ME</windows:platform>
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Internet Explorer 5.5 Service Pack 2</product>
      </affected>
      <dates>
        <submitted date="2004-07-30-12:00">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </submitted>
        <status_change date="2004-08-02-12:00">DRAFT</status_change>
        <status_change date="2004-08-25-12:00">INTERIM</status_change>
        <status_change date="2004-09-09-12:00">ACCEPTED</status_change>
      </dates>
      <description>Integer overflow in imgbmp.cxx for Windows 2000 allows remote attackers to execute arbitrary code via a BMP image with a large bfOffBits value.</description>
      <reference source="CVE">CVE-2004-0566</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-53" comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false"/>
          <criterion test_ref="wft-269" comment="the version of mshtml.dll is less than 5.50.4943.400" negate="false"/>
          <criterion test_ref="wrt-245" comment="the patch kb832894 is installed (Installed Components key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL327" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Linux kernel</product>
      </affected>
      <dates>
        <submitted date="2003-09-26-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>The execve system call in Linux 2.4.x records the file descriptor of the executable process in the file table of the calling process, which allows local users to gain read access to restricted file descriptors.</description>
      <reference source="CVE">CVE-2003-0476</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-223" comment="kernel version is less than 2.4.20-19.9" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL328" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Linux kernel</product>
      </affected>
      <dates>
        <submitted date="2003-09-26-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>The /proc filesystem in Linux allows local users to obtain sensitive information by opening various entries in /proc/self before executing a setuid program, which causes the program to fail to change the ownership and permissions of those entries.</description>
      <reference source="CVE">CVE-2003-0501</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-223" comment="kernel version is less than 2.4.20-19.9" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL330" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Microsoft Color Management Module</product>
      </affected>
      <dates>
        <submitted date="2005-08-02-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2005-08-03-11:30">DRAFT</status_change>
        <status_change date="2005-08-18-07:37">INTERIM</status_change>
        <status_change date="2005-09-21-01:33">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the Microsoft Color Management Module for Windows allows remote attackers to execute arbitrary code via an image with crafted ICC profile format tags.</description>
      <reference source="CVE">CVE-2005-1219</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-35" comment="Windows XP 32 bit Service Pack 2" negate="false"/>
          <criterion test_ref="wft-409" comment="the version of mscms.dll is less than 5.1.2600.2709" negate="false"/>
          <criterion test_ref="wrt-128" comment="the patch KB901214 is installed " negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL331" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Microsoft Windows Workstation Service</product>
      </affected>
      <dates>
        <submitted date="2003-11-12-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <modified date="2004-03-08-12:00" comment="Added 64-bit edition support to this definition allowing us to deprecated OVAL332">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <status_change date="2004-03-09-12:00">INTERIM</status_change>
        <status_change date="2004-03-25-12:00">ACCEPTED</status_change>
        <modified date="2004-09-13-10:26" comment="">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2004-09-15-12:00">INTERIM</status_change>
        <status_change date="2004-09-29-12:00">ACCEPTED</status_change>
      </dates>
      <description>Stack-based buffer overflow in a logging function for Windows Workstation Service (WKSSVC.DLL) allows remote attackers to execute arbitrary code via RPC calls that cause long entries to be written to a debug log file ("NetSetup.LOG"), as demonstrated using the NetAddAlternateComputerName API.</description>
      <reference source="CVE">CVE-2003-0812</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-30" comment="a vulnerable version of wkssvc.dll exists" negate="false"/>
          <criterion test_ref="wrt-83" comment="the patch q828035 is installed (Hotfix key)" negate="true"/>
          <criterion test_ref="cmp-66" comment="Windows XP (sp1 or earlier) is installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-71" comment="the workstation service is enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL333" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Internet Explorer 5.5</product>
      </affected>
      <dates>
        <submitted date="2004-01-27-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2004-03-09-12:00">ACCEPTED</status_change>
      </dates>
      <description>Cross-Frame scripting vulnerability in the WebBrowser control as used in Internet Explorer 5.5 and 6.0 allows remote attackers to execute arbitrary code, read arbitrary files, or conduct other unauthorized activities via script that accesses the Document property, which bypasses &lt;frame> and &lt;iframe> domain restrictions.</description>
      <reference source="CVE">CVE-2002-1217</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-271" comment="Internet Explorer 5.5 Installed" negate="false"/>
          <criterion test_ref="wft-262" comment="the version of mshtml.dll is less than 5.50.4922.900" negate="false"/>
          <criterion test_ref="wrt-206" comment="the patch q328970 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-207" comment="the patch q324929 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-208" comment="the patch q810847 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-209" comment="the patch q813489 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-210" comment="the patch q818529 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-211" comment="the patch q822925 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-212" comment="the patch q828750 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-19" comment="the patch q824145 is installed (Installed Components key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL334" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Network News Transport Protocol (NNTP)</product>
      </affected>
      <dates>
        <submitted date="2003-09-16-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2004-03-09-12:00">ACCEPTED</status_change>
      </dates>
      <description>Memory leak in NNTP service in Windows NT 4.0 and Windows 2000 allows remote attackers to cause a denial of service (memory exhaustion) via a large number of malformed posts.</description>
      <reference source="CVE">CVE-2001-0543</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
          <criterion test_ref="wrt-224" comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="true"/>
          <criterion test_ref="wft-283" comment="the version of nntpsvc.dll is less than 5.0.2195.3881" negate="false"/>
          <criterion test_ref="wrt-325" comment="Patch Q303984 Installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-326" comment="the NNTP service is enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL335" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Internet Explorer 5.01 Service Pack 2</product>
      </affected>
      <dates>
        <submitted date="2003-11-12-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <modified date="2004-01-21-12:00" comment="Removed the test for Windows 2000 sp2 installed.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 5.01 sp2 patch.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <modified date="2004-03-04-12:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <status_change date="2004-03-09-12:00">INTERIM</status_change>
        <status_change date="2004-03-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and execute Javascript by setting the window's "href" to the malicious Javascript, then calling execCommand("Refresh") to refresh the page, aka BodyRefreshLoadsJPU or the "ExecCommand Cross Domain" vulnerability.</description>
      <reference source="CVE">CVE-2003-0814</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-56" comment="Internet Explorer 5.01 Service Pack 2 is installed" negate="false"/>
          <criterion test_ref="wft-23" comment="the version of mshtml.dll is less than 5.0.3523.1700" negate="false"/>
          <criterion test_ref="wrt-19" comment="the patch q824145 is installed (Installed Components key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL336" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 95</windows:platform>
        <windows:platform>Microsoft Windows 98</windows:platform>
        <windows:platform>Microsoft Windows ME</windows:platform>
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Word 2000</product>
      </affected>
      <dates>
        <submitted date="2003-11-19-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2004-03-09-12:00">ACCEPTED</status_change>
        <modified date="2005-04-11-12:00" comment="modified wft-19 - wft-19 corrected literal string">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <status_change date="2005-04-11-08:48">INTERIM</status_change>
        <status_change date="2005-04-27-12:07">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Word 97, 98(J), 2000, and 2002, and Microsoft Works Suites 2001 through 2004, do not properly check the length of the "Macro names" data value, which could allow remote attackers to execute arbitrary code via a buffer overflow attack.</description>
      <reference source="CVE">CVE-2003-0820</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-132" comment="Word 2000 is installed" negate="false"/>
          <criterion test_ref="wft-19" comment="the version of winword.exe is less than 9.0.0.8216" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL340" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Windows 2000</product>
      </affected>
      <dates>
        <submitted date="2003-10-16-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <status_change date="2004-03-09-12:00">ACCEPTED</status_change>
        <modified date="2005-01-27-12:00" comment="Added the patch KB891711 (from MS05-002) which supercedes the previous patch">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-01-28-09:27">INTERIM</status_change>
        <status_change date="2005-02-16-07:32">ACCEPTED</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <modified date="2005-09-26-12:22" comment="modified wft-285 - Changed comment to match test">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-28-01:04">INTERIM</status_change>
        <status_change date="2005-10-19-05:47">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in a function in User32.dll on Windows NT through Server 2003 allows local users to execute arbitrary code via long (1) LB_DIR messages to ListBox or (2) CB_DIR messages to ComboBox controls in a privileged application.</description>
      <reference source="CVE">CVE-2003-0659</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
          <criterion test_ref="wft-285" comment="File %windir%\system32\user32.dll version is less than 5.0.2195.6799" negate="false"/>
          <criterion test_ref="wrt-304" comment="the patch kb824141 is installed (Hotfix key)" negate="true"/>
          <criterion test_ref="wrt-68" comment="the patch kb891711 is installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-305" comment="the utility manager Service is enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL341" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Internet Explorer 5.01 Service Pack 3</product>
      </affected>
      <dates>
        <submitted date="2003-11-12-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <modified date="2004-01-21-12:00" comment="Removed the test for Windows 2000 sp3 installed.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 5.01 sp3 patch.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <modified date="2004-03-04-12:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <status_change date="2004-03-09-12:00">INTERIM</status_change>
        <status_change date="2004-03-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and execute Javascript by setting the window's "href" to the malicious Javascript, then calling execCommand("Refresh") to refresh the page, aka BodyRefreshLoadsJPU or the "ExecCommand Cross Domain" vulnerability.</description>
      <reference source="CVE">CVE-2003-0814</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-55" comment="Internet Explorer 5.01 Service Pack 3 is installed" negate="false"/>
          <criterion test_ref="wft-23" comment="the version of mshtml.dll is less than 5.0.3523.1700" negate="false"/>
          <criterion test_ref="wrt-19" comment="the patch q824145 is installed (Installed Components key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL342" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Internet Explorer 5.01 Service Pack 4</product>
      </affected>
      <dates>
        <submitted date="2003-11-12-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <modified date="2004-01-21-12:00" comment="Removed the test for Windows 2000 sp4 installed.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 5.01 sp4 patch.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <modified date="2004-03-04-12:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <status_change date="2004-03-09-12:00">INTERIM</status_change>
        <status_change date="2004-03-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and execute Javascript by setting the window's "href" to the malicious Javascript, then calling execCommand("Refresh") to refresh the page, aka BodyRefreshLoadsJPU or the "ExecCommand Cross Domain" vulnerability.</description>
      <reference source="CVE">CVE-2003-0814</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-54" comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false"/>
          <criterion test_ref="wft-24" comment="the version of mshtml.dll is less than 5.0.3810.1700" negate="false"/>
          <criterion test_ref="wrt-19" comment="the patch q824145 is installed (Installed Components key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL343" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows ME</windows:platform>
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Internet Explorer 5.5 Service Pack 2</product>
      </affected>
      <dates>
        <submitted date="2003-11-12-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <modified date="2004-01-21-12:00" comment="Removed the test for specific Windows operating systems.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 5.5 sp2 patch.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <modified date="2004-03-04-12:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <status_change date="2004-03-09-12:00">INTERIM</status_change>
        <status_change date="2004-03-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and execute Javascript by setting the window's "href" to the malicious Javascript, then calling execCommand("Refresh") to refresh the page, aka BodyRefreshLoadsJPU or the "ExecCommand Cross Domain" vulnerability.</description>
      <reference source="CVE">CVE-2003-0814</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-53" comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false"/>
          <criterion test_ref="wft-25" comment="the version of mshtml.dll is less than 5.50.4934.1600" negate="false"/>
          <criterion test_ref="wrt-19" comment="the patch q824145 is installed (Installed Components key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL344" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows ME</windows:platform>
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Microsoft Internet Explorer 6 Service Pack 1</product>
      </affected>
      <dates>
        <submitted date="2003-11-12-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <modified date="2004-01-21-12:00" comment="Removed the test for specific Windows operating systems.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 6 sp1 patch.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <modified date="2004-01-29-12:00" comment="Added Windows XP 64-bit to the list of affected platforms">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <modified date="2004-03-04-12:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <status_change date="2004-03-09-12:00">INTERIM</status_change>
        <status_change date="2004-03-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and execute Javascript by setting the window's "href" to the malicious Javascript, then calling execCommand("Refresh") to refresh the page, aka BodyRefreshLoadsJPU or the "ExecCommand Cross Domain" vulnerability.</description>
      <reference source="CVE">CVE-2003-0814</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-50" comment="Internet Explorer 6 Service Pack 1 is installed" negate="false"/>
          <criterion test_ref="wft-27" comment="the version of mshtml.dll is less than 6.0.2800.1276" negate="false"/>
          <criterion test_ref="wrt-19" comment="the patch q824145 is installed (Installed Components key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL345" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>php</product>
      </affected>
      <dates>
        <submitted date="2005-07-19-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2005-07-27-10:36">DRAFT</status_change>
        <status_change date="2005-08-18-07:37">INTERIM</status_change>
        <status_change date="2005-09-21-01:33">ACCEPTED</status_change>
      </dates>
      <description>Race condition in shtool 2.0.1 and earlier allows local users to create or modify arbitrary files via a symlink attack on the .shtool.$$ temporary file, a different vulnerability than CVE-2005-1759.</description>
      <reference source="CVE">CVE-2005-1751</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="rvt-27" comment="php RPM prior to  0:4.3.2-24.ent" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="upt-1" comment="/tmp is writable by everyone" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL349" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Internet Explorer 6 Service Pack 1 for Windows Server 2003</product>
      </affected>
      <dates>
        <submitted date="2003-11-12-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <modified date="2004-01-21-12:00" comment="Removed the test for Windows Server 2003.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 6 sp1 patch.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <modified date="2004-01-29-12:00" comment="Added Windows XP 64-bit, Version 2003 and Windows Server 2003 64-Bit to the list of affected platforms">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <modified date="2004-03-04-12:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <status_change date="2004-03-09-12:00">INTERIM</status_change>
        <status_change date="2004-03-25-12:00">ACCEPTED</status_change>
        <modified date="2005-05-10-12:00" comment="modified wrt-51 - Comment updated to indicate IE 6.">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </modified>
        <status_change date="2005-05-11-05:33">INTERIM</status_change>
        <status_change date="2005-06-01-03:30">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and execute Javascript by setting the window's "href" to the malicious Javascript, then calling execCommand("Refresh") to refresh the page, aka BodyRefreshLoadsJPU or the "ExecCommand Cross Domain" vulnerability.</description>
      <reference source="CVE">CVE-2003-0814</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-51" comment="Internet Explorer 6  for Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wft-28" comment="the version of mshtml.dll is less than 6.0.3790.94" negate="false"/>
          <criterion test_ref="wrt-60" comment="the patch q824145 is installed (Hotfix key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL350" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>php</product>
      </affected>
      <dates>
        <submitted date="2005-07-19-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2005-07-27-10:36">DRAFT</status_change>
        <status_change date="2005-08-18-07:37">INTERIM</status_change>
        <status_change date="2005-09-21-01:33">ACCEPTED</status_change>
      </dates>
      <description>Eval injection vulnerability in PEAR XML_RPC 1.3.0 and earlier (aka XML-RPC or xmlrpc) and PHPXMLRPC (aka XML-RPC For PHP or php-xmlrpc) 1.1 and earlier, as used in products such as (1) WordPress, (2) Serendipity, (3) Drupal, (4) egroupware, (5) MailWatch, (6) TikiWiki, (7) phpWebSite, (8) Ampache, and others, allows remote attackers to execute arbitrary PHP code via an XML file, which is not properly sanitized before being used in an eval statement.</description>
      <reference source="CVE">CVE-2005-1921</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="rvt-27" comment="php RPM prior to  0:4.3.2-24.ent" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uft-4" comment="/etc/httpd/conf.d/php.conf exists" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL351" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Internet Explorer 5.01 Service Pack 2</product>
      </affected>
      <dates>
        <submitted date="2003-11-12-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <modified date="2004-01-21-12:00" comment="Removed the test for Windows 2000 sp2 installed.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of having IE 5.01 sp2 installed.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <modified date="2004-03-04-12:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <status_change date="2004-03-09-12:00">INTERIM</status_change>
        <status_change date="2004-03-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and read arbitrary files by (1) modifying the createTextRange method and using CreateLink, as demonstrated using LinkillerSaveRef, LinkillerJPU, and Linkiller, or (2) modifying the createRange method and using the FIND dialog to select text, as demonstrated using Findeath, aka the "Function Pointer Override Cross Domain" vulnerability.</description>
      <reference source="CVE">CVE-2003-0815</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-56" comment="Internet Explorer 5.01 Service Pack 2 is installed" negate="false"/>
          <criterion test_ref="wft-23" comment="the version of mshtml.dll is less than 5.0.3523.1700" negate="false"/>
          <criterion test_ref="wrt-19" comment="the patch q824145 is installed (Installed Components key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL352" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Internet Explorer 5.01 Service Pack 3</product>
      </affected>
      <dates>
        <submitted date="2003-11-12-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <modified date="2004-01-21-12:00" comment="Removed the test for Windows 2000 sp3 installed.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of having IE 5.01 sp3 installed.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <modified date="2004-03-04-12:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <status_change date="2004-03-09-12:00">INTERIM</status_change>
        <status_change date="2004-03-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and read arbitrary files by (1) modifying the createTextRange method and using CreateLink, as demonstrated using LinkillerSaveRef, LinkillerJPU, and Linkiller, or (2) modifying the createRange method and using the FIND dialog to select text, as demonstrated using Findeath, aka the "Function Pointer Override Cross Domain" vulnerability.</description>
      <reference source="CVE">CVE-2003-0815</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-55" comment="Internet Explorer 5.01 Service Pack 3 is installed" negate="false"/>
          <criterion test_ref="wft-23" comment="the version of mshtml.dll is less than 5.0.3523.1700" negate="false"/>
          <criterion test_ref="wrt-19" comment="the patch q824145 is installed (Installed Components key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL353" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Internet Explorer 5.01 Service Pack 4</product>
      </affected>
      <dates>
        <submitted date="2003-11-12-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <modified date="2004-01-21-12:00" comment="Removed the test for Windows 2000 sp4 installed.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of having IE 5.01 sp4 installed.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <modified date="2004-03-04-12:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <status_change date="2004-03-09-12:00">INTERIM</status_change>
        <status_change date="2004-03-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and read arbitrary files by (1) modifying the createTextRange method and using CreateLink, as demonstrated using LinkillerSaveRef, LinkillerJPU, and Linkiller, or (2) modifying the createRange method and using the FIND dialog to select text, as demonstrated using Findeath, aka the "Function Pointer Override Cross Domain" vulnerability.</description>
      <reference source="CVE">CVE-2003-0815</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-54" comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false"/>
          <criterion test_ref="wft-24" comment="the version of mshtml.dll is less than 5.0.3810.1700" negate="false"/>
          <criterion test_ref="wrt-19" comment="the patch q824145 is installed (Installed Components key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL356" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows ME</windows:platform>
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Internet Explorer 5.5 Service Pack 2</product>
      </affected>
      <dates>
        <submitted date="2003-11-12-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <modified date="2004-01-21-12:00" comment="Removed the test for specific Windows operating systems.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 5.5 sp2 patch.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <modified date="2004-03-04-12:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <status_change date="2004-03-09-12:00">INTERIM</status_change>
        <status_change date="2004-03-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and read arbitrary files by (1) modifying the createTextRange method and using CreateLink, as demonstrated using LinkillerSaveRef, LinkillerJPU, and Linkiller, or (2) modifying the createRange method and using the FIND dialog to select text, as demonstrated using Findeath, aka the "Function Pointer Override Cross Domain" vulnerability.</description>
      <reference source="CVE">CVE-2003-0815</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-53" comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false"/>
          <criterion test_ref="wft-25" comment="the version of mshtml.dll is less than 5.50.4934.1600" negate="false"/>
          <criterion test_ref="wrt-19" comment="the patch q824145 is installed (Installed Components key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL357" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows ME</windows:platform>
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Microsoft Internet Explorer 6 Service Pack 1</product>
      </affected>
      <dates>
        <submitted date="2003-11-12-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <modified date="2004-01-21-12:00" comment="Removed the test for specific Windows operating systems.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 6 sp1 patch.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <modified date="2004-01-29-12:00" comment="Added Windows XP 64-bit to the list of affected platforms">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <modified date="2004-03-04-12:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <status_change date="2004-03-09-12:00">INTERIM</status_change>
        <status_change date="2004-03-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and read arbitrary files by (1) modifying the createTextRange method and using CreateLink, as demonstrated using LinkillerSaveRef, LinkillerJPU, and Linkiller, or (2) modifying the createRange method and using the FIND dialog to select text, as demonstrated using Findeath, aka the "Function Pointer Override Cross Domain" vulnerability.</description>
      <reference source="CVE">CVE-2003-0815</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-50" comment="Internet Explorer 6 Service Pack 1 is installed" negate="false"/>
          <criterion test_ref="wft-27" comment="the version of mshtml.dll is less than 6.0.2800.1276" negate="false"/>
          <criterion test_ref="wrt-19" comment="the patch q824145 is installed (Installed Components key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL358" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>cpio</product>
      </affected>
      <dates>
        <submitted date="2005-08-08-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2005-08-09-07:56">DRAFT</status_change>
        <status_change date="2005-08-24-09:56">INTERIM</status_change>
        <status_change date="2005-09-21-01:33">ACCEPTED</status_change>
      </dates>
      <description>Race condition in cpio 2.6 and earlier allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by cpio after the decompression is complete.</description>
      <reference source="CVE">CVE-2005-1111</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="rvt-28" comment="cpio rpm is older than 0:2.5-4.RHEL3" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="upt-61" comment="/bin/cpio is executable by all" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL359" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Internet Explorer 6 Service Pack 1 for Windows Server 2003</product>
      </affected>
      <dates>
        <submitted date="2003-11-12-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <modified date="2004-01-21-12:00" comment="Removed the test for Windows Server 2003.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 6 sp1 patch.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <modified date="2004-01-29-12:00" comment="Added Windows XP 64-bit, Version 2003 and Windows Server 2003 64-Bit to the list of affected platforms">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <modified date="2004-03-04-12:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <status_change date="2004-03-09-12:00">INTERIM</status_change>
        <status_change date="2004-03-25-12:00">ACCEPTED</status_change>
        <modified date="2005-05-10-12:00" comment="modified wrt-51 - Comment updated to indicate IE 6.">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </modified>
        <status_change date="2005-05-11-05:33">INTERIM</status_change>
        <status_change date="2005-06-01-03:30">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and read arbitrary files by (1) modifying the createTextRange method and using CreateLink, as demonstrated using LinkillerSaveRef, LinkillerJPU, and Linkiller, or (2) modifying the createRange method and using the FIND dialog to select text, as demonstrated using Findeath, aka the "Function Pointer Override Cross Domain" vulnerability.</description>
      <reference source="CVE">CVE-2003-0815</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-51" comment="Internet Explorer 6  for Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wft-28" comment="the version of mshtml.dll is less than 6.0.3790.94" negate="false"/>
          <criterion test_ref="wrt-60" comment="the patch q824145 is installed (Hotfix key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL361" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Internet Explorer 5.01 Service Pack 2</product>
      </affected>
      <dates>
        <submitted date="2003-11-12-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <modified date="2004-01-21-12:00" comment="Removed the test for Windows 2000 sp2 installed.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 5.01 sp2 patch.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <modified date="2004-03-04-12:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <status_change date="2004-03-09-12:00">INTERIM</status_change>
        <status_change date="2004-03-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions by (1) using the NavigateAndFind method to load a file: URL containing Javascript, as demonstrated by NAFfileJPU, (2) using the window.open method to load a file: URL containing Javascript, as demonstrated using WsOpenFileJPU, (3) setting the href property in the base tag for the _search window, as demonstrated using WsBASEjpu, (4) loading the search window into an Iframe, as demonstrated using WsFakeSrc, (5) caching a javascript: URL in the browser history, then accessing that URL in the same frame as the target domain, as demonstrated using WsOpenJpuInHistory, NAFjpuInHistory, BackMyParent, BackMyParent2, and RefBack, aka the "Script URLs Cross Domain" vulnerability.</description>
      <reference source="CVE">CVE-2003-0816</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-56" comment="Internet Explorer 5.01 Service Pack 2 is installed" negate="false"/>
          <criterion test_ref="wft-23" comment="the version of mshtml.dll is less than 5.0.3523.1700" negate="false"/>
          <criterion test_ref="wrt-19" comment="the patch q824145 is installed (Installed Components key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL362" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Internet Explorer 5.01 Service Pack 3</product>
      </affected>
      <dates>
        <submitted date="2003-11-12-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <modified date="2004-01-21-12:00" comment="Removed the test for Windows 2000 sp3 installed.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 5.01 sp3 patch.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <modified date="2004-03-04-12:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <status_change date="2004-03-09-12:00">INTERIM</status_change>
        <status_change date="2004-03-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions by (1) using the NavigateAndFind method to load a file: URL containing Javascript, as demonstrated by NAFfileJPU, (2) using the window.open method to load a file: URL containing Javascript, as demonstrated using WsOpenFileJPU, (3) setting the href property in the base tag for the _search window, as demonstrated using WsBASEjpu, (4) loading the search window into an Iframe, as demonstrated using WsFakeSrc, (5) caching a javascript: URL in the browser history, then accessing that URL in the same frame as the target domain, as demonstrated using WsOpenJpuInHistory, NAFjpuInHistory, BackMyParent, BackMyParent2, and RefBack, aka the "Script URLs Cross Domain" vulnerability.</description>
      <reference source="CVE">CVE-2003-0816</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-55" comment="Internet Explorer 5.01 Service Pack 3 is installed" negate="false"/>
          <criterion test_ref="wft-23" comment="the version of mshtml.dll is less than 5.0.3523.1700" negate="false"/>
          <criterion test_ref="wrt-19" comment="the patch q824145 is installed (Installed Components key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL363" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Internet Explorer 5.01 Service Pack 4</product>
      </affected>
      <dates>
        <submitted date="2003-11-12-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <modified date="2004-01-21-12:00" comment="Removed the test for Windows 2000 sp4 installed.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 5.01 sp4 patch.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <modified date="2004-03-04-12:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <status_change date="2004-03-09-12:00">INTERIM</status_change>
        <status_change date="2004-03-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions by (1) using the NavigateAndFind method to load a file: URL containing Javascript, as demonstrated by NAFfileJPU, (2) using the window.open method to load a file: URL containing Javascript, as demonstrated using WsOpenFileJPU, (3) setting the href property in the base tag for the _search window, as demonstrated using WsBASEjpu, (4) loading the search window into an Iframe, as demonstrated using WsFakeSrc, (5) caching a javascript: URL in the browser history, then accessing that URL in the same frame as the target domain, as demonstrated using WsOpenJpuInHistory, NAFjpuInHistory, BackMyParent, BackMyParent2, and RefBack, aka the "Script URLs Cross Domain" vulnerability.</description>
      <reference source="CVE">CVE-2003-0816</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-54" comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false"/>
          <criterion test_ref="wft-24" comment="the version of mshtml.dll is less than 5.0.3810.1700" negate="false"/>
          <criterion test_ref="wrt-19" comment="the patch q824145 is installed (Installed Components key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL364" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Microsoft FrontPage Server Extensions 2000</product>
      </affected>
      <dates>
        <submitted date="2003-12-09-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <modified date="2004-03-05-12:00" comment="Changed the definition to test for fp30reg.dll and fp4areg.dll instead of fp4awel.dll.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <status_change date="2004-03-09-12:00">INTERIM</status_change>
        <status_change date="2004-03-25-12:00">ACCEPTED</status_change>
        <modified date="2005-09-26-10:50" comment="modified wft-114 - Changed comment to match test">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <modified date="2005-09-27-01:22" comment="modified wft-31 - Changed comment to match test">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-28-01:04">INTERIM</status_change>
        <status_change date="2005-10-19-05:47">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the debug functionality in fp30reg.dll of Microsoft FrontPage Server Extensions (FPSE) 2000 and 2002 allows remote attackers to execute arbitrary code via a crafted chunked encoded request.</description>
      <reference source="CVE">CVE-2003-0822</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-66" comment="Windows XP (sp1 or earlier) is installed" negate="false"/>
          <criterion test_ref="cmp-112" comment="a vulnerable version of fp30reg.dll or fp4areg.dll exists" negate="false"/>
          <criterion test_ref="wrt-88" comment="the patch q810217 is installed (Hotfix key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-31" comment="FrontPage Server Extensions 2000 are enabled (2K, XP)" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL366" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Microsoft FrontPage Server Extensions 2002</product>
      </affected>
      <dates>
        <submitted date="2003-12-09-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <modified date="2004-03-05-12:00" comment="Changed the definition to test for fp30reg.dll and fp5areg.dll instead of fp5awel.dll.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <status_change date="2004-03-09-12:00">INTERIM</status_change>
        <status_change date="2004-03-25-12:00">ACCEPTED</status_change>
        <modified date="2004-09-14-09:51" comment="XP SP2 added">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2004-09-15-12:00">INTERIM</status_change>
        <status_change date="2004-09-29-12:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the debug functionality in fp30reg.dll of Microsoft FrontPage Server Extensions (FPSE) 2000 and 2002 allows remote attackers to execute arbitrary code via a crafted chunked encoded request.</description>
      <reference source="CVE">CVE-2003-0822</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-77" comment="Windows NT, 2000, or XP is installed" negate="false"/>
          <criterion test_ref="cmp-113" comment="a vulnerable version of fp30reg.dll or fp5areg.dll exists" negate="false"/>
          <criterion test_ref="wrt-29" comment="Win2K/XP/2003 service pack 2 (or later) is installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-32" comment="FrontPage Server Extensions 2002 are enabled (NT, 2K, XP)" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL367" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft SharePoint Team Services</product>
      </affected>
      <dates>
        <submitted date="2003-12-09-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <modified date="2004-03-05-12:00" comment="Changed the definition to test for fp30reg.dll and fp5areg.dll instead of fp5awel.dll.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <status_change date="2004-03-09-12:00">INTERIM</status_change>
        <status_change date="2004-03-25-12:00">ACCEPTED</status_change>
        <modified date="2004-09-14-09:52" comment="XP SP2 added">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2004-09-15-12:00">INTERIM</status_change>
        <status_change date="2004-09-29-12:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the debug functionality in fp30reg.dll of Microsoft FrontPage Server Extensions (FPSE) 2000 and 2002 allows remote attackers to execute arbitrary code via a crafted chunked encoded request.</description>
      <reference source="CVE">CVE-2003-0822</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-78" comment="Windows 2000, XP, or 2003 is installed" negate="false"/>
          <criterion test_ref="cmp-113" comment="a vulnerable version of fp30reg.dll or fp5areg.dll exists" negate="false"/>
          <criterion test_ref="wrt-29" comment="Win2K/XP/2003 service pack 2 (or later) is installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-32" comment="FrontPage Server Extensions 2002 are enabled (NT, 2K, XP)" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL368" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Internet Explorer 5.01 Service Pack 2</product>
      </affected>
      <dates>
        <submitted date="2003-12-18-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <modified date="2004-01-21-12:00" comment="Removed the test for Windows 2000 sp2 installed.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 5.01 sp2 patch.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <modified date="2004-03-04-12:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <status_change date="2004-03-09-12:00">INTERIM</status_change>
        <status_change date="2004-03-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 6 SP1 and earlier allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by calling the window.moveBy method, aka HijackClick, a different vulnerability than CVE-2003-1027.</description>
      <reference source="CVE">CVE-2003-0823</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-56" comment="Internet Explorer 5.01 Service Pack 2 is installed" negate="false"/>
          <criterion test_ref="wft-23" comment="the version of mshtml.dll is less than 5.0.3523.1700" negate="false"/>
          <criterion test_ref="wrt-19" comment="the patch q824145 is installed (Installed Components key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL369" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Internet Explorer 5.01 Service Pack 3</product>
      </affected>
      <dates>
        <submitted date="2003-12-18-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <modified date="2004-01-21-12:00" comment="Removed the test for Windows 2000 sp3 installed.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 5.01 sp3 patch.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <modified date="2004-03-04-12:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <status_change date="2004-03-09-12:00">INTERIM</status_change>
        <status_change date="2004-03-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 6 SP1 and earlier allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by calling the window.moveBy method, aka HijackClick, a different vulnerability than CVE-2003-1027.</description>
      <reference source="CVE">CVE-2003-0823</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-55" comment="Internet Explorer 5.01 Service Pack 3 is installed" negate="false"/>
          <criterion test_ref="wft-23" comment="the version of mshtml.dll is less than 5.0.3523.1700" negate="false"/>
          <criterion test_ref="wrt-19" comment="the patch q824145 is installed (Installed Components key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL370" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Internet Explorer 5.01 Service Pack 4</product>
      </affected>
      <dates>
        <submitted date="2003-12-18-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <modified date="2004-01-21-12:00" comment="Removed the test for Windows 2000 sp4 installed.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 5.01 sp4 patch.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <modified date="2004-03-04-12:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <status_change date="2004-03-09-12:00">INTERIM</status_change>
        <status_change date="2004-03-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 6 SP1 and earlier allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by calling the window.moveBy method, aka HijackClick, a different vulnerability than CVE-2003-1027.</description>
      <reference source="CVE">CVE-2003-0823</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-54" comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false"/>
          <criterion test_ref="wft-24" comment="the version of mshtml.dll is less than 5.0.3810.1700" negate="false"/>
          <criterion test_ref="wrt-19" comment="the patch q824145 is installed (Installed Components key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL371" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows ME</windows:platform>
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Internet Explorer 5.5 Service Pack 2</product>
      </affected>
      <dates>
        <submitted date="2003-12-18-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <modified date="2004-01-21-12:00" comment="Removed the test for specific Windows operating systems.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 5.5 sp2 patch.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <modified date="2004-03-04-12:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <status_change date="2004-03-09-12:00">INTERIM</status_change>
        <status_change date="2004-03-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 6 SP1 and earlier allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by calling the window.moveBy method, aka HijackClick, a different vulnerability than CVE-2003-1027.</description>
      <reference source="CVE">CVE-2003-0823</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-53" comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false"/>
          <criterion test_ref="wft-25" comment="the version of mshtml.dll is less than 5.50.4934.1600" negate="false"/>
          <criterion test_ref="wrt-19" comment="the patch q824145 is installed (Installed Components key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL372" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows ME</windows:platform>
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Microsoft Internet Explorer 6 Service Pack 1</product>
      </affected>
      <dates>
        <submitted date="2003-12-18-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <modified date="2004-01-21-12:00" comment="Removed the test for specific Windows operating systems.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 6 sp1 patch.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <modified date="2004-01-29-12:00" comment="Added Windows XP 64-bit to the list of affected platforms">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <modified date="2004-03-04-12:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <status_change date="2004-03-09-12:00">INTERIM</status_change>
        <status_change date="2004-03-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 6 SP1 and earlier allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by calling the window.moveBy method, aka HijackClick, a different vulnerability than CVE-2003-1027.</description>
      <reference source="CVE">CVE-2003-0823</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-50" comment="Internet Explorer 6 Service Pack 1 is installed" negate="false"/>
          <criterion test_ref="wft-27" comment="the version of mshtml.dll is less than 6.0.2800.1276" negate="false"/>
          <criterion test_ref="wrt-19" comment="the patch q824145 is installed (Installed Components key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL373" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Internet Information Server 5.0</product>
      </affected>
      <dates>
        <submitted date="2003-10-10-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <modified date="2005-03-07-12:00" comment="modified wrt-222 - changed pattern match">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-03-09-07:55">INTERIM</status_change>
        <status_change date="2005-03-29-07:59">ACCEPTED</status_change>
      </dates>
      <description>The ASP function Response.AddHeader in Microsoft Internet Information Server (IIS) 4.0 and 5.0 does not limit memory requests when constructing headers, which allow remote attackers to generate a large header to cause a denial of service (memory consumption) with an ASP page.</description>
      <reference source="CVE">CVE-2003-0225</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-223" comment="IIS major version equals 5" negate="false"/>
          <criterion test_ref="wrt-215" comment="IIS minor version equals 0" negate="false"/>
          <criterion test_ref="wft-221" comment="File %windir%\system32\inetsrv\asp.dll version is less than 5.0.2195.6672" negate="false"/>
          <criterion test_ref="wrt-219" comment="Patch Q811114 Installed" negate="true"/>
          <criterion test_ref="wrt-222" comment="SP4 or later Installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL374" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>HTML Help ActiveX Control</product>
      </affected>
      <dates>
        <submitted date="2003-09-18-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <modified date="2004-03-04-12:00" comment="Added the configuration check to see if active scripting is enabled by the current user when local machine settings are not in use.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <status_change date="2004-03-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the HTML Help ActiveX Control (hhctrl.ocx) in Microsoft Windows 98, 98 Second Edition, Millennium Edition, NT 4.0, NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows remote attackers to execute code via (1) a long parameter to the Alink function, or (2) script containing a long argument to the showHelp function.</description>
      <reference source="CVE">CVE-2002-0693</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
          <criterion test_ref="wft-286" comment="the version of hhctrl.ocx is less than 5.2.3669.0" negate="false"/>
          <criterion test_ref="wft-287" comment="the version of hhsetup.dll is less than 5.2.3644.0" negate="false"/>
          <criterion test_ref="wft-102" comment="the version of itircl.dll is less than 5.2.3644.0" negate="false"/>
          <criterion test_ref="wft-103" comment="the version of itss.dll is less than 5.2.3644.0" negate="false"/>
          <criterion test_ref="wrt-328" comment="the patch q323255 is installed (Hotfix key)" negate="true"/>
          <criterion test_ref="cmp-212" comment="Windows 2000 Service Pack 4 (or later) is installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-76" comment="active scripting is enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL380" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Linux kernel</product>
      </affected>
      <dates>
        <submitted date="2003-09-26-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>The STP protocol, as enabled in Linux 2.4.x, does not provide sufficient security by design, which allows attackers to modify the bridge topology.</description>
      <reference source="CVE">CVE-2003-0550</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-223" comment="kernel version is less than 2.4.20-19.9" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL381" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>HTML Help Facility</product>
      </affected>
      <dates>
        <submitted date="2005-06-20-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <status_change date="2005-06-22-12:38">DRAFT</status_change>
        <status_change date="2005-07-27-10:37">INTERIM</status_change>
        <status_change date="2005-08-18-07:37">ACCEPTED</status_change>
      </dates>
      <description>Integer overflow in Microsoft Windows 98, 2000, XP SP2 and earlier, and Server 2003 SP1 and earlier allows remote attackers to execute arbitrary code via a crafted compiled Help (.CHM) file with a large size field that triggers a heap-based buffer overflow, as demonstrated using a "ms-its:" URL in Internet Explorer.</description>
      <reference source="CVE">CVE-2005-1208</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="cmp-84" comment="a vulnerable version of hh.exe exists" negate="false"/>
          <criterion test_ref="wrt-57" comment="the patch kb896358 is installed (Hotfix key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL382" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>gzip</product>
      </affected>
      <dates>
        <submitted date="2005-06-20-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2005-06-22-12:38">DRAFT</status_change>
        <status_change date="2005-07-27-10:37">INTERIM</status_change>
        <status_change date="2005-08-18-07:37">ACCEPTED</status_change>
      </dates>
      <description>Directory traversal vulnerability in gunzip -N in gzip 1.2.4 through 1.3.5 allows remote attackers to write to arbitrary directories via a .. (dot dot) in the original filename within a compressed file.</description>
      <reference source="CVE">CVE-2005-1228</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="rvt-7" comment="gzip RPM earlier than 0:1.3.3-12rhel3" negate="false"/>
        </software>
        <configuration operation="OR">
          <criterion test_ref="upt-529" comment="/usr/bin/gzip is executable" negate="false"/>
          <criterion test_ref="upt-428" comment="/usr/bin/gunzip is executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL384" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Linux kernel</product>
      </affected>
      <dates>
        <submitted date="2003-09-26-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>The STP protocol implementation in Linux 2.4.x does not properly verify certain lengths, which could allow attackers to cause a denial of service.</description>
      <reference source="CVE">CVE-2003-0551</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-223" comment="kernel version is less than 2.4.20-19.9" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL385" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Linux kernel</product>
      </affected>
      <dates>
        <submitted date="2003-09-26-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Linux 2.4.x allows remote attackers to spoof the bridge Forwarding table via forged packets whose source addresses are the same as the target.</description>
      <reference source="CVE">CVE-2003-0552</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-223" comment="kernel version is less than 2.4.20-19.9" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL386" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Linux kernel</product>
      </affected>
      <dates>
        <submitted date="2003-09-25-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Integer signedness error in the decode_fh function of nfs3xdr.c in Linux kernel before 2.4.21 allows remote attackers to cause a denial of service (kernel panic) via a negative size value within XDR data of an NFSv3 procedure call.</description>
      <reference source="CVE">CVE-2003-0619</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-221" comment="kernel version is less than 2.4.20-13.9" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL387" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Linux kernel</product>
      </affected>
      <dates>
        <submitted date="2003-09-26-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>The C-Media PCI sound driver in Linux before 2.4.21 does not use the get_user function to access userspace, which crosses security boundaries and may facilitate the exploitation of vulnerabilities, a different vulnerability than CVE-2003-0700.</description>
      <reference source="CVE">CVE-2003-0699</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-223" comment="kernel version is less than 2.4.20-19.9" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL388" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Internet Explorer 6.0</product>
      </affected>
      <dates>
        <submitted date="2004-01-27-05:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2004-03-09-05:00">ACCEPTED</status_change>
        <modified date="2005-09-20-04:00" comment="Changed IE registry test to wrt-18">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-21-01:27">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 5.5 and 6.0 allows remote attackers to bypass the cross-domain security model and access information on the local system or in other domains, and possibly execute code, via cached methods and objects, aka "Cross Domain Verification via Cached Methods."</description>
      <reference source="CVE">CVE-2002-1254</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wft-241" comment="the version of mshtml.dll is less than 6.0.2722.900" negate="false"/>
          <criterion test_ref="wrt-206" comment="the patch q328970 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-207" comment="the patch q324929 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-208" comment="the patch q810847 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-209" comment="the patch q813489 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-210" comment="the patch q818529 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-211" comment="the patch q822925 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-212" comment="the patch q828750 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-19" comment="the patch q824145 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-18" comment="Internet Explorer 6 is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL390" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Internet Explorer 5.01 Service Pack 4</product>
      </affected>
      <dates>
        <submitted date="2005-08-23-04:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2005-08-25-10:05">DRAFT</status_change>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
        <modified date="2005-12-26-09:40" comment="Removed reference to patch kb896727 from criteria.">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </modified>
        <status_change date="2006-01-12-08:59">ACCEPTED</status_change>
      </dates>
      <description>Unknown vulnerability in Internet Explorer 5.0, 5.5, and 6.0 allows remote attackers to execute arbitrary code via a web site or an HTML e-mail containing a crafted JPEG image that causes memory corruption, aka "JPEG Image Rendering Memory Corruption Vulnerability".</description>
      <reference source="CVE">CVE-2005-1988</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-54" comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false"/>
          <criterion test_ref="wft-629" comment="the version of mshtml.dll is less than 5.0.3831.1800" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL392" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Microsoft Internet Explorer 6</product>
      </affected>
      <dates>
        <submitted date="2003-11-12-05:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <modified date="2004-01-21-05:00" comment="Removed the test for Windows XP.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 6 patch.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <modified date="2004-03-04-05:00" comment="Removed the IE 6 SP 1 part of this definition as the SP 1 part is defined in a different OVAL.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <status_change date="2004-03-09-05:00">INTERIM</status_change>
        <status_change date="2004-03-25-05:00">ACCEPTED</status_change>
        <modified date="2005-09-20-04:00" comment="modified wrt-18 - Changed value element to include pattern match">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-21-01:27">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and execute Javascript by setting the window's "href" to the malicious Javascript, then calling execCommand("Refresh") to refresh the page, aka BodyRefreshLoadsJPU or the "ExecCommand Cross Domain" vulnerability.</description>
      <reference source="CVE">CVE-2003-0814</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-18" comment="Internet Explorer 6 is installed" negate="false"/>
          <criterion test_ref="wft-26" comment="the version of mshtml.dll is less than 6.0.2734.1600" negate="false"/>
          <criterion test_ref="wrt-19" comment="the patch q824145 is installed (Installed Components key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL393" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Internet Explorer 6.0</product>
      </affected>
      <dates>
        <submitted date="2004-01-27-05:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2004-03-09-05:00">ACCEPTED</status_change>
        <modified date="2005-09-20-04:00" comment="Changed IE registry test to wrt-18">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-21-01:27">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 5.01 through 6.0 does not properly check certain parameters of a PNG file when opening it, which allows remote attackers to cause a denial of service (crash) by triggering a heap-based buffer overflow using invalid length codes during decompression, aka "Malformed PNG Image File Failure."</description>
      <reference source="CVE">CVE-2002-1185</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wft-241" comment="the version of mshtml.dll is less than 6.0.2722.900" negate="false"/>
          <criterion test_ref="wrt-206" comment="the patch q328970 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-207" comment="the patch q324929 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-208" comment="the patch q810847 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-209" comment="the patch q813489 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-210" comment="the patch q818529 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-211" comment="the patch q822925 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-212" comment="the patch q828750 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-19" comment="the patch q824145 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-18" comment="Internet Explorer 6 is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL401" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Linux kernel</product>
      </affected>
      <dates>
        <submitted date="2003-09-26-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>The C-Media PCI sound driver in Linux before 2.4.22 does not use the get_user function to access userspace in certain conditions, which crosses security boundaries and may facilitate the exploitation of vulnerabilities, a different vulnerability than CVE-2003-0699.</description>
      <reference source="CVE">CVE-2003-0700</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-223" comment="kernel version is less than 2.4.20-19.9" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL402" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>Simple Network Management Protocol (SNMP)</product>
      </affected>
      <dates>
        <submitted date="2004-09-15-12:43">
          <contributor organization="The MITRE Corporation">Matt Busby</contributor>
        </submitted>
        <modified date="2004-09-15-03:43" comment="Filled out initial submission.  Now a complete definition.">
          <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
        </modified>
        <status_change date="2004-09-22-02:10">DRAFT</status_change>
        <status_change date="2004-10-06-12:00">INTERIM</status_change>
        <status_change date="2004-10-20-12:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in SNMP agent service in Windows 95/98/98SE, Windows NT 4.0, Windows 2000, and Windows XP allows remote attackers to cause a denial of service or execute arbitrary code via a malformed management request.  NOTE: this candidate may be split or merged with other candidates.  This and other PROTOS-related candidates, especially CVE-2002-0012 and CVE-2002-0013, will be updated when more accurate information is available.</description>
      <reference source="CVE">CVE-2002-0053</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" negate="false"/>
          <criterion test_ref="wft-242" comment="the version of snmp.exe is less than 5.0.2195.4919" negate="false"/>
          <criterion test_ref="wrt-263" comment="Patch Q314147 Installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-264" comment="the SNMP service is enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL403" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>HTML Help Facility</product>
      </affected>
      <dates>
        <submitted date="2003-09-30-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2004-03-09-12:00">ACCEPTED</status_change>
        <modified date="2005-03-07-12:00" comment="modified wrt-222 - changed pattern match">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-03-09-07:55">INTERIM</status_change>
        <status_change date="2005-03-29-07:59">ACCEPTED</status_change>
      </dates>
      <description>The HTML Help facility in Microsoft Windows 98, 98 Second Edition, Millennium Edition, NT 4.0, NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP uses the Local Computer Security Zone when opening .chm files from the Temporary Internet Files folder, which allows remote attackers to execute arbitrary code via HTML mail that references or inserts a malicious .chm file containing shortcuts that can be executed, aka "Code Execution via Compiled HTML Help File."</description>
      <reference source="CVE">CVE-2002-0694</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
          <criterion test_ref="wft-287" comment="the version of hhsetup.dll is less than 5.2.3644.0" negate="false"/>
          <criterion test_ref="wft-102" comment="the version of itircl.dll is less than 5.2.3644.0" negate="false"/>
          <criterion test_ref="wft-103" comment="the version of itss.dll is less than 5.2.3644.0" negate="false"/>
          <criterion test_ref="wrt-328" comment="the patch q323255 is installed (Hotfix key)" negate="true"/>
          <criterion test_ref="wrt-222" comment="SP4 or later Installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL406" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>ISA Server 2000</product>
      </affected>
      <dates>
        <submitted date="2003-12-03-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <status_change date="2004-03-09-12:00">ACCEPTED</status_change>
      </dates>
      <description>The Winsock Proxy service in Microsoft Proxy Server 2.0 and the Microsoft Firewall service in Internet Security and Acceleration (ISA) Server 2000 allow remote attackers to cause a denial of service (CPU consumption or packet storm) via a spoofed, malformed packet to UDP port 1745.</description>
      <reference source="CVE">CVE-2003-0110</reference>
      <status>ACCEPTED</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-105" comment="ISA Server 2000 is installed" negate="false"/>
          <criterion test_ref="wft-100" comment="the version of w3proxy.exe is less than 3.0.1200.257" negate="false"/>
          <criterion test_ref="wft-101" comment="the version of wpsrv.exe is less than 3.0.1200.257" negate="false"/>
          <criterion test_ref="wrt-331" comment="Patch isahf257 installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-332" comment="Microsoft Firewall Service Enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL407" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Windows Shell</product>
      </affected>
      <dates>
        <submitted date="2005-05-04-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2005-05-04-12:32">DRAFT</status_change>
        <status_change date="2005-06-01-03:30">INTERIM</status_change>
        <status_change date="2005-06-22-12:38">ACCEPTED</status_change>
      </dates>
      <description>The document processing application used by the Windows Shell in Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code by modifying the CLSID stored in a file so that it is processed by HTML Application Host (MSHTA), as demonstrated using a Microsoft Word document.</description>
      <reference source="CVE">CVE-2005-0063</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-182" comment="Microsoft Windows Server 2003 32-Bit Edition" negate="false"/>
          <criterion test_ref="wft-588" comment="the version of shell32.dll is less than 6.0.3790.280" negate="false"/>
          <criterion test_ref="wrt-434" comment="the patch  KB893086 is installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-280" comment=".hta applications are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL408" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Internet Explorer 5.5</product>
      </affected>
      <dates>
        <submitted date="2004-01-27-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2004-03-09-12:00">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 5.5 and 6.0 allows remote attackers to bypass the cross-domain security model and access information on the local system or in other domains, and possibly execute code, via cached methods and objects, aka "Cross Domain Verification via Cached Methods."</description>
      <reference source="CVE">CVE-2002-1254</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-271" comment="Internet Explorer 5.5 Installed" negate="false"/>
          <criterion test_ref="wft-262" comment="the version of mshtml.dll is less than 5.50.4922.900" negate="false"/>
          <criterion test_ref="wrt-206" comment="the patch q328970 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-207" comment="the patch q324929 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-208" comment="the patch q810847 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-209" comment="the patch q813489 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-210" comment="the patch q818529 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-211" comment="the patch q822925 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-212" comment="the patch q828750 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-19" comment="the patch q824145 is installed (Installed Components key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL409" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows ME</windows:platform>
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Internet Explorer 5.5 Service Pack 2</product>
      </affected>
      <dates>
        <submitted date="2003-11-12-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <modified date="2004-01-21-12:00" comment="Removed the test for specific Windows operating systems.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 5.5 sp2 patch.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <modified date="2004-03-04-12:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <status_change date="2004-03-09-12:00">INTERIM</status_change>
        <status_change date="2004-03-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions by (1) using the NavigateAndFind method to load a file: URL containing Javascript, as demonstrated by NAFfileJPU, (2) using the window.open method to load a file: URL containing Javascript, as demonstrated using WsOpenFileJPU, (3) setting the href property in the base tag for the _search window, as demonstrated using WsBASEjpu, (4) loading the search window into an Iframe, as demonstrated using WsFakeSrc, (5) caching a javascript: URL in the browser history, then accessing that URL in the same frame as the target domain, as demonstrated using WsOpenJpuInHistory, NAFjpuInHistory, BackMyParent, BackMyParent2, and RefBack, aka the "Script URLs Cross Domain" vulnerability.</description>
      <reference source="CVE">CVE-2003-0816</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-53" comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false"/>
          <criterion test_ref="wft-25" comment="the version of mshtml.dll is less than 5.50.4934.1600" negate="false"/>
          <criterion test_ref="wrt-19" comment="the patch q824145 is installed (Installed Components key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL411" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Konqueror</product>
      </affected>
      <dates>
        <submitted date="2003-09-04-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <status_change date="2004-05-05-12:00">ACCEPTED</status_change>
      </dates>
      <description>KDE Konqueror for KDE 3.1.2 and earlier does not remove authentication credentials from URLs of the "user:password@host" form in the HTTP-Referer header, which could allow remote web sites to steal the credentials for pages that link to the sites.</description>
      <reference source="CVE">CVE-2003-0459</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-224" comment="kdelibs version is less than 3.1-12" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-304" comment="/usr/bin/konqueror is executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL416" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows ME</windows:platform>
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Microsoft Internet Explorer 6 Service Pack 1</product>
      </affected>
      <dates>
        <submitted date="2003-11-12-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <modified date="2004-01-21-12:00" comment="Removed the test for specific Windows operating systems.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 6 sp1 patch.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <modified date="2004-01-29-12:00" comment="Added Windows XP 64-bit to the list of affected platforms">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <modified date="2004-03-04-12:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <status_change date="2004-03-09-12:00">INTERIM</status_change>
        <status_change date="2004-03-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions by (1) using the NavigateAndFind method to load a file: URL containing Javascript, as demonstrated by NAFfileJPU, (2) using the window.open method to load a file: URL containing Javascript, as demonstrated using WsOpenFileJPU, (3) setting the href property in the base tag for the _search window, as demonstrated using WsBASEjpu, (4) loading the search window into an Iframe, as demonstrated using WsFakeSrc, (5) caching a javascript: URL in the browser history, then accessing that URL in the same frame as the target domain, as demonstrated using WsOpenJpuInHistory, NAFjpuInHistory, BackMyParent, BackMyParent2, and RefBack, aka the "Script URLs Cross Domain" vulnerability.</description>
      <reference source="CVE">CVE-2003-0816</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-50" comment="Internet Explorer 6 Service Pack 1 is installed" negate="false"/>
          <criterion test_ref="wft-27" comment="the version of mshtml.dll is less than 6.0.2800.1276" negate="false"/>
          <criterion test_ref="wrt-19" comment="the patch q824145 is installed (Installed Components key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL417" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 4</redhat:platform>
        <product>mozilla</product>
      </affected>
      <dates>
        <submitted date="2005-08-15-04:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2005-08-19-10:05">DRAFT</status_change>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 and 7.2 allows remote attackers to cause a denial of service (access violation and crash), and possibly execute arbitrary code, by calling InstallVersion.compareTo with an object instead of a string.</description>
      <reference source="CVE">CVE-2005-2265</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-1" comment="Red Hat Enterprise 4 is installed" negate="false"/>
          <criterion test_ref="rvt-32" comment="mozilla RPM is earlier than 37:1.7.10-1.4.1" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="upt-859" comment="/usr/bin/mozilla is executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL420" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 95</windows:platform>
        <windows:platform>Microsoft Windows 98</windows:platform>
        <windows:platform>Microsoft Windows ME</windows:platform>
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Word 2003</product>
      </affected>
      <dates>
        <submitted date="2005-09-15-04:00">
          <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
        </submitted>
        <status_change date="2005-09-21-01:33">DRAFT</status_change>
        <status_change date="2005-10-12-05:49">INTERIM</status_change>
        <status_change date="2005-11-16-08:02">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in Microsoft Word 2002 (10.6612.6714) SP3, and possibly other versions, allows remote attackers to cause a denial of service (application exception) and possibly execute arbitrary code in winword.exe via certain unexpected values in a .doc file, including (1) an offset that triggers an out-of-bounds memory access, (2) a certain value that causes a large memory copy as triggered by an integer conversion error, and other values.</description>
      <reference source="CVE">CVE-2004-0963</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-607" comment="Word 2003 is installed" negate="false"/>
          <criterion test_ref="wft-639" comment="the version of wordview.exe is less than 11.0.6506.0" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL423" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>LPRng</product>
      </affected>
      <dates>
        <submitted date="2003-08-17-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>psbanner in the LPRng package allows local users to overwrite arbitrary files via a symbolic link attack on the /tmp/before file.</description>
      <reference source="CVE">CVE-2003-0136</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-225" comment="lprng version is less than 3.8.19-3.1" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="upt-83" comment="psbanner is world-executable" negate="false"/>
          <criterion test_ref="rlt-204" comment="lpd listening on the network" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL424" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Telnet protocol</product>
      </affected>
      <dates>
        <submitted date="2003-10-10-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <modified date="2004-07-20-12:00" comment="Changed patch registry key value to IsInstalled">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2004-07-21-12:00">INTERIM</status_change>
        <status_change date="2004-08-11-12:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in telnet server in Windows 2000 and Interix 2.2 allows remote attackers to execute arbitrary code via malformed protocol options.</description>
      <reference source="CVE">CVE-2002-0020</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
          <criterion test_ref="wft-290" comment="the version of tlntsvr.exe is less than 5.0.33668.1" negate="false"/>
          <criterion test_ref="wrt-333" comment="Patch Q307298 Installed" negate="true"/>
          <criterion test_ref="wrt-259" comment="Windows 2000 Security Roll-up 1 Installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-334" comment="the telnet service is enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL429" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Word 2002</product>
      </affected>
      <dates>
        <submitted date="2004-08-24-12:00">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </submitted>
        <status_change date="2004-08-25-12:00">DRAFT</status_change>
        <status_change date="2004-09-09-12:00">INTERIM</status_change>
        <status_change date="2004-09-29-12:00">ACCEPTED</status_change>
        <modified date="2005-01-13-12:00" comment="modified wft-484 - Corrected registry key in path component">
          <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
        </modified>
        <status_change date="2005-01-20-12:11">INTERIM</status_change>
        <status_change date="2005-02-16-12:00">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Outlook 2000 and 2002, when configured to use Microsoft Word as the email editor, does not block scripts that are used while editing email messages in HTML or Rich Text Format (RTF), which could allow remote attackers to execute arbitrary scripts via an email that the user forwards or replies to.</description>
      <reference source="CVE">CVE-2002-1056</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
          <criterion test_ref="wrt-133" comment="Word 2002 is installed" negate="false"/>
          <criterion test_ref="wft-484" comment="the version of msohev.dll less than 10.0.2609.0" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL430" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>lv</product>
      </affected>
      <dates>
        <submitted date="2003-08-19-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>lv reads a .lv file from the current working directory, which allows local users to execute arbitrary commands as other lv users by placing malicious .lv files into other directories.</description>
      <reference source="CVE">CVE-2003-0188</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-226" comment="lv version is less than 4.49.4-9.9.1" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL434" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Mutt</product>
      </affected>
      <dates>
        <submitted date="2003-08-18-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <status_change date="2004-05-05-12:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in Mutt 1.4.0 and possibly earlier versions, 1.5.x up to 1.5.3, and other programs that use Mutt code such as Balsa before 2.0.10, allows a remote malicious IMAP server to cause a denial of service (crash) and possibly execute arbitrary code via a crafted folder.</description>
      <reference source="CVE">CVE-2003-0140</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-227" comment="mutt version is less than 1.4.1-1" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-305" comment="/usr/bin/mutt is executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL436" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>MySQL</product>
      </affected>
      <dates>
        <submitted date="2003-08-18-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Double-free vulnerability in mysqld for MySQL before 3.23.55 allows attackers with MySQL access to cause a denial of service (crash) via mysql_change_user.</description>
      <reference source="CVE">CVE-2003-0073</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-228" comment="mysql-server version is less than 3.23.56-1.9" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="rlt-205" comment="mysqld is listening to the network" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL440" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Microsoft Color Management Module</product>
      </affected>
      <dates>
        <submitted date="2005-08-02-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2005-08-03-11:30">DRAFT</status_change>
        <status_change date="2005-08-18-07:37">INTERIM</status_change>
        <status_change date="2005-09-21-01:33">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the Microsoft Color Management Module for Windows allows remote attackers to execute arbitrary code via an image with crafted ICC profile format tags.</description>
      <reference source="CVE">CVE-2005-1219</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-57" comment="Windows XP 32-bit SP1 is installed" negate="false"/>
          <criterion test_ref="wft-411" comment="the version of mscms.dll is less than 5.1.2600.1710" negate="false"/>
          <criterion test_ref="wrt-128" comment="the patch KB901214 is installed " negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL442" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>MySQL</product>
      </affected>
      <dates>
        <submitted date="2003-08-18-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>MySQL 3.23.55 and earlier creates world-writeable files and allows mysql users to gain root privileges by using the "SELECT * INFO OUTFILE" operator to overwrite a configuration file and cause mysql to run as root upon restart, as demonstrated by modifying my.cnf.</description>
      <reference source="CVE">CVE-2003-0150</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-228" comment="mysql-server version is less than 3.23.56-1.9" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="rlt-205" comment="mysqld is listening to the network" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL443" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>nfs-utils</product>
      </affected>
      <dates>
        <submitted date="2003-09-02-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Off-by-one error in the xlog function of mountd in the Linux NFS utils package (nfs-utils) before 1.0.4 allows remote attackers to cause a denial of service and possibly execute arbitrary code via certain RPC requests to mountd that do not contain newlines.</description>
      <reference source="CVE">CVE-2003-0252</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-229" comment="nfs-utils version is less than 1.0.1-3.9" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="rlt-206" comment="rpc.mountd listens on the network" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL444" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Internet Explorer 6.0</product>
      </affected>
      <dates>
        <submitted date="2004-01-27-05:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2004-03-09-05:00">ACCEPTED</status_change>
        <modified date="2005-09-20-04:00" comment="Changed IE registry test to wrt-18">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-21-01:27">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 5.01 through 6.0 allows remote attackers to identify the path to the Temporary Internet Files folder and obtain user information such as cookies via certain uses of the OBJECT tag, which are not subjected to the proper security checks, aka "Temporary Internet Files folders Name Reading."</description>
      <reference source="CVE">CVE-2002-1188</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wft-241" comment="the version of mshtml.dll is less than 6.0.2722.900" negate="false"/>
          <criterion test_ref="wrt-206" comment="the patch q328970 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-207" comment="the patch q324929 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-208" comment="the patch q810847 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-209" comment="the patch q813489 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-210" comment="the patch q818529 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-211" comment="the patch q822925 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-212" comment="the patch q828750 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-19" comment="the patch q824145 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-18" comment="Internet Explorer 6 is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL445" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>OpenSSH</product>
      </affected>
      <dates>
        <submitted date="2003-08-29-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>OpenSSH-portable (OpenSSH) 3.6.1p1 and earlier with PAM support enabled immediately sends an error message when a user does not exist, which allows remote attackers to determine valid usernames via a timing attack.</description>
      <reference source="CVE">CVE-2003-0190</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-230" comment="openssh-server version is less than 3.5p1-6.9" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="rlt-207" comment="sshd listens on the network" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL446" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>OpenSSH</product>
      </affected>
      <dates>
        <submitted date="2003-09-21-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>"Memory bugs" in OpenSSH 3.7.1 and earlier, with unknown impact, a different set of vulnerabilities than CVE-2003-0693 and CVE-2003-0695.</description>
      <reference source="CVE">CVE-2003-0682</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-231" comment="openssh-server version is less than 3.5p1-11" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="rlt-207" comment="sshd listens on the network" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL447" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>OpenSSH</product>
      </affected>
      <dates>
        <submitted date="2003-09-21-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>A "buffer management error" in buffer_append_space of buffer.c for OpenSSH before 3.7 may allow remote attackers to execute arbitrary code by causing an incorrect amount of memory to be freed and corrupting the heap, a different vulnerability than CVE-2003-0695.</description>
      <reference source="CVE">CVE-2003-0693</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-231" comment="openssh-server version is less than 3.5p1-11" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="rlt-207" comment="sshd listens on the network" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL449" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Bind</product>
      </affected>
      <dates>
        <submitted date="2005-01-19-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-24-03:40">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>BIND 8.3.x through 8.3.3 allows remote attackers to cause a denial of service (termination due to assertion failure) via a request for a subdomain that does not exist, with an OPT resource record with a large UDP payload size.</description>
      <reference source="CVE">CVE-2002-1220</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-6" comment="Solaris 9 Installed" negate="false"/>
          <criterion test_ref="sat-19" comment="Internet Domain Name Server (BIND, SUNWinamd) installed" negate="false"/>
          <criterion test_ref="spt-26" comment="Patch 112970-03 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-14" comment="in.named running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL450" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Windows kernel</product>
      </affected>
      <dates>
        <submitted date="2004-12-21-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2005-01-12-12:41">DRAFT</status_change>
        <status_change date="2005-02-02-12:00">INTERIM</status_change>
        <status_change date="2005-02-23-09:25">ACCEPTED</status_change>
      </dates>
      <description>The Local Procedure Call (LPC) interface of the Windows Kernel for Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 does not properly validate the lengths of messages sent to the LPC port, which allows local users to gain privileges, aka "Windows Kernel Vulnerability."</description>
      <reference source="CVE">CVE-2004-0893</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-35" comment="Windows XP 32 bit Service Pack 2" negate="false"/>
          <criterion test_ref="wft-327" comment="the version of lsasrv.dll is less than 5.1.2600.2525" negate="false"/>
          <criterion test_ref="wrt-36" comment="the patch kb885835is installed (Hotfix key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL451" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Utilities Manager/Windows Messaging</product>
      </affected>
      <dates>
        <submitted date="2003-09-09-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2004-03-09-12:00">ACCEPTED</status_change>
        <modified date="2005-03-07-12:00" comment="modified wrt-222 - changed pattern match">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-03-09-07:55">INTERIM</status_change>
        <status_change date="2005-03-29-07:59">ACCEPTED</status_change>
      </dates>
      <description>The control for listing accessibility options in the Accessibility Utility Manager on Windows 2000 (ListView) does not properly handle Windows messages, which allows local users to execute arbitrary code via a "Shatter" style message to the Utility Manager that references a user-controlled callback function.</description>
      <reference source="CVE">CVE-2003-0350</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
          <criterion test_ref="wft-291" comment="the version of sp3res.dll is less than 5.0.2195.6713" negate="false"/>
          <criterion test_ref="wft-292" comment="the version of umandlg.dll is less than 1.0.0.3" negate="false"/>
          <criterion test_ref="wrt-335" comment="Patch KB822679 Installed" negate="true"/>
          <criterion test_ref="wrt-222" comment="SP4 or later Installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL452" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>OpenSSH</product>
      </affected>
      <dates>
        <submitted date="2003-09-21-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Multiple "buffer management errors" in OpenSSH before 3.7.1 may allow attackers to cause a denial of service or execute arbitrary code using (1) buffer_init in buffer.c, (2) buffer_free in buffer.c, or (3) a separate function in channels.c, a different vulnerability than CVE-2003-0693.</description>
      <reference source="CVE">CVE-2003-0695</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-231" comment="openssh-server version is less than 3.5p1-11" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="rlt-207" comment="sshd listens on the network" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL459" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Internet Explorer 6 Service Pack 1 for Windows Server 2003</product>
      </affected>
      <dates>
        <submitted date="2003-11-12-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <modified date="2004-01-21-12:00" comment="Removed the test for Windows Server 2003.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 6 sp1 patch.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <modified date="2004-01-29-12:00" comment="Added Windows XP 64-bit, Version 2003 and Windows Server 2003 64-Bit to the list of affected platforms">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <modified date="2004-03-04-12:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <status_change date="2004-03-09-12:00">INTERIM</status_change>
        <status_change date="2004-03-25-12:00">ACCEPTED</status_change>
        <modified date="2005-05-10-12:00" comment="modified wrt-51 - Comment updated to indicate IE 6.">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </modified>
        <status_change date="2005-05-11-05:33">INTERIM</status_change>
        <status_change date="2005-06-01-03:30">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions by (1) using the NavigateAndFind method to load a file: URL containing Javascript, as demonstrated by NAFfileJPU, (2) using the window.open method to load a file: URL containing Javascript, as demonstrated using WsOpenFileJPU, (3) setting the href property in the base tag for the _search window, as demonstrated using WsBASEjpu, (4) loading the search window into an Iframe, as demonstrated using WsFakeSrc, (5) caching a javascript: URL in the browser history, then accessing that URL in the same frame as the target domain, as demonstrated using WsOpenJpuInHistory, NAFjpuInHistory, BackMyParent, BackMyParent2, and RefBack, aka the "Script URLs Cross Domain" vulnerability.</description>
      <reference source="CVE">CVE-2003-0816</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-51" comment="Internet Explorer 6  for Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wft-28" comment="the version of mshtml.dll is less than 6.0.3790.94" negate="false"/>
          <criterion test_ref="wrt-60" comment="the patch q824145 is installed (Hotfix key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL461" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>OpenSSL</product>
      </affected>
      <dates>
        <submitted date="2003-08-11-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <modified date="2004-05-11-12:00" comment="Added cmp-914 which uses an or to combine the 5 version tests. Previously the tests had been combined with an and.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>The SSL and TLS components for OpenSSL 0.9.6i and earlier, 0.9.7, and 0.9.7a allow remote attackers to perform an unauthorized RSA private key operation via a modified Bleichenbacher attack that uses a large number of SSL or TLS connections using PKCS #1 v1.5 padding that cause OpenSSL to leak information regarding the relationship between ciphertext and the associated plaintext, aka the "Klima-Pokorny-Rosa attack."</description>
      <reference source="CVE">CVE-2003-0131</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="cmp-914" comment="affected version of SSL and TLS components for OpenSSL" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL463" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>HTML Help Facility</product>
      </affected>
      <dates>
        <submitted date="2005-06-20-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <status_change date="2005-06-22-12:38">DRAFT</status_change>
        <status_change date="2005-07-27-10:37">INTERIM</status_change>
        <status_change date="2005-08-18-07:37">ACCEPTED</status_change>
      </dates>
      <description>Integer overflow in Microsoft Windows 98, 2000, XP SP2 and earlier, and Server 2003 SP1 and earlier allows remote attackers to execute arbitrary code via a crafted compiled Help (.CHM) file with a large size field that triggers a heap-based buffer overflow, as demonstrated using a "ms-its:" URL in Internet Explorer.</description>
      <reference source="CVE">CVE-2005-1208</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1106" comment="Windows 2000 (sp4 or earlier) is installed" negate="false"/>
          <criterion test_ref="wft-4" comment="the version of hh.exe is less than 5.2.3790.309" negate="false"/>
          <criterion test_ref="wrt-57" comment="the patch kb896358 is installed (Hotfix key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL466" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>OpenSSL</product>
      </affected>
      <dates>
        <submitted date="2003-08-11-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <modified date="2004-05-11-12:00" comment="Added cmp-914 which uses an or to combine the 5 version tests. Previously the tests had been combined with an and.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>OpenSSL does not use RSA blinding by default, which allows local and remote attackers to obtain the server's private key by determining factors using timing differences on (1) the number of extra reductions during Montgomery reduction, and (2) the use of different integer multiplication algorithms ("Karatsuba" and normal).</description>
      <reference source="CVE">CVE-2003-0147</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="cmp-914" comment="affected version of SSL and TLS components for OpenSSL" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL467" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Small Business Server 2000</product>
      </affected>
      <dates>
        <submitted date="2005-06-22-12:00">
          <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
        </submitted>
        <status_change date="2005-06-22-12:38">DRAFT</status_change>
        <status_change date="2005-07-27-10:37">INTERIM</status_change>
        <status_change date="2005-08-18-07:37">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the Server Message Block (SMB) functionality for Microsoft Windows 2000, XP SP1 and SP2, and Server 2003 and SP1 allows remote attackers to execute arbitrary code via unknown vectors, aka the "Server Message Block Vulnerability."</description>
      <reference source="CVE">CVE-2005-1206</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-63" comment="the patch KB896422 is installed" negate="true"/>
          <criterion test_ref="wft-145" comment="the version of srv.sys is less than 5.0.2195.7044" negate="false"/>
          <criterion test_ref="wrt-539" comment="Win2K/XP/2003 service pack 5 (or later) is installed" negate="true"/>
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL468" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>ISA Server 2000</product>
      </affected>
      <dates>
        <submitted date="2005-06-23-04:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2005-06-29-04:00">DRAFT</status_change>
        <status_change date="2005-07-27-04:00">INTERIM</status_change>
        <status_change date="2005-08-18-04:00">ACCEPTED</status_change>
        <modified date="2005-09-19-04:00" comment="modified wft-81 - Removed extra trailing \\ on registry component.">
          <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
        </modified>
        <status_change date="2005-09-21-01:27">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Microsoft ISA Server 2000 allows remote attackers to connect to services utilizing the NetBIOS protocol via a NetBIOS connection with an ISA Server that uses the NetBIOS (all) predefined packet filter.</description>
      <reference source="CVE">CVE-2005-1216</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-11" comment="ISA Server 2000 SP2 (or earlier) is installed" negate="false"/>
          <criterion test_ref="wft-81" comment="the version of w3proxy.exe is less than 3.0.1200.430" negate="false"/>
          <criterion test_ref="wrt-52" comment="the patch KB899753 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL469" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>pam_smb</product>
      </affected>
      <dates>
        <submitted date="2003-09-05-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in PAM SMB module (pam_smb) 1.1.6 and earlier, when authenticating to a remote service, allows remote attackers to execute arbitrary code.</description>
      <reference source="CVE">CVE-2003-0686</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-237" comment="pam_smb version is less than 1.1.6-9.9" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL470" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>CGI.pm</product>
      </affected>
      <dates>
        <submitted date="2003-09-25-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <status_change date="2004-05-05-12:00">ACCEPTED</status_change>
      </dates>
      <description>Cross-site scripting (XSS) vulnerability in start_form() of CGI.pm allows remote attackers to insert web script via a URL that is fed into the form's action parameter.</description>
      <reference source="CVE">CVE-2003-0615</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-238" comment="perl-CGI version is less than 2.81-88.3" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL471" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Internet Explorer 5.01</product>
      </affected>
      <dates>
        <submitted date="2003-08-29-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2004-03-09-12:00">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 5.01 through 6.0 does not properly perform security checks on certain encoded characters within a URL, which allows a remote attacker to steal potentially sensitive information from a user by redirecting the user to another site that has that information, aka "Encoded Characters Information Disclosure."</description>
      <reference source="CVE">CVE-2002-1186</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-214" comment="Internet Explorer 5.01 Installed" negate="false"/>
          <criterion test_ref="wft-293" comment="File %windir%\system32\mshtml.dll version is less than 5.0.3510.1100" negate="false"/>
          <criterion test_ref="wrt-206" comment="the patch q328970 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-207" comment="the patch q324929 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-208" comment="the patch q810847 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-209" comment="the patch q813489 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-210" comment="the patch q818529 is installed (Installed Components key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL472" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Microsoft Internet Explorer 6</product>
      </affected>
      <dates>
        <submitted date="2003-11-12-05:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <modified date="2004-01-21-05:00" comment="Removed the test for Windows XP.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 6 patch.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <modified date="2004-03-04-05:00" comment="Removed the IE 6 SP 1 part of this definition as the SP 1 part is defined in a different OVAL.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <status_change date="2004-03-09-05:00">INTERIM</status_change>
        <status_change date="2004-03-25-05:00">ACCEPTED</status_change>
        <modified date="2005-09-20-04:00" comment="modified wrt-18 - Changed value element to include pattern match">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-21-01:27">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and read arbitrary files by (1) modifying the createTextRange method and using CreateLink, as demonstrated using LinkillerSaveRef, LinkillerJPU, and Linkiller, or (2) modifying the createRange method and using the FIND dialog to select text, as demonstrated using Findeath, aka the "Function Pointer Override Cross Domain" vulnerability.</description>
      <reference source="CVE">CVE-2003-0815</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-18" comment="Internet Explorer 6 is installed" negate="false"/>
          <criterion test_ref="wft-26" comment="the version of mshtml.dll is less than 6.0.2734.1600" negate="false"/>
          <criterion test_ref="wrt-19" comment="the patch q824145 is installed (Installed Components key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL477" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Exchange Server 2003</product>
      </affected>
      <dates>
        <submitted date="2004-01-20-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <status_change date="2004-03-09-12:00">INTERIM</status_change>
        <status_change date="2004-03-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Exchange 2003 and Outlook Web Access (OWA), when configured to use NTLM authentication, does not properly reuse HTTP connections, which can cause OWA users to view mailboxes of other users when Kerberos has been disabled as an authentication method for IIS 6.0, e.g. when SharePoint Services 2.0 is installed.</description>
      <reference source="CVE">CVE-2003-0904</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" negate="false"/>
          <criterion test_ref="wft-34" comment="the version of exprox.dll is less than 6.5.6980.57" negate="false"/>
          <criterion test_ref="wrt-109" comment="the patch KB832759 is installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="ukn-21" comment="this is a front-end server providing Outlook Web Access" negate="false"/>
          <criterion test_ref="ukn-22" comment="the back-end server is Exchange Server 2003 running on Windows 2003" negate="false"/>
          <criterion test_ref="wrt-106" comment="HTTP connection reuse is disabled" negate="true"/>
          <criterion test_ref="ukn-20" comment="Kerberos is disabled on the virtual server that hosts OWA on the Exchange Server 2003 back-end server" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL478" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Internet Security and Acceleration Server 2000</product>
      </affected>
      <dates>
        <submitted date="2004-01-13-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
        <status_change date="2004-03-09-12:00">INTERIM</status_change>
        <status_change date="2004-03-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the H.323 filter of Microsoft Internet Security and Acceleration Server 2000 allows remote attackers to execute arbitrary code in the Microsoft Firewall Service via certain H.323 traffic, as demonstrated by the NISCC/OUSPG PROTOS test suite for the H.225 protocol.</description>
      <reference source="CVE">CVE-2003-0819</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-105" comment="ISA Server 2000 is installed" negate="false"/>
          <criterion test_ref="wft-33" comment="the version of h32fltr.dll is less than 3.0.1200.291" negate="false"/>
          <criterion test_ref="wrt-112" comment="the patch q816458 is installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-108" comment="H.323 filter is enabled" negate="false"/>
          <criterion test_ref="wrt-107" comment="Microsoft Firewall Service is not disabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL479" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Microsoft Internet Explorer 6</product>
        <product>Microsoft Internet Explorer 6 Service Pack 1</product>
      </affected>
      <dates>
        <submitted date="2003-11-12-05:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <modified date="2004-01-21-05:00" comment="Removed the test for Windows XP.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 6 patch.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <modified date="2004-03-04-05:00" comment="Removed the IE 6 SP 1 part of this definition as the SP 1 part is defined in a different OVAL.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <status_change date="2004-03-09-05:00">INTERIM</status_change>
        <status_change date="2004-03-25-05:00">ACCEPTED</status_change>
        <modified date="2005-09-20-04:00" comment="modified wrt-18 - Changed value element to include pattern match">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-21-01:27">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions by (1) using the NavigateAndFind method to load a file: URL containing Javascript, as demonstrated by NAFfileJPU, (2) using the window.open method to load a file: URL containing Javascript, as demonstrated using WsOpenFileJPU, (3) setting the href property in the base tag for the _search window, as demonstrated using WsBASEjpu, (4) loading the search window into an Iframe, as demonstrated using WsFakeSrc, (5) caching a javascript: URL in the browser history, then accessing that URL in the same frame as the target domain, as demonstrated using WsOpenJpuInHistory, NAFjpuInHistory, BackMyParent, BackMyParent2, and RefBack, aka the "Script URLs Cross Domain" vulnerability.</description>
      <reference source="CVE">CVE-2003-0816</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-18" comment="Internet Explorer 6 is installed" negate="false"/>
          <criterion test_ref="wft-26" comment="the version of mshtml.dll is less than 6.0.2734.1600" negate="false"/>
          <criterion test_ref="wrt-19" comment="the patch q824145 is installed (Installed Components key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL483" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Internet Information Server 5.0</product>
      </affected>
      <dates>
        <submitted date="2004-01-14-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <status_change date="2004-03-09-12:00">ACCEPTED</status_change>
        <modified date="2005-03-07-12:00" comment="modified wrt-222 - changed pattern match">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-03-09-07:55">INTERIM</status_change>
        <status_change date="2005-03-29-07:59">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in ssinc.dll for Microsoft Internet Information Services (IIS) 5.0 allows local users to execute arbitrary code via a web page with a Server Side Include (SSI) directive with a long filename, aka "Server Side Include Web Pages Buffer Overrun."</description>
      <reference source="CVE">CVE-2003-0224</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-223" comment="IIS major version equals 5" negate="false"/>
          <criterion test_ref="wrt-215" comment="IIS minor version equals 0" negate="false"/>
          <criterion test_ref="wft-296" comment="File %windir%\system32\inetsrv\ssinc.dll version is less than 5.0.2195.6624" negate="false"/>
          <criterion test_ref="wrt-219" comment="Patch Q811114 Installed" negate="true"/>
          <criterion test_ref="wrt-222" comment="SP4 or later Installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wmt-2" comment="SmartHTML interpreter is enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL484" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft SQL Server 2000</product>
      </affected>
      <dates>
        <submitted date="2004-09-15-12:00">
          <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
        </submitted>
        <modified date="2004-09-16-12:00" comment="filling out initial submission.">
          <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
        </modified>
        <modified date="2004-09-16-10:31" comment="Added service pack 3 test">
          <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
        </modified>
        <status_change date="2004-09-22-12:00">DRAFT</status_change>
        <status_change date="2004-10-06-12:00">INTERIM</status_change>
        <status_change date="2004-10-20-12:00">ACCEPTED</status_change>
        <modified date="2005-04-08-12:00" comment="modified wft-492 - wft-492 corrected literal string">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <status_change date="2005-04-11-08:48">INTERIM</status_change>
        <status_change date="2005-04-27-12:07">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the SQLXML ISAPI extension of Microsoft SQL Server 2000 allows remote attackers to execute arbitrary code via data queries with a long content-type parameter, aka "Unchecked Buffer in SQLXML ISAPI Extension."</description>
      <reference source="CVE">CVE-2002-0186</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-260" comment="SQL Server 2000 is installed" negate="false"/>
          <criterion test_ref="wrt-101" comment="MDAC 2.6 is installed" negate="false"/>
          <criterion test_ref="wft-491" comment="the version of sqlisapi.dll is less than 2000.80.309.0" negate="false"/>
          <criterion test_ref="wft-492" comment="the version of sqlservr.exe is less than 2000.80.760.0" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL485" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>php</product>
      </affected>
      <dates>
        <submitted date="2003-08-29-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Cross-site scripting (XSS) vulnerability in the transparent SID support capability for PHP before 4.3.2 (session.use_trans_sid) allows remote attackers to insert arbitrary script via the PHPSESSID parameter.</description>
      <reference source="CVE">CVE-2003-0442</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-239" comment="php version is less than 4.2.2-17.2" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL489" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft SQL Server 2000</product>
      </affected>
      <dates>
        <submitted date="2004-09-15-12:00">
          <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
        </submitted>
        <modified date="2004-09-16-12:00" comment="Input of initial submission.">
          <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
        </modified>
        <status_change date="2004-09-22-12:00">DRAFT</status_change>
        <status_change date="2004-10-06-12:00">INTERIM</status_change>
        <status_change date="2004-10-20-12:00">ACCEPTED</status_change>
        <modified date="2005-04-08-12:00" comment="modified wft-492 - wft-492 corrected literal string">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <status_change date="2005-04-11-08:48">INTERIM</status_change>
        <status_change date="2005-04-27-12:07">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the SQLXML ISAPI extension of Microsoft SQL Server 2000 allows remote attackers to execute arbitrary code via data queries with a long content-type parameter, aka "Unchecked Buffer in SQLXML ISAPI Extension."</description>
      <reference source="CVE">CVE-2002-0186</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-460" comment="SQL Server 2000 installed" negate="false"/>
          <criterion test_ref="wrt-102" comment="MDAC 2.7 (RTM) is installed" negate="false"/>
          <criterion test_ref="wft-491" comment="the version of sqlisapi.dll is less than 2000.80.309.0" negate="false"/>
          <criterion test_ref="wft-492" comment="the version of sqlservr.exe is less than 2000.80.760.0" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL490" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Internet Explorer 5.01 Service Pack 2</product>
      </affected>
      <dates>
        <submitted date="2004-02-03-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <status_change date="2004-03-09-12:00">INTERIM</status_change>
        <status_change date="2004-03-25-12:00">ACCEPTED</status_change>
        <modified date="2005-09-26-12:50" comment="modified wft-90 - Changed comment to match test">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-28-01:04">INTERIM</status_change>
        <status_change date="2005-10-19-05:47">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to spoof the domain of a URL via a "%01" character before an @ sign in the user@domain portion of the URL, which hides the rest of the URL, including the real site, in the address bar, aka the "Improper URL Canonicalization Vulnerability."</description>
      <reference source="CVE">CVE-2003-1025</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-56" comment="Internet Explorer 5.01 Service Pack 2 is installed" negate="false"/>
          <criterion test_ref="wft-90" comment="the version of mshtml.dll is less than 5.0.3526.800" negate="false"/>
          <criterion test_ref="wrt-141" comment="the patch q832894 is installed (Installed Components key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL491" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Internet Explorer 5.01 Service Pack 3</product>
      </affected>
      <dates>
        <submitted date="2004-02-03-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <status_change date="2004-03-09-12:00">INTERIM</status_change>
        <status_change date="2004-03-25-12:00">ACCEPTED</status_change>
        <modified date="2005-09-26-12:50" comment="modified wft-90 - Changed comment to match test">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-28-01:04">INTERIM</status_change>
        <status_change date="2005-10-19-05:47">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to spoof the domain of a URL via a "%01" character before an @ sign in the user@domain portion of the URL, which hides the rest of the URL, including the real site, in the address bar, aka the "Improper URL Canonicalization Vulnerability."</description>
      <reference source="CVE">CVE-2003-1025</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-55" comment="Internet Explorer 5.01 Service Pack 3 is installed" negate="false"/>
          <criterion test_ref="wft-90" comment="the version of mshtml.dll is less than 5.0.3526.800" negate="false"/>
          <criterion test_ref="wrt-141" comment="the patch q832894 is installed (Installed Components key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL494" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Remote Procedure Call (RPC)</product>
      </affected>
      <dates>
        <submitted date="2003-12-03-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <status_change date="2004-03-09-12:00">ACCEPTED</status_change>
      </dates>
      <description>The RPC DCOM interface in Windows 2000 SP3 and SP4 allows remote attackers to cause a denial of service (crash), and local attackers to use the DoS to hijack the epmapper pipe to gain privileges, via certain messages to the __RemoteGetClassObject interface that cause a NULL pointer to be passed to the PerformScmStage function.</description>
      <reference source="CVE">CVE-2003-0605</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
          <criterion test_ref="wft-239" comment="the version of rpcrt4.dll is less than 5.0.2195.6802" negate="false"/>
          <criterion test_ref="wrt-281" comment="the patch kb824146 is installed (Hotfix key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-7" comment="DCOM is enabled on systems with SP3 or later" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL495" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Internet Explorer 5.5</product>
      </affected>
      <dates>
        <submitted date="2004-01-27-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2004-03-09-12:00">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 5.01 through 6.0 does not properly perform security checks on certain encoded characters within a URL, which allows a remote attacker to steal potentially sensitive information from a user by redirecting the user to another site that has that information, aka "Encoded Characters Information Disclosure."</description>
      <reference source="CVE">CVE-2002-1186</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-271" comment="Internet Explorer 5.5 Installed" negate="false"/>
          <criterion test_ref="wft-262" comment="the version of mshtml.dll is less than 5.50.4922.900" negate="false"/>
          <criterion test_ref="wrt-206" comment="the patch q328970 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-207" comment="the patch q324929 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-208" comment="the patch q810847 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-209" comment="the patch q813489 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-210" comment="the patch q818529 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-211" comment="the patch q822925 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-212" comment="the patch q828750 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-19" comment="the patch q824145 is installed (Installed Components key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL499" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>pine</product>
      </affected>
      <dates>
        <submitted date="2003-09-12-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in PINE before 4.58 allows remote attackers to execute arbitrary code via a malformed message/external-body MIME type.</description>
      <reference source="CVE">CVE-2003-0720</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-240" comment="pine version is less than 4.44-19.90.0" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-314" comment="/usr/bin/pine is executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL500" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>Remote Access Service (RAS)</product>
      </affected>
      <dates>
        <submitted date="2003-06-08-12:00">
          <contributor organization="The MITRE Corporation">Matt Busby</contributor>
        </submitted>
        <status_change date="2004-06-30-12:00">INTERIM</status_change>
        <status_change date="2004-07-12-12:00">ACCEPTED</status_change>
      </dates>
      <description>The default permissions for the RAS Administration key in Windows NT 4.0 allows local users to execute arbitrary commands by changing the value to point to a malicious DLL, aka one of the "Registry Permissions" vulnerabilities.</description>
      <reference source="CVE">CVE-2001-0045</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" negate="false"/>
          <criterion test_ref="cmp-1011" comment="For Windows NT 4.0 Workstation, Server and Enterprise Edition" negate="false"/>
          <criterion test_ref="cmp-1012" comment="For Terminal Server" negate="false"/>
          <criterion test_ref="wrt-454" comment="Patch Q265714 Installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-258" comment="RAS Enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL503" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>pine</product>
      </affected>
      <dates>
        <submitted date="2003-09-12-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Integer signedness error in rfc2231_get_param from strings.c in PINE before 4.58 allows remote attackers to execute arbitrary code via an email that causes an out-of-bounds array access using a negative number.</description>
      <reference source="CVE">CVE-2003-0721</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-240" comment="pine version is less than 4.44-19.90.0" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-314" comment="/usr/bin/pine is executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL507" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Microsoft Internet Explorer 6</product>
      </affected>
      <dates>
        <submitted date="2004-07-30-04:00">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </submitted>
        <status_change date="2004-08-02-04:00">DRAFT</status_change>
        <status_change date="2004-08-25-04:00">INTERIM</status_change>
        <status_change date="2004-09-09-04:00">ACCEPTED</status_change>
        <modified date="2005-09-20-04:00" comment="modified wrt-18 - Changed value element to include pattern match">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-21-01:27">INTERIM</status_change>
        <modified date="2005-09-26-12:19" comment="modified wft-268 - Changed comment to match test">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Integer overflow in imgbmp.cxx for Windows 2000 allows remote attackers to execute arbitrary code via a BMP image with a large bfOffBits value.</description>
      <reference source="CVE">CVE-2004-0566</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-18" comment="Internet Explorer 6 is installed" negate="false"/>
          <criterion test_ref="wft-268" comment="the version of mshtml.dll is less than 6.0.2743.600" negate="false"/>
          <criterion test_ref="wrt-245" comment="the patch kb832894 is installed (Installed Components key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL508" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Internet Explorer 5.01 Service Pack 2</product>
      </affected>
      <dates>
        <submitted date="2003-11-12-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <modified date="2004-01-21-12:00" comment="Removed the test for Windows 2000 sp2 installed.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 5.01 sp2 patch.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <modified date="2004-03-04-12:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <status_change date="2004-03-09-12:00">INTERIM</status_change>
        <status_change date="2004-03-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions and read arbitrary files via an XML object.</description>
      <reference source="CVE">CVE-2003-0817</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-56" comment="Internet Explorer 5.01 Service Pack 2 is installed" negate="false"/>
          <criterion test_ref="wft-23" comment="the version of mshtml.dll is less than 5.0.3523.1700" negate="false"/>
          <criterion test_ref="wrt-19" comment="the patch q824145 is installed (Installed Components key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL509" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Internet Explorer 5.01 Service Pack 4</product>
      </affected>
      <dates>
        <submitted date="2004-07-30-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <status_change date="2004-08-02-12:00">DRAFT</status_change>
        <status_change date="2004-08-25-12:00">INTERIM</status_change>
        <status_change date="2004-09-09-12:00">ACCEPTED</status_change>
        <modified date="2005-09-26-12:21" comment="modified wft-279 - Changed comment to match test">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-28-01:04">INTERIM</status_change>
        <status_change date="2005-10-19-05:47">ACCEPTED</status_change>
      </dates>
      <description>Double-free vulnerability in mshtml.dll for certain versions of Internet Explorer 6.x allows remote attackers to cause a denial of service (application crash) via a malformed GIF image.</description>
      <reference source="CVE">CVE-2003-1048</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-54" comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false"/>
          <criterion test_ref="wft-279" comment="the version of mshtml.dll is less than 5.0.3819.300" negate="false"/>
          <criterion test_ref="wrt-245" comment="the patch kb832894 is installed (Installed Components key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL510" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Internet Explorer 5.01 Service Pack 4</product>
      </affected>
      <dates>
        <submitted date="2004-02-03-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <status_change date="2004-03-09-12:00">INTERIM</status_change>
        <status_change date="2004-03-25-12:00">ACCEPTED</status_change>
        <modified date="2005-09-26-12:49" comment="modified wft-91 - Changed comment to match test">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-28-01:04">INTERIM</status_change>
        <status_change date="2005-10-19-05:47">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to spoof the domain of a URL via a "%01" character before an @ sign in the user@domain portion of the URL, which hides the rest of the URL, including the real site, in the address bar, aka the "Improper URL Canonicalization Vulnerability."</description>
      <reference source="CVE">CVE-2003-1025</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-54" comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false"/>
          <criterion test_ref="wft-91" comment="the version of mshtml.dll is less than 5.0.3813.800" negate="false"/>
          <criterion test_ref="wrt-141" comment="the patch q832894 is installed (Installed Components key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL511" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows ME</windows:platform>
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Internet Explorer 5.5 Service Pack 2</product>
      </affected>
      <dates>
        <submitted date="2004-02-03-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <status_change date="2004-03-09-12:00">INTERIM</status_change>
        <status_change date="2004-03-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to spoof the domain of a URL via a "%01" character before an @ sign in the user@domain portion of the URL, which hides the rest of the URL, including the real site, in the address bar, aka the "Improper URL Canonicalization Vulnerability."</description>
      <reference source="CVE">CVE-2003-1025</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-53" comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false"/>
          <criterion test_ref="wft-92" comment="the version of mshtml.dll is less than 5.50.4937.800" negate="false"/>
          <criterion test_ref="wrt-141" comment="the patch q832894 is installed (Installed Components key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL512" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Microsoft Internet Explorer 6</product>
      </affected>
      <dates>
        <submitted date="2004-02-03-05:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <status_change date="2004-03-09-05:00">INTERIM</status_change>
        <status_change date="2004-03-25-05:00">ACCEPTED</status_change>
        <modified date="2005-09-20-04:00" comment="modified wrt-18 - Changed value element to include pattern match">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-21-01:27">INTERIM</status_change>
        <modified date="2005-09-26-12:51" comment="modified wft-93 - Changed comment to match test">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to spoof the domain of a URL via a "%01" character before an @ sign in the user@domain portion of the URL, which hides the rest of the URL, including the real site, in the address bar, aka the "Improper URL Canonicalization Vulnerability."</description>
      <reference source="CVE">CVE-2003-1025</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-18" comment="Internet Explorer 6 is installed" negate="false"/>
          <criterion test_ref="wft-93" comment="the version of mshtml.dll is less than 6.0.2737.800" negate="false"/>
          <criterion test_ref="wrt-141" comment="the patch q832894 is installed (Installed Components key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL513" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows ME</windows:platform>
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Microsoft Internet Explorer 6 Service Pack 1</product>
      </affected>
      <dates>
        <submitted date="2004-02-03-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <status_change date="2004-03-09-12:00">INTERIM</status_change>
        <status_change date="2004-03-25-12:00">ACCEPTED</status_change>
        <modified date="2005-09-26-12:52" comment="modified wft-94 - Changed comment to match test">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-28-01:04">INTERIM</status_change>
        <status_change date="2005-10-19-05:47">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to spoof the domain of a URL via a "%01" character before an @ sign in the user@domain portion of the URL, which hides the rest of the URL, including the real site, in the address bar, aka the "Improper URL Canonicalization Vulnerability."</description>
      <reference source="CVE">CVE-2003-1025</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-50" comment="Internet Explorer 6 Service Pack 1 is installed" negate="false"/>
          <criterion test_ref="wft-94" comment="the version of mshtml.dll is less than 6.0.2800.1400" negate="false"/>
          <criterion test_ref="wrt-141" comment="the patch q832894 is installed (Installed Components key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL515" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Internet Explorer 5.01 Service Pack 2</product>
      </affected>
      <dates>
        <submitted date="2004-07-30-12:00">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </submitted>
        <status_change date="2004-08-02-12:00">DRAFT</status_change>
        <status_change date="2004-08-25-12:00">INTERIM</status_change>
        <status_change date="2004-09-09-12:00">ACCEPTED</status_change>
      </dates>
      <description>Integer overflow in imgbmp.cxx for Windows 2000 allows remote attackers to execute arbitrary code via a BMP image with a large bfOffBits value.</description>
      <reference source="CVE">CVE-2004-0566</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-56" comment="Internet Explorer 5.01 Service Pack 2 is installed" negate="false"/>
          <criterion test_ref="wft-270" comment="the version of mshtml.dll is less than 5.0.3532.300" negate="false"/>
          <criterion test_ref="wrt-245" comment="the patch kb832894 is installed (Installed Components key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL517" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Internet Explorer 6 Service Pack 1 for Windows Server 2003</product>
      </affected>
      <dates>
        <submitted date="2004-07-30-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <status_change date="2004-08-02-12:00">DRAFT</status_change>
        <status_change date="2004-08-25-12:00">INTERIM</status_change>
        <status_change date="2004-09-09-12:00">ACCEPTED</status_change>
        <modified date="2005-05-10-12:00" comment="modified wrt-51 - Comment updated to indicate IE 6.">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </modified>
        <status_change date="2005-05-11-05:33">INTERIM</status_change>
        <status_change date="2005-06-01-03:30">ACCEPTED</status_change>
        <modified date="2005-09-26-11:00" comment="modified wft-266 - Changed comment to match test">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-28-01:04">INTERIM</status_change>
        <status_change date="2005-10-19-05:47">ACCEPTED</status_change>
      </dates>
      <description>Double-free vulnerability in mshtml.dll for certain versions of Internet Explorer 6.x allows remote attackers to cause a denial of service (application crash) via a malformed GIF image.</description>
      <reference source="CVE">CVE-2003-1048</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-51" comment="Internet Explorer 6  for Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wft-266" comment="the version of mshtml.dll is less than 6.0.3790.191" negate="false"/>
          <criterion test_ref="wrt-237" comment="the patch kb867801 is installed (Hotfix key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL519" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Microsoft Internet Explorer 6</product>
      </affected>
      <dates>
        <submitted date="2004-07-30-04:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <status_change date="2004-08-02-04:00">DRAFT</status_change>
        <status_change date="2004-08-25-04:00">INTERIM</status_change>
        <status_change date="2004-09-09-04:00">ACCEPTED</status_change>
        <modified date="2005-09-20-04:00" comment="modified wrt-18 - Changed value element to include pattern match">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-21-01:27">INTERIM</status_change>
        <modified date="2005-09-26-12:19" comment="modified wft-268 - Changed comment to match test">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>The WebBrowser ActiveX control, or the Internet Explorer HTML rendering engine (MSHTML), as used in Internet Explorer 6, allows remote attackers to execute arbitrary code in the Local Security context by using the showModalDialog method and modifying the location to execute code such as Javascript, as demonstrated using (1) delayed HTTP redirect operations, and an HTTP response with a Location: header containing a "URL:" prepended to a "ms-its" protocol URI, or (2) modifying the location attribute of the window, as exploited by the Download.ject (aka Scob aka Toofer) using the ADODB.Stream object.</description>
      <reference source="CVE">CVE-2004-0549</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-18" comment="Internet Explorer 6 is installed" negate="false"/>
          <criterion test_ref="wft-268" comment="the version of mshtml.dll is less than 6.0.2743.600" negate="false"/>
          <criterion test_ref="wrt-245" comment="the patch kb832894 is installed (Installed Components key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL520" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Internet Explorer 5.01 Service Pack 3</product>
      </affected>
      <dates>
        <submitted date="2003-11-12-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <modified date="2004-01-21-12:00" comment="Removed the test for Windows 2000 sp3 installed.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 5.01 sp3 patch.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <modified date="2004-03-04-12:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <status_change date="2004-03-09-12:00">INTERIM</status_change>
        <status_change date="2004-03-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions and read arbitrary files via an XML object.</description>
      <reference source="CVE">CVE-2003-0817</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-55" comment="Internet Explorer 5.01 Service Pack 3 is installed" negate="false"/>
          <criterion test_ref="wft-23" comment="the version of mshtml.dll is less than 5.0.3523.1700" negate="false"/>
          <criterion test_ref="wrt-19" comment="the patch q824145 is installed (Installed Components key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL522" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Postfix</product>
      </affected>
      <dates>
        <submitted date="2003-09-02-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <status_change date="2004-05-05-12:00">ACCEPTED</status_change>
      </dates>
      <description>Postfix 1.1.11 and earlier allows remote attackers to use Postfix to conduct "bounce scans" or DDos attacks of other hosts via an email address to the local host containing the target IP address and service name followed by a "!" string, which causes Postfix to attempt to use SMTP to communicate with the target on the associated port.</description>
      <reference source="CVE">CVE-2003-0468</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-241" comment="postfix version is less than 1.1.12-1" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="rlt-208" comment="smtpd listens on the network" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL525" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 95</windows:platform>
        <windows:platform>Microsoft Windows 98</windows:platform>
        <windows:platform>Microsoft Windows ME</windows:platform>
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Data Access Compnents 2.5</product>
      </affected>
      <dates>
        <submitted date="2004-01-13-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2004-03-09-12:00">INTERIM</status_change>
        <status_change date="2004-03-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in a component of Microsoft Data Access Components (MDAC) 2.5 through 2.8 allows remote attackers to execute arbitrary code via a malformed UDP response to a broadcast request.</description>
      <reference source="CVE">CVE-2003-0903</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-100" comment="MDAC 2.5 is installed" negate="false"/>
          <criterion test_ref="wft-40" comment="the version of odbcbcp.dll is less than 3.70.11.46" negate="false"/>
          <criterion test_ref="wft-35" comment="the version of sqlsrv32.dll is less than 3.70.11.46" negate="false"/>
          <criterion test_ref="wrt-110" comment="the patch q832483 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL526" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Internet Explorer 6 Service Pack 1 for Windows Server 2003</product>
      </affected>
      <dates>
        <submitted date="2004-02-03-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <status_change date="2004-03-09-12:00">INTERIM</status_change>
        <status_change date="2004-03-25-12:00">ACCEPTED</status_change>
        <modified date="2005-05-10-12:00" comment="modified wrt-51 - Comment updated to indicate IE 6.">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </modified>
        <status_change date="2005-05-11-05:33">INTERIM</status_change>
        <status_change date="2005-06-01-03:30">ACCEPTED</status_change>
        <modified date="2005-09-26-12:54" comment="modified wft-95 - Changed comment to match test">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-28-01:04">INTERIM</status_change>
        <status_change date="2005-10-19-05:47">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to spoof the domain of a URL via a "%01" character before an @ sign in the user@domain portion of the URL, which hides the rest of the URL, including the real site, in the address bar, aka the "Improper URL Canonicalization Vulnerability."</description>
      <reference source="CVE">CVE-2003-1025</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-51" comment="Internet Explorer 6  for Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wft-95" comment="the version of mshtml.dll is less than 6.0.3790.118" negate="false"/>
          <criterion test_ref="wrt-140" comment="the patch q832894 is installed (Hotfix key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL527" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Internet Explorer 5.01 Service Pack 2</product>
      </affected>
      <dates>
        <submitted date="2004-02-03-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <modified date="2004-03-04-12:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <status_change date="2004-03-09-12:00">INTERIM</status_change>
        <status_change date="2004-03-25-12:00">ACCEPTED</status_change>
        <modified date="2005-09-26-12:50" comment="modified wft-90 - Changed comment to match test">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-28-01:04">INTERIM</status_change>
        <status_change date="2005-10-19-05:47">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by using method caching (SaveRef) to access the window.moveBy method, which is otherwise inaccessible, as demonstrated by HijackClickV2, a different vulnerability than CVE-2003-0823, aka the "Function Pointer Drag and Drop Vulnerability."</description>
      <reference source="CVE">CVE-2003-1027</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-56" comment="Internet Explorer 5.01 Service Pack 2 is installed" negate="false"/>
          <criterion test_ref="wft-90" comment="the version of mshtml.dll is less than 5.0.3526.800" negate="false"/>
          <criterion test_ref="wrt-141" comment="the patch q832894 is installed (Installed Components key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL529" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Internet Explorer 5.01 Service Pack 3</product>
      </affected>
      <dates>
        <submitted date="2004-02-03-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <modified date="2004-03-04-12:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <status_change date="2004-03-09-12:00">INTERIM</status_change>
        <status_change date="2004-03-25-12:00">ACCEPTED</status_change>
        <modified date="2005-09-26-12:50" comment="modified wft-90 - Changed comment to match test">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-28-01:04">INTERIM</status_change>
        <status_change date="2005-10-19-05:47">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by using method caching (SaveRef) to access the window.moveBy method, which is otherwise inaccessible, as demonstrated by HijackClickV2, a different vulnerability than CVE-2003-0823, aka the "Function Pointer Drag and Drop Vulnerability."</description>
      <reference source="CVE">CVE-2003-1027</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-55" comment="Internet Explorer 5.01 Service Pack 3 is installed" negate="false"/>
          <criterion test_ref="wft-90" comment="the version of mshtml.dll is less than 5.0.3526.800" negate="false"/>
          <criterion test_ref="wrt-141" comment="the patch q832894 is installed (Installed Components key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL530" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Internet Explorer 5.01 Service Pack 4</product>
      </affected>
      <dates>
        <submitted date="2004-02-03-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <modified date="2004-03-04-12:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <status_change date="2004-03-09-12:00">INTERIM</status_change>
        <status_change date="2004-03-25-12:00">ACCEPTED</status_change>
        <modified date="2005-09-26-12:49" comment="modified wft-91 - Changed comment to match test">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-28-01:04">INTERIM</status_change>
        <status_change date="2005-10-19-05:47">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by using method caching (SaveRef) to access the window.moveBy method, which is otherwise inaccessible, as demonstrated by HijackClickV2, a different vulnerability than CVE-2003-0823, aka the "Function Pointer Drag and Drop Vulnerability."</description>
      <reference source="CVE">CVE-2003-1027</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-54" comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false"/>
          <criterion test_ref="wft-91" comment="the version of mshtml.dll is less than 5.0.3813.800" negate="false"/>
          <criterion test_ref="wrt-141" comment="the patch q832894 is installed (Installed Components key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL531" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows ME</windows:platform>
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Internet Explorer 5.5 Service Pack 2</product>
      </affected>
      <dates>
        <submitted date="2004-02-03-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <modified date="2004-03-04-12:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <status_change date="2004-03-09-12:00">INTERIM</status_change>
        <status_change date="2004-03-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by using method caching (SaveRef) to access the window.moveBy method, which is otherwise inaccessible, as demonstrated by HijackClickV2, a different vulnerability than CVE-2003-0823, aka the "Function Pointer Drag and Drop Vulnerability."</description>
      <reference source="CVE">CVE-2003-1027</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-53" comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false"/>
          <criterion test_ref="wft-92" comment="the version of mshtml.dll is less than 5.50.4937.800" negate="false"/>
          <criterion test_ref="wrt-141" comment="the patch q832894 is installed (Installed Components key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL532" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Microsoft Internet Explorer 6</product>
      </affected>
      <dates>
        <submitted date="2004-02-03-05:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <modified date="2004-03-04-05:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <status_change date="2004-03-09-05:00">INTERIM</status_change>
        <status_change date="2004-03-25-05:00">ACCEPTED</status_change>
        <modified date="2005-09-20-04:00" comment="modified wrt-18 - Changed value element to include pattern match">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-21-01:27">INTERIM</status_change>
        <modified date="2005-09-26-12:51" comment="modified wft-93 - Changed comment to match test">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by using method caching (SaveRef) to access the window.moveBy method, which is otherwise inaccessible, as demonstrated by HijackClickV2, a different vulnerability than CVE-2003-0823, aka the "Function Pointer Drag and Drop Vulnerability."</description>
      <reference source="CVE">CVE-2003-1027</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-18" comment="Internet Explorer 6 is installed" negate="false"/>
          <criterion test_ref="wft-93" comment="the version of mshtml.dll is less than 6.0.2737.800" negate="false"/>
          <criterion test_ref="wrt-141" comment="the patch q832894 is installed (Installed Components key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL534" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows ME</windows:platform>
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Microsoft Internet Explorer 6 Service Pack 1</product>
      </affected>
      <dates>
        <submitted date="2004-02-03-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <modified date="2004-03-04-12:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <status_change date="2004-03-09-12:00">INTERIM</status_change>
        <status_change date="2004-03-25-12:00">ACCEPTED</status_change>
        <modified date="2005-09-26-12:52" comment="modified wft-94 - Changed comment to match test">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-28-01:04">INTERIM</status_change>
        <status_change date="2005-10-19-05:47">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by using method caching (SaveRef) to access the window.moveBy method, which is otherwise inaccessible, as demonstrated by HijackClickV2, a different vulnerability than CVE-2003-0823, aka the "Function Pointer Drag and Drop Vulnerability."</description>
      <reference source="CVE">CVE-2003-1027</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-50" comment="Internet Explorer 6 Service Pack 1 is installed" negate="false"/>
          <criterion test_ref="wft-94" comment="the version of mshtml.dll is less than 6.0.2800.1400" negate="false"/>
          <criterion test_ref="wrt-141" comment="the patch q832894 is installed (Installed Components key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL539" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Microsoft Word for Windows 6.0 Converter</product>
      </affected>
      <dates>
        <submitted date="2005-01-05-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2005-01-06-09:31">DRAFT</status_change>
        <status_change date="2005-02-02-12:00">INTERIM</status_change>
        <status_change date="2005-02-23-09:25">ACCEPTED</status_change>
        <modified date="2005-12-20-07:05" comment="Replaced all criteria. 1) Included XP64,Gold, 2) dropped explicit check for Hotfix kb885836, 3) check version of wordpad.exe rather than mswrd wpc files.">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </modified>
        <status_change date="2006-01-04-08:04">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Word for Windows 6.0 Converter (MSWRD632.WPC), as used in WordPad, does not properly validate certain data lengths, which allows remote attackers to execute arbitrary code via a .wri, .rtf, and .doc file sent by email or malicious web site, aka "Font Conversion Vulnerability," a different vulnerability than CVE-2004-0571.</description>
      <reference source="CVE">CVE-2004-0901</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1112" comment="Windows XP 64-bit" negate="false"/>
          <criterion test_ref="wft-713" comment="the version of wordpad.exe is less than 5.2.3790.224" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL542" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Internet Explorer 5.5</product>
      </affected>
      <dates>
        <submitted date="2004-01-27-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2004-03-09-12:00">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 5.01 through 6.0 does not properly check certain parameters of a PNG file when opening it, which allows remote attackers to cause a denial of service (crash) by triggering a heap-based buffer overflow using invalid length codes during decompression, aka "Malformed PNG Image File Failure."</description>
      <reference source="CVE">CVE-2002-1185</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-271" comment="Internet Explorer 5.5 Installed" negate="false"/>
          <criterion test_ref="wft-262" comment="the version of mshtml.dll is less than 5.50.4922.900" negate="false"/>
          <criterion test_ref="wrt-206" comment="the patch q328970 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-207" comment="the patch q324929 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-208" comment="the patch q810847 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-209" comment="the patch q813489 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-210" comment="the patch q818529 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-211" comment="the patch q822925 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-212" comment="the patch q828750 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-19" comment="the patch q824145 is installed (Installed Components key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL543" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Microsoft Internet Explorer 6</product>
        <product>Microsoft Internet Explorer 6 Service Pack 1</product>
      </affected>
      <dates>
        <submitted date="2003-11-12-05:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <modified date="2004-01-21-05:00" comment="Removed the test for Windows XP.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 6 patch.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <modified date="2004-03-04-05:00" comment="Removed the IE 6 SP 1 part of this definition as the SP 1 part is defined in a different OVAL.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <status_change date="2004-03-09-05:00">INTERIM</status_change>
        <status_change date="2004-03-25-05:00">ACCEPTED</status_change>
        <modified date="2005-09-20-04:00" comment="modified wrt-18 - Changed value element to include pattern match">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-21-01:27">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions and read arbitrary files via an XML object.</description>
      <reference source="CVE">CVE-2003-0817</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-18" comment="Internet Explorer 6 is installed" negate="false"/>
          <criterion test_ref="wft-26" comment="the version of mshtml.dll is less than 6.0.2734.1600" negate="false"/>
          <criterion test_ref="wrt-19" comment="the patch q824145 is installed (Installed Components key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL544" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Postfix</product>
      </affected>
      <dates>
        <submitted date="2003-09-02-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <status_change date="2004-05-05-12:00">ACCEPTED</status_change>
      </dates>
      <description>The address parser code in Postfix 1.1.12 and earlier allows remote attackers to cause a denial of service (lock) via (1) a malformed envelope address to a local host that would generate a bounce and contains the ".!" string in the MAIL FROM or Errors-To headers, which causes nqmgr to lock up, or (2) via a valid MAIL FROM with a RCPT TO containing a ".!" string, which causes an instance of the SMTP listener to lock up.</description>
      <reference source="CVE">CVE-2003-0540</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-241" comment="postfix version is less than 1.1.12-1" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="rlt-208" comment="smtpd listens on the network" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL548" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Internet Explorer 5.01 Service Pack 4</product>
      </affected>
      <dates>
        <submitted date="2003-11-12-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <modified date="2004-01-21-12:00" comment="Removed the test for Windows 2000 sp4 installed.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 5.01 sp4 patch.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <modified date="2004-03-04-12:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <status_change date="2004-03-09-12:00">INTERIM</status_change>
        <status_change date="2004-03-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions and read arbitrary files via an XML object.</description>
      <reference source="CVE">CVE-2003-0817</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-54" comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false"/>
          <criterion test_ref="wft-24" comment="the version of mshtml.dll is less than 5.0.3810.1700" negate="false"/>
          <criterion test_ref="wrt-19" comment="the patch q824145 is installed (Installed Components key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL549" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows ME</windows:platform>
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Internet Explorer 5.5 Service Pack 2</product>
      </affected>
      <dates>
        <submitted date="2003-11-12-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <modified date="2004-01-21-12:00" comment="Removed the test for specific Windows operating systems.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 5.5 sp2 patch.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <modified date="2004-03-04-12:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <status_change date="2004-03-09-12:00">INTERIM</status_change>
        <status_change date="2004-03-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions and read arbitrary files via an XML object.</description>
      <reference source="CVE">CVE-2003-0817</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-53" comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false"/>
          <criterion test_ref="wft-25" comment="the version of mshtml.dll is less than 5.50.4934.1600" negate="false"/>
          <criterion test_ref="wrt-19" comment="the patch q824145 is installed (Installed Components key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL550" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 4</redhat:platform>
        <product>mozilla</product>
      </affected>
      <dates>
        <submitted date="2005-08-15-04:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2005-08-19-10:05">DRAFT</status_change>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Firefox before 1.0.5 and Mozilla before 1.7.9 does not properly clone base objects, which allows remote attackers to execute arbitrary code by navigating the prototype chain to reach a privileged object.</description>
      <reference source="CVE">CVE-2005-2270</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-1" comment="Red Hat Enterprise 4 is installed" negate="false"/>
          <criterion test_ref="rvt-32" comment="mozilla RPM is earlier than 37:1.7.10-1.4.1" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="upt-859" comment="/usr/bin/mozilla is executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL551" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>MSDTC</product>
      </affected>
      <dates>
        <submitted date="2005-10-12-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-10-19-05:46">DRAFT</status_change>
        <status_change date="2005-11-16-08:02">INTERIM</status_change>
        <status_change date="2005-12-01-06:00">ACCEPTED</status_change>
      </dates>
      <description>The MIDL_user_allocate function in the Microsoft Distributed Transaction Coordinator (MSDTC) proxy (MSDTCPRX.DLL) allocates a 4K page of memory regardless of the required size, which allows attackers to overwrite arbitrary memory locations using an incorrect size value that is provided to the NdrAllocate function, which writes management data to memory outside of the allocated buffer.</description>
      <reference source="CVE">CVE-2005-2119</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
          <criterion test_ref="wrt-432" comment="Win2K/XP/2003 service pack 4 is installed" negate="false"/>
          <criterion test_ref="cmp-605" comment="Either ole32.dll or rpcss.dll has a version less than 5.0.2195.7059" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL552" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>smbd</product>
      </affected>
      <dates>
        <submitted date="2003-08-11-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the SMB/CIFS packet fragment re-assembly code for SMB daemon (smbd) in Samba before 2.2.8, and Samba-TNG before 0.3.1, allows remote attackers to execute arbitrary code.</description>
      <reference source="CVE">CVE-2003-0085</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-242" comment="samba version is less than 2.2.7a-7.9.0" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="rlt-209" comment="smbd listens on the network" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL553" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 95</windows:platform>
        <windows:platform>Microsoft Windows 98</windows:platform>
        <windows:platform>Microsoft Windows ME</windows:platform>
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Data Access Compnents 2.6</product>
      </affected>
      <dates>
        <submitted date="2004-01-13-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2004-03-09-12:00">INTERIM</status_change>
        <status_change date="2004-03-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in a component of Microsoft Data Access Components (MDAC) 2.5 through 2.8 allows remote attackers to execute arbitrary code via a malformed UDP response to a broadcast request.</description>
      <reference source="CVE">CVE-2003-0903</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-101" comment="MDAC 2.6 is installed" negate="false"/>
          <criterion test_ref="wft-41" comment="the version of odbcbcp.dll is less than 2000.80.747.0" negate="false"/>
          <criterion test_ref="wft-36" comment="the version of sqlsrv32.dll is less than 2000.80.747.0" negate="false"/>
          <criterion test_ref="wrt-110" comment="the patch q832483 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL554" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Samba</product>
      </affected>
      <dates>
        <submitted date="2003-08-11-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>The code for writing reg files in Samba before 2.2.8 allows local users to overwrite arbitrary files via a race condition involving chown.</description>
      <reference source="CVE">CVE-2003-0086</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-242" comment="samba version is less than 2.2.7a-7.9.0" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL555" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>Xsun</product>
      </affected>
      <dates>
        <submitted date="2004-12-28-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-12-12:41">DRAFT</status_change>
        <status_change date="2005-02-02-12:00">INTERIM</status_change>
        <status_change date="2005-02-23-09:25">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in Xsun in Solaris 8 and earlier allows local users to execute arbitrary commands via a long HOME environmental variable.</description>
      <reference source="CVE">CVE-2001-0422</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-43" comment="Solaris 7 or 8 installed" negate="false"/>
          <criterion test_ref="spt-4" comment="Patch 108376-25 or later installed" negate="true"/>
          <criterion test_ref="spt-5" comment="Patch 108652-30 or later installed" negate="true"/>
          <criterion test_ref="sat-12" comment="X Window System platform software (SUNWxwplt) installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL556" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows ME</windows:platform>
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Microsoft Internet Explorer 6 Service Pack 1</product>
      </affected>
      <dates>
        <submitted date="2003-11-12-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <modified date="2004-01-21-12:00" comment="Removed the test for specific Windows operating systems.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 6 sp1 patch.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <modified date="2004-01-29-12:00" comment="Added Windows XP 64-bit to the list of affected platforms">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <modified date="2004-03-04-12:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <status_change date="2004-03-09-12:00">INTERIM</status_change>
        <status_change date="2004-03-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions and read arbitrary files via an XML object.</description>
      <reference source="CVE">CVE-2003-0817</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-50" comment="Internet Explorer 6 Service Pack 1 is installed" negate="false"/>
          <criterion test_ref="wft-27" comment="the version of mshtml.dll is less than 6.0.2800.1276" negate="false"/>
          <criterion test_ref="wrt-19" comment="the patch q824145 is installed (Installed Components key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL564" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Samba</product>
      </affected>
      <dates>
        <submitted date="2003-08-17-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Multiple buffer overflows in Samba before 2.2.8a may allow remote attackers to execute arbitrary code or cause a denial of service, as discovered by the Samba team and a different vulnerability than CVE-2003-0201.</description>
      <reference source="CVE">CVE-2003-0196</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-243" comment="samba version is less than 2.2.7a-8.9.0" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="rlt-210" comment="smbd is listening on the network" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL566" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Internet Explorer 6 Service Pack 1 for Windows Server 2003</product>
      </affected>
      <dates>
        <submitted date="2003-11-12-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <modified date="2004-01-21-12:00" comment="Removed the test for Windows Server 2003.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 6 sp1 patch.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <modified date="2004-01-29-12:00" comment="Added Windows XP 64-bit, Version 2003 and Windows Server 2003 64-Bit to the list of affected platforms">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <modified date="2004-03-04-12:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <status_change date="2004-03-09-12:00">INTERIM</status_change>
        <status_change date="2004-03-25-12:00">ACCEPTED</status_change>
        <modified date="2005-05-10-12:00" comment="modified wrt-51 - Comment updated to indicate IE 6.">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </modified>
        <status_change date="2005-05-11-05:33">INTERIM</status_change>
        <status_change date="2005-06-01-03:30">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions and read arbitrary files via an XML object.</description>
      <reference source="CVE">CVE-2003-0817</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-51" comment="Internet Explorer 6  for Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wft-28" comment="the version of mshtml.dll is less than 6.0.3790.94" negate="false"/>
          <criterion test_ref="wrt-60" comment="the patch q824145 is installed (Hotfix key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL567" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Samba, Samba-TNG</product>
      </affected>
      <dates>
        <submitted date="2003-08-17-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x versions, and Samba-TNG before 0.3.2, allows remote attackers to execute arbitrary code.</description>
      <reference source="CVE">CVE-2003-0201</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-243" comment="samba version is less than 2.2.7a-8.9.0" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="rlt-210" comment="smbd is listening on the network" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL569" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>semi MIME library</product>
      </affected>
      <dates>
        <submitted date="2003-08-29-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>The (1) semi MIME library 1.14.5 and earlier, and (2) wemi 1.14.0 and possibly other versions, allows local users to overwrite arbitrary files via a symlink attack on temporary files.</description>
      <reference source="CVE">CVE-2003-0440</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="cmp-319" comment="Vulnerable Config" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-320" comment="Vulnerable Config" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL572" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Sendmail</product>
      </affected>
      <dates>
        <submitted date="2003-08-11-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using the parseaddr function in parseaddr.c.</description>
      <reference source="CVE">CVE-2003-0694</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-246" comment="sendmail version is less than 8.12.8-5.90" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-323" comment="Vulnerable Config" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL573" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Windows Shell</product>
      </affected>
      <dates>
        <submitted date="2005-05-04-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2005-05-04-12:32">DRAFT</status_change>
        <status_change date="2005-06-01-03:30">INTERIM</status_change>
        <status_change date="2005-06-22-12:38">ACCEPTED</status_change>
      </dates>
      <description>The document processing application used by the Windows Shell in Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code by modifying the CLSID stored in a file so that it is processed by HTML Application Host (MSHTA), as demonstrated using a Microsoft Word document.</description>
      <reference source="CVE">CVE-2005-0063</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-35" comment="Windows XP 32 bit Service Pack 2" negate="false"/>
          <criterion test_ref="wft-591" comment="the version of shell32.dll is less than 6.0.2900.2620" negate="false"/>
          <criterion test_ref="wrt-435" comment="the patch  KB893086 is installed " negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-280" comment=".hta applications are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL575" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Windows Workstation Service</product>
      </affected>
      <dates>
        <submitted date="2003-11-12-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <status_change date="2004-03-09-12:00">ACCEPTED</status_change>
      </dates>
      <description>Stack-based buffer overflow in a logging function for Windows Workstation Service (WKSSVC.DLL) allows remote attackers to execute arbitrary code via RPC calls that cause long entries to be written to a debug log file ("NetSetup.LOG"), as demonstrated using the NetAddAlternateComputerName API.</description>
      <reference source="CVE">CVE-2003-0812</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
          <criterion test_ref="wft-8" comment="the version of wkssvc.dll is less than 5.00.2195.6862" negate="false"/>
          <criterion test_ref="wrt-86" comment="the patch q828748 is installed (Hotfix key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-71" comment="the workstation service is enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL576" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2005-10-12-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-10-19-05:46">DRAFT</status_change>
        <status_change date="2005-11-16-08:02">INTERIM</status_change>
        <status_change date="2005-12-01-06:00">ACCEPTED</status_change>
      </dates>
      <description>COM+ in Microsoft Windows does not properly "create and use memory structures," which allows local users or remote attackers to execute arbitrary code.</description>
      <reference source="CVE">CVE-2005-1978</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wrt-4" comment="Win2K/XP/2003 service pack 1 is installed" negate="false"/>
          <criterion test_ref="cmp-608" comment="Either ole32.dll or rpcss.dll has a version less than 5.2.3790.2492" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL581" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2005-10-12-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-10-19-05:46">DRAFT</status_change>
        <status_change date="2005-11-16-08:02">INTERIM</status_change>
        <status_change date="2005-12-01-06:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in Collaboration Data Objects (CDO), as used in Microsoft Windows and Microsoft Exchange Server, allows remote attackers to execute arbitrary code when CDOSYS or CDOEX processes an e-mail message with a large header name, as demonstrated using the "Content-Type" string.</description>
      <reference source="CVE">CVE-2005-1987</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wrt-4" comment="Win2K/XP/2003 service pack 1 is installed" negate="false"/>
          <criterion test_ref="wft-680" comment="cdosys.dll is less than 6.5.6756.0" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL582" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 98</windows:platform>
        <windows:platform>Microsoft Windows ME</windows:platform>
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Microsoft Virtual Machine (VM)</product>
      </affected>
      <dates>
        <submitted date="2004-04-30-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <status_change date="2004-05-25-12:00">INTERIM</status_change>
        <status_change date="2004-06-16-12:00">ACCEPTED</status_change>
      </dates>
      <description>Two vulnerabilities in Microsoft Virtual Machine (VM) up to and including build 5.0.3805, as used in Internet Explorer and other applications, allow remote attackers to read files via a Java applet with a spoofed location in the CODEBASE parameter in the APPLET tag, possibly due to a parsing error.</description>
      <reference source="CVE">CVE-2002-1258</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wft-302" comment="the version of msjava.dll is less than 5.0.3809.0" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL584" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>mozilla</product>
      </affected>
      <dates>
        <submitted date="2005-11-11-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-12-12-10:00">DRAFT</status_change>
        <status_change date="2005-12-28-04:28">INTERIM</status_change>
        <status_change date="2006-01-12-08:59">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the International Domain Name (IDN) support in Mozilla Firefox 1.0.6 and earlier, and Netscape 8.0.3.3 and 7.2, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a hostname with all "soft" hyphens (character 0xAD), which is not properly handled by the NormalizeIDN call in nsStandardURL::BuildNormalizedSpec.</description>
      <reference source="CVE">CVE-2005-2871</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-621" comment="Mozilla Suite version 1.7.10 or earlier is installed" negate="false"/>
          <criterion test_ref="cmp-631" comment="Mozilla Firefox version 1.0.6 or earlier is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL585" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 95</windows:platform>
        <windows:platform>Microsoft Windows 98</windows:platform>
        <windows:platform>Microsoft Windows ME</windows:platform>
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Word 97</product>
      </affected>
      <dates>
        <submitted date="2003-11-19-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <status_change date="2004-03-09-12:00">INTERIM</status_change>
        <status_change date="2004-03-25-12:00">ACCEPTED</status_change>
        <modified date="2005-04-11-12:00" comment="modified wft-17 - wft-17 corrected literal string">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <status_change date="2005-04-11-12:01">INTERIM</status_change>
        <modified date="2005-04-20-12:00" comment="Corrected unknown test">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
      </dates>
      <description>Microsoft Word 97, 98(J), 2000, and 2002, and Microsoft Works Suites 2001 through 2004, do not properly check the length of the "Macro names" data value, which could allow remote attackers to execute arbitrary code via a buffer overflow attack.</description>
      <reference source="CVE">CVE-2003-0820</reference>
      <status>INTERIM</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="ukn-10" comment="Word 97 is installed" negate="false"/>
          <criterion test_ref="wft-17" comment="the version of winword.exe is less than 8.0.0.9315" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL586" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 95</windows:platform>
        <windows:platform>Microsoft Windows 98</windows:platform>
        <windows:platform>Microsoft Windows ME</windows:platform>
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Word 98</product>
      </affected>
      <dates>
        <submitted date="2003-11-19-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <status_change date="2004-03-09-12:00">INTERIM</status_change>
        <status_change date="2004-03-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Word 97, 98(J), 2000, and 2002, and Microsoft Works Suites 2001 through 2004, do not properly check the length of the "Macro names" data value, which could allow remote attackers to execute arbitrary code via a buffer overflow attack.</description>
      <reference source="CVE">CVE-2003-0820</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="ukn-11" comment="Word 98 is installed" negate="false"/>
          <criterion test_ref="wft-18" comment="the version of winword.exe is less than 8.0.0.9716" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL587" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Windows Shell</product>
      </affected>
      <dates>
        <submitted date="2005-05-04-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2005-05-04-12:32">DRAFT</status_change>
        <status_change date="2005-06-01-03:30">INTERIM</status_change>
        <status_change date="2005-06-22-12:38">ACCEPTED</status_change>
      </dates>
      <description>The document processing application used by the Windows Shell in Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code by modifying the CLSID stored in a file so that it is processed by HTML Application Host (MSHTA), as demonstrated using a Microsoft Word document.</description>
      <reference source="CVE">CVE-2005-0063</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-183" comment="Windows Server 2003 64-Bit Edition or Windows XP 64-Bit Edition Version 2003 " negate="false"/>
          <criterion test_ref="wft-589" comment="the version of shell32.dll is less than 6.0.3790.274" negate="false"/>
          <criterion test_ref="wrt-434" comment="the patch  KB893086 is installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-280" comment=".hta applications are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL588" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Internet Explorer 6 Service Pack 1 for Windows Server 2003</product>
      </affected>
      <dates>
        <submitted date="2003-12-18-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <modified date="2004-01-21-12:00" comment="Removed the test for Windows Server 2003.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 6 sp1 patch.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <modified date="2004-01-29-12:00" comment="Added Windows XP 64-bit, Version 2003 and Windows Server 2003 64-Bit to the list of affected platforms">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <modified date="2004-03-04-12:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <status_change date="2004-03-09-12:00">INTERIM</status_change>
        <status_change date="2004-03-25-12:00">ACCEPTED</status_change>
        <modified date="2005-05-10-12:00" comment="modified wrt-51 - Comment updated to indicate IE 6.">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </modified>
        <status_change date="2005-05-11-05:33">INTERIM</status_change>
        <status_change date="2005-06-01-03:30">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 6 SP1 and earlier allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by calling the window.moveBy method, aka HijackClick, a different vulnerability than CVE-2003-1027.</description>
      <reference source="CVE">CVE-2003-0823</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-51" comment="Internet Explorer 6  for Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wft-28" comment="the version of mshtml.dll is less than 6.0.3790.94" negate="false"/>
          <criterion test_ref="wrt-60" comment="the patch q824145 is installed (Hotfix key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL591" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>Microsoft FrontPage Server Extensions 2000</product>
      </affected>
      <dates>
        <submitted date="2003-12-09-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <modified date="2004-01-14-12:00" comment="Changed the definition to look at the file shtml.dll instead of fp4awel.dll.  It was determined that this is where the vulnerability (a buffer overflow) actually existed.  Also added the configuration test saying you are vulnerable if the SmartHTML interpreter is enabled.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <status_change date="2004-03-09-12:00">INTERIM</status_change>
        <status_change date="2004-03-25-12:00">ACCEPTED</status_change>
        <modified date="2005-09-26-10:51" comment="modified wft-12 - Changed comment to match test">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-28-01:04">INTERIM</status_change>
        <status_change date="2005-10-19-05:47">ACCEPTED</status_change>
      </dates>
      <description>Unknown vulnerability in the SmartHTML interpreter (shtml.dll) in Microsoft FrontPage Server Extensions 2000 and 2002, and Microsoft SharePoint Team Services 2002, allows remote attackers to cause a denial of service (response failure) via a certain request.</description>
      <reference source="CVE">CVE-2003-0824</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" negate="false"/>
          <criterion test_ref="wft-12" comment="the version of shtml.dll is less than 4.00.02.7523" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-33" comment="FrontPage Server Extensions 2000 are enabled (WinNT)" negate="false"/>
          <criterion test_ref="wmt-2" comment="SmartHTML interpreter is enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL592" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Licence Logging Service</product>
      </affected>
      <dates>
        <submitted date="2005-04-13-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-04-20-12:13">DRAFT</status_change>
        <status_change date="2005-05-11-05:41">INTERIM</status_change>
        <status_change date="2005-06-01-03:30">ACCEPTED</status_change>
      </dates>
      <description>Unknown vulnerability in the rwho daemon (in.rwhod) for Solaris 7 through 9 allows remote attackers to execute arbitrary code.</description>
      <reference source="CVE">CVE-2004-1351</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-87" comment="Solaris 7 or 8 OR Solaris 9 and Remote Network Server Commands (SUNWrcmds) installed" negate="false"/>
          <criterion test_ref="spt-68" comment="Patch 118239-01 or later installed" negate="true"/>
          <criterion test_ref="spt-69" comment="Patch 116984-01 or later installed" negate="true"/>
          <criterion test_ref="spt-70" comment="Patch 117455-01 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-19" comment="in.rwhod is running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL594" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>MSN Messenger</product>
      </affected>
      <dates>
        <submitted date="2005-03-29-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2005-03-29-08:38">DRAFT</status_change>
        <status_change date="2005-04-13-12:15">INTERIM</status_change>
        <status_change date="2005-05-04-12:33">ACCEPTED</status_change>
        <modified date="2005-11-24-12:00" comment="Added wrt-620 to see if MSN Messenger 6.2 is installed.  Changed wrt-195 to check for 6.2.0205 or later.">
          <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
        </modified>
        <status_change date="2005-12-12-09:30">INTERIM</status_change>
        <modified date="2005-12-20-07:05" comment="Added wrt-195.">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </modified>
        <status_change date="2006-01-04-08:04">ACCEPTED</status_change>
      </dates>
      <description>Multiple buffer overflows in libpng 1.2.5 and earlier, as used in multiple products, allow remote attackers to execute arbitrary code via malformed PNG images in which (1) the png_handle_tRNS function does not properly validate the length of transparency chunk (tRNS) data, or the (2) png_handle_sBIT or (3) png_handle_hIST functions do not perform sufficient bounds checking.</description>
      <reference source="CVE">CVE-2004-0597</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-620" comment="MSN Messenger 6.2 is installed" negate="false"/>
          <criterion test_ref="wrt-195" comment="MSN Messenger 6.2.0205 or later is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL595" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Sendmail</product>
      </affected>
      <dates>
        <submitted date="2003-09-21-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>A "potential buffer overflow in ruleset parsing" for Sendmail 8.12.9, when using the nonstandard rulesets (1) recipient (2), final, or (3) mailer-specific envelope recipients, has unknown consequences.</description>
      <reference source="CVE">CVE-2003-0681</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-247" comment="sendmail version is less than 8.12.8-9.90" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-323" comment="Vulnerable Config" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL597" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Sendmail</product>
      </affected>
      <dates>
        <submitted date="2003-09-05-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>The DNS map code in Sendmail 8.12.8 and earlier, when using the "enhdnsbl" feature, does not properly initialize certain data structures, which allows remote attackers to cause a denial of service (process crash) via an invalid DNS response that causes Sendmail to free incorrect data.</description>
      <reference source="CVE">CVE-2003-0688</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-248" comment="sendmail version is less than 8.12.8-6.90" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="rlt-212" comment="sendmail is listening to the network" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL598" class="vulnerability">
      <affected family="hp-ux">
        <hpux:platform>HP-UX 11</hpux:platform>
        <product>remshd</product>
      </affected>
      <dates>
        <submitted date="2005-11-30-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-12-20-11:03">DRAFT</status_change>
        <status_change date="2006-01-04-08:04">INTERIM</status_change>
        <status_change date="2006-01-25-07:30">ACCEPTED</status_change>
      </dates>
      <description>Unspecified vulnerability in xterm for HP-UX 11.00, 11.11, and 11.23 allows local users to gain privileges via unknown vectors.</description>
      <reference source="CVE">CVE-2005-3779</reference>
      <status>ACCEPTED</status>
      <version>5</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-684" comment="700 Series or 800 Series OS Release 11.00, 11.11, or 11.23" negate="false"/>
          <criterion test_ref="hst-28" comment="X11.X11-RUN-CL is installed" negate="false"/>
          <criterion test_ref="cmp-685" comment="A vulnerable patch to xterm is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL603" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Sendmail</product>
      </affected>
      <dates>
        <submitted date="2003-09-21-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using the parseaddr function in parseaddr.c.</description>
      <reference source="CVE">CVE-2003-0694</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-247" comment="sendmail version is less than 8.12.8-9.90" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-323" comment="Vulnerable Config" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL605" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Services for UNIX</product>
      </affected>
      <dates>
        <submitted date="2005-06-22-12:00">
          <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
        </submitted>
        <status_change date="2005-06-22-12:38">DRAFT</status_change>
        <status_change date="2005-07-27-10:37">INTERIM</status_change>
        <status_change date="2005-08-18-07:37">ACCEPTED</status_change>
      </dates>
      <description>The Telnet client for Microsoft Windows XP, Windows Server 2003, and Windows Services for UNIX allows remote attackers to read sensitive environment variables via the NEW-ENVIRON option with a SEND ENV_USERVAR command.</description>
      <reference source="CVE">CVE-2005-1205</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="cmp-167" comment="a vulnerable version of telnet.exe exists" negate="false"/>
          <criterion test_ref="wrt-27" comment="the patch KB896428 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL606" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Microsoft FrontPage Server Extensions 2000</product>
      </affected>
      <dates>
        <submitted date="2003-12-09-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <modified date="2004-01-14-12:00" comment="Changed the definition to look at the file shtml.dll instead of fp4awel.dll.  It was determined that this is where the vulnerability (a buffer overflow) actually existed.  Also added the configuration test saying you are vulnerable if the SmartHTML interpreter is enabled.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <status_change date="2004-03-09-12:00">INTERIM</status_change>
        <status_change date="2004-03-25-12:00">ACCEPTED</status_change>
        <modified date="2005-09-26-10:51" comment="modified wft-12 - Changed comment to match test">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-28-01:04">INTERIM</status_change>
        <status_change date="2005-10-19-05:47">ACCEPTED</status_change>
      </dates>
      <description>Unknown vulnerability in the SmartHTML interpreter (shtml.dll) in Microsoft FrontPage Server Extensions 2000 and 2002, and Microsoft SharePoint Team Services 2002, allows remote attackers to cause a denial of service (response failure) via a certain request.</description>
      <reference source="CVE">CVE-2003-0824</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-66" comment="Windows XP (sp1 or earlier) is installed" negate="false"/>
          <criterion test_ref="wft-12" comment="the version of shtml.dll is less than 4.00.02.7523" negate="false"/>
          <criterion test_ref="wrt-88" comment="the patch q810217 is installed (Hotfix key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-31" comment="FrontPage Server Extensions 2000 are enabled (2K, XP)" negate="false"/>
          <criterion test_ref="wmt-2" comment="SmartHTML interpreter is enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL608" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Internet Explorer 6.0 for Windows Server 2003</product>
      </affected>
      <dates>
        <submitted date="2005-06-22-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2005-06-22-12:38">DRAFT</status_change>
        <status_change date="2005-07-27-10:37">INTERIM</status_change>
        <status_change date="2005-08-18-07:37">ACCEPTED</status_change>
      </dates>
      <description>The legacy &lt;script> data-island capability for XML in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to read arbitrary XML files, and portions of other files, via a URL whose "src" attribute redirects to a local file.</description>
      <reference source="CVE">CVE-2002-0648</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-51" comment="Internet Explorer 6  for Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="cmp-179" comment="a vulnerable version of mshtml.dll exisits" negate="false"/>
          <criterion test_ref="wrt-62" comment="the patch kb883939 is installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL614" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>SquirrelMail</product>
      </affected>
      <dates>
        <submitted date="2003-08-17-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail before 1.2.11 allow remote attackers to inject arbitrary HTML code and steal information from a client's web browser.</description>
      <reference source="CVE">CVE-2003-0160</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-249" comment="squirrelmail version is less than 1.2.11-1" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL619" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>unzip</product>
      </affected>
      <dates>
        <submitted date="2003-09-04-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Directory traversal vulnerability in UnZip 5.50 allows attackers to overwrite arbitrary files via invalid characters between two . (dot) characters, which are filtered and result in a ".." sequence.</description>
      <reference source="CVE">CVE-2003-0282</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-250" comment="unzip version is less than 5.50-33" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-335" comment="/usr/bin/unzip is executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL623" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>sysreport</product>
      </affected>
      <dates>
        <submitted date="2005-07-11-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2005-07-27-10:36">DRAFT</status_change>
        <status_change date="2005-08-18-07:37">INTERIM</status_change>
        <status_change date="2005-09-21-01:33">ACCEPTED</status_change>
      </dates>
      <description>sysreport 1.3.15 and earlier includes contents of the up2date file in a report, which leaks the password for a proxy server in plaintext and allows local users to gain privileges.</description>
      <reference source="CVE">CVE-2005-1760</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="rvt-24" comment="sysreport RPM earlier than 0:1.3.7.2-6" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="upt-58" comment="/tmp is world-writable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL624" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Outlook</product>
      </affected>
      <dates>
        <submitted date="2006-01-11-12:56">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-01-12-09:21">DRAFT</status_change>
        <status_change date="2006-02-01-09:08">INTERIM</status_change>
        <status_change date="2006-02-22-08:27">ACCEPTED</status_change>
      </dates>
      <description>Unspecified vulnerability in Microsoft Outlook 2000 through 2003, Exchange 5.0 Server SP2 and 5.5 SP4, Exchange 2000 SP3, and Office allows remote attackers to execute arbitrary code via an e-mail message with a crafted Transport Neutral Encapsulation Format (TNEF) MIME attachment, related to message length validation.</description>
      <reference source="CVE">CVE-2006-0002</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-504" comment="Exchange 5.5 with SP4 Installed" negate="false"/>
          <criterion test_ref="wft-734" comment="the version of Mapi32.dll is less than 5.5.2658.34" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL625" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Microsoft FrontPage Server Extensions 2002</product>
      </affected>
      <dates>
        <submitted date="2003-12-09-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <modified date="2004-01-14-12:00" comment="Changed the definition to look at the file shtml.dll instead of fp5awel.dll.  It was determined that this is where the vulnerability (a buffer overflow) actually existed.  Also added the configuration test saying you are vulnerable if the SmartHTML interpreter is enabled.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <status_change date="2004-03-09-12:00">INTERIM</status_change>
        <status_change date="2004-03-25-12:00">ACCEPTED</status_change>
        <modified date="2004-09-14-09:52" comment="XP SP2 added">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2004-09-15-12:00">INTERIM</status_change>
      </dates>
      <description>Unknown vulnerability in the SmartHTML interpreter (shtml.dll) in Microsoft FrontPage Server Extensions 2000 and 2002, and Microsoft SharePoint Team Services 2002, allows remote attackers to cause a denial of service (response failure) via a certain request.</description>
      <reference source="CVE">CVE-2003-0824</reference>
      <status>INTERIM</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-77" comment="Windows NT, 2000, or XP is installed" negate="false"/>
          <criterion test_ref="ukn-13" comment="a vulnerable version of shtml.dll exists (FPSE 2002 or SPTS 2003)" negate="false"/>
          <criterion test_ref="wrt-29" comment="Win2K/XP/2003 service pack 2 (or later) is installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-32" comment="FrontPage Server Extensions 2002 are enabled (NT, 2K, XP)" negate="false"/>
          <criterion test_ref="wmt-2" comment="SmartHTML interpreter is enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL629" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Internet Explorer 6 Service Pack 1 for Windows Server 2003</product>
      </affected>
      <dates>
        <submitted date="2004-02-03-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <modified date="2004-03-04-12:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <status_change date="2004-03-09-12:00">INTERIM</status_change>
        <status_change date="2004-03-25-12:00">ACCEPTED</status_change>
        <modified date="2005-05-10-12:00" comment="modified wrt-51 - Comment updated to indicate IE 6.">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </modified>
        <status_change date="2005-05-11-05:33">INTERIM</status_change>
        <status_change date="2005-06-01-03:30">ACCEPTED</status_change>
        <modified date="2005-09-26-12:54" comment="modified wft-95 - Changed comment to match test">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-28-01:04">INTERIM</status_change>
        <status_change date="2005-10-19-05:47">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by using method caching (SaveRef) to access the window.moveBy method, which is otherwise inaccessible, as demonstrated by HijackClickV2, a different vulnerability than CVE-2003-0823, aka the "Function Pointer Drag and Drop Vulnerability."</description>
      <reference source="CVE">CVE-2003-1027</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-51" comment="Internet Explorer 6  for Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wft-95" comment="the version of mshtml.dll is less than 6.0.3790.118" negate="false"/>
          <criterion test_ref="wrt-140" comment="the patch q832894 is installed (Hotfix key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL630" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Internet Explorer 5.01 Service Pack 2</product>
      </affected>
      <dates>
        <submitted date="2004-02-03-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <modified date="2004-03-04-12:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <status_change date="2004-03-09-12:00">INTERIM</status_change>
        <status_change date="2004-03-25-12:00">ACCEPTED</status_change>
        <modified date="2005-09-26-12:50" comment="modified wft-90 - Changed comment to match test">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-28-01:04">INTERIM</status_change>
        <status_change date="2005-10-19-05:47">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions via a javascript protocol URL in a sub-frame, which is added to the history list and executed in the top window's zone when the history.back (back) function is called, as demonstrated by BackToFramedJpu, aka the "Travel Log Cross Domain Vulnerability."</description>
      <reference source="CVE">CVE-2003-1026</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-56" comment="Internet Explorer 5.01 Service Pack 2 is installed" negate="false"/>
          <criterion test_ref="wft-90" comment="the version of mshtml.dll is less than 5.0.3526.800" negate="false"/>
          <criterion test_ref="wrt-141" comment="the patch q832894 is installed (Installed Components key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL631" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>up2date</product>
      </affected>
      <dates>
        <submitted date="2003-09-03-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>up2date 3.0.7 and 3.1.23 does not properly verify RPM GPG signatures, which could allow remote attackers to cause unsigned packages to be installed from the Red Hat Network, if that network is compromised.</description>
      <reference source="CVE">CVE-2003-0546</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-251" comment="up2date version is less than 3.1.23.1-5" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-2" comment="rhnsd is running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL634" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>vsftpd</product>
      </affected>
      <dates>
        <submitted date="2003-08-11-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>vsftpd FTP daemon in Red Hat Linux 9 is not compiled against TCP wrappers (tcp_wrappers) but is installed as a standalone service, which inadvertently prevents vsftpd from restricting access as intended.</description>
      <reference source="CVE">CVE-2003-0135</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-252" comment="vsftpd version is less than 1.1.3-8" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="rlt-213" comment="vsftpd is listening to the network" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL636" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 95</windows:platform>
        <windows:platform>Microsoft Windows 98</windows:platform>
        <windows:platform>Microsoft Windows ME</windows:platform>
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Excel 2000</product>
      </affected>
      <dates>
        <submitted date="2003-11-19-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2004-03-09-12:00">ACCEPTED</status_change>
        <modified date="2005-04-11-12:00" comment="modified wft-15 - wft-15 corrected literal string">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <status_change date="2005-04-11-08:48">INTERIM</status_change>
        <status_change date="2005-04-27-12:07">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Excel 97, 2000, and 2002 allows remote attackers to execute arbitrary code via a spreadsheet with a malicious XLM (Excel 4) macro that bypasses the macro security model.</description>
      <reference source="CVE">CVE-2003-0821</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-137" comment="Excel 2000 is installed" negate="false"/>
          <criterion test_ref="wft-15" comment="the version of excel.exe is less than 9.0.0.8216" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL637" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>mozilla</product>
      </affected>
      <dates>
        <submitted date="2005-08-15-04:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2005-08-19-10:05">DRAFT</status_change>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>A regression error in Firefox 1.0.3 and Mozilla 1.7.7 allows remote attackers to inject arbitrary Javascript from one page into the frameset of another site, aka the frame injection spoofing vulnerability, a re-introduction of a vulnerability that was originally identified and addressed by CVE-2004-0718.</description>
      <reference source="CVE">CVE-2005-1937</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-216" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="rvt-31" comment="mozilla RPM is earlier than 37:1.7.10-1.1.3.1" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="upt-859" comment="/usr/bin/mozilla is executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL642" class="vulnerability">
      <affected family="hp-ux">
        <hpux:platform>HP-UX 11</hpux:platform>
        <product>Samba</product>
      </affected>
      <dates>
        <submitted date="2006-01-13-02:24">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-01-25-07:30">DRAFT</status_change>
        <status_change date="2006-02-22-08:27">INTERIM</status_change>
        <status_change date="2006-03-09-12:19">ACCEPTED</status_change>
      </dates>
      <description>Integer overflow in the Samba daemon (smbd) in Samba 2.x and 3.0.x through 3.0.9 allows remote authenticated users to cause a denial of service (application crash) and possibly execute arbitrary code via a Samba request with a large number of security descriptors that triggers a heap-based buffer overflow.</description>
      <reference source="CVE">CVE-2004-1154</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-716" comment="An HPUX 11.11 or 11.23 is installed" negate="false"/>
          <criterion test_ref="cmp-718" comment="Any of the CIFS components has a version equal to A.02.01" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL643" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Internet Explorer 5.01 Service Pack 3</product>
      </affected>
      <dates>
        <submitted date="2004-02-03-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <modified date="2004-03-04-12:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <status_change date="2004-03-09-12:00">INTERIM</status_change>
        <status_change date="2004-03-25-12:00">ACCEPTED</status_change>
        <modified date="2005-09-26-12:50" comment="modified wft-90 - Changed comment to match test">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-28-01:04">INTERIM</status_change>
        <status_change date="2005-10-19-05:47">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions via a javascript protocol URL in a sub-frame, which is added to the history list and executed in the top window's zone when the history.back (back) function is called, as demonstrated by BackToFramedJpu, aka the "Travel Log Cross Domain Vulnerability."</description>
      <reference source="CVE">CVE-2003-1026</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-55" comment="Internet Explorer 5.01 Service Pack 3 is installed" negate="false"/>
          <criterion test_ref="wft-90" comment="the version of mshtml.dll is less than 5.0.3526.800" negate="false"/>
          <criterion test_ref="wrt-141" comment="the patch q832894 is installed (Installed Components key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL644" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>MDAC 2.8</product>
      </affected>
      <dates>
        <submitted date="2005-03-29-12:00">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </submitted>
        <status_change date="2005-03-29-08:38">DRAFT</status_change>
        <status_change date="2005-04-13-12:15">INTERIM</status_change>
        <status_change date="2005-05-04-12:33">ACCEPTED</status_change>
      </dates>
      <description>The License Logging service for Windows NT Server, Windows 2000 Server, and Windows Server 2003 does not properly validate the length of messages, which leads to an "unchecked buffer" and allows remote attackers to cause a denial of service (crash) and possibly execute arbtirary code, aka the "License Logging Service Vulnerability."</description>
      <reference source="CVE">CVE-2005-0050</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-45" comment="Windows NT Server 4.0, Terminal Server Edition is installed" negate="false"/>
          <criterion test_ref="wrt-96" comment="the patch kb885834 is installed (Hotfix key)" negate="true"/>
          <criterion test_ref="wft-393" comment="the version of Llssrv.exe is less than 4.0.1381.33632" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-344" comment="license logging service is enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL647" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>mikmod</product>
      </affected>
      <dates>
        <submitted date="2005-06-20-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2005-06-22-12:38">DRAFT</status_change>
        <status_change date="2005-07-27-10:37">INTERIM</status_change>
        <status_change date="2005-08-18-07:37">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in mikmod 3.1.6 and earlier allows remote attackers to execute arbitrary code via an archive file that contains a file with a long filename.</description>
      <reference source="CVE">CVE-2003-0427</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="rvt-8" comment="mikmod RPM prior to 0:3.1.6-22.EL3" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="upt-730" comment="/usr/bin/mikmod is executable by any user" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL648" class="vulnerability">
      <affected family="hp-ux">
        <hpux:platform>HP-UX 11</hpux:platform>
        <product>ftpd</product>
      </affected>
      <dates>
        <submitted date="2006-01-30-07:20">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-02-01-09:08">DRAFT</status_change>
        <status_change date="2006-02-22-08:27">INTERIM</status_change>
        <status_change date="2006-03-09-12:19">ACCEPTED</status_change>
      </dates>
      <description>wu-ftpd 2.6.2 and earlier, with the restricted-gid option enabled, allows local users to bypass access restrictions by changing the permissions to prevent access to their home directory, which causes wu-ftpd to use the root directory instead.</description>
      <reference source="CVE">CVE-2004-0148</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-682" comment="700 Series or 800 Series OS Release 11.23" negate="false"/>
          <criterion test_ref="hst-26" comment="InternetSrvcs.INETSVCS2-RUN is installed" negate="false"/>
          <criterion test_ref="cmp-725" comment="Either PHNE_30983 or PHNE_31732 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL653" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft ASN.1 Library</product>
      </affected>
      <dates>
        <submitted date="2004-02-12-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <status_change date="2004-03-09-12:00">INTERIM</status_change>
        <status_change date="2004-03-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Multiple integer overflows in Microsoft ASN.1 library (MSASN1.DLL), as used in LSASS.EXE, CRYPT32.DLL, and other Microsoft executables and libraries on Windows NT 4.0, 2000, and XP, allow remote attackers to execute arbitrary code via ASN.1 BER encodings with (1) very large length fields that cause arbitrary heap data to be overwritten, or (2) modified bit strings.</description>
      <reference source="CVE">CVE-2003-0818</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
          <criterion test_ref="wft-49" comment="the version of msasn1.dll is less than 5.0.2195.6823" negate="false"/>
          <criterion test_ref="wrt-99" comment="the patch kb828028 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL657" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>xinetd</product>
      </affected>
      <dates>
        <submitted date="2003-08-18-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <modified date="2004-05-17-12:00" comment="Changed tested epoch in xinetd test rvt-253 to 2, based on testing.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-06-16-12:00">ACCEPTED</status_change>
      </dates>
      <description>Memory leak in xinetd 2.3.10 allows remote attackers to cause a denial of service (memory consumption) via a large number of rejected connections.</description>
      <reference source="CVE">CVE-2003-0211</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-253" comment="xinetd version is less than 2:2.3.11-1.9.0" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="rlt-214" comment="xinetd is listening to the network" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL662" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <solaris:platform>Sun Solaris 10</solaris:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2006-01-16-12:05">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-01-25-07:30">DRAFT</status_change>
        <status_change date="2006-02-22-08:27">INTERIM</status_change>
        <status_change date="2006-03-09-12:19">ACCEPTED</status_change>
      </dates>
      <description>Multiple unspecified vulnerabilities in lpsched in Sun Solaris 8, 9, and 10 allow local users to delete arbitrary files or disable the LP print service via unknown attack vectors.</description>
      <reference source="CVE">CVE-2006-0227</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-719" comment="Solaris 8 (SPARC) meets Sun Alert ID 102033 criteria." negate="false"/>
          <criterion test_ref="cmp-720" comment="Solaris 8 (x86) meets Sun Alert ID 102033 criteria." negate="false"/>
          <criterion test_ref="cmp-721" comment="Solaris 9 (SPARC) meets Sun Alert ID 102033 criteria." negate="false"/>
          <criterion test_ref="cmp-722" comment="Solaris 9 (x86) meets Sun Alert ID 102033 criteria." negate="false"/>
          <criterion test_ref="cmp-723" comment="Solaris 10 (sparc) meets Sun Alert ID 102033 criteria." negate="false"/>
          <criterion test_ref="cmp-724" comment="Solaris 10 (x86) meets Sun Alert ID 102033 criteria." negate="false"/>
          <criterion test_ref="uft-32" comment="Target is configured as a print server" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL664" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>xpdf</product>
      </affected>
      <dates>
        <submitted date="2003-08-29-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <status_change date="2004-05-05-12:00">ACCEPTED</status_change>
      </dates>
      <description>Various PDF viewers including (1) Adobe Acrobat 5.06 and (2) Xpdf 1.01 allow remote attackers to execute arbitrary commands via shell metacharacters in an embedded hyperlink.</description>
      <reference source="CVE">CVE-2003-0434</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-254" comment="xpdf version is less than 2.0.1-11" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-338" comment="xpdf is executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL667" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>ypserv</product>
      </affected>
      <dates>
        <submitted date="2003-08-29-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>ypserv NIS server before 2.7 allows remote attackers to cause a denial of service via a TCP client request that does not respond to the server, which causes ypserv to block.</description>
      <reference source="CVE">CVE-2003-0251</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-255" comment="ypserv version is less than 2.8-0.9E" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="rlt-215" comment="ypserv is listening on the network" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL668" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 95</windows:platform>
        <windows:platform>Microsoft Windows 98</windows:platform>
        <windows:platform>Microsoft Windows ME</windows:platform>
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Word 2002</product>
      </affected>
      <dates>
        <submitted date="2003-11-19-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <status_change date="2004-03-09-12:00">INTERIM</status_change>
        <status_change date="2004-03-25-12:00">ACCEPTED</status_change>
        <modified date="2005-04-11-12:00" comment="modified wft-22 - wft-22 corrected literal string">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <status_change date="2005-04-11-08:48">INTERIM</status_change>
        <status_change date="2005-04-27-12:07">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Word 97, 98(J), 2000, and 2002, and Microsoft Works Suites 2001 through 2004, do not properly check the length of the "Macro names" data value, which could allow remote attackers to execute arbitrary code via a buffer overflow attack.</description>
      <reference source="CVE">CVE-2003-0820</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-133" comment="Word 2002 is installed" negate="false"/>
          <criterion test_ref="wft-22" comment="the version of winword.exe is less than 10.0.5815.0" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL670" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>mozilla</product>
      </affected>
      <dates>
        <submitted date="2006-02-07-06:13">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-02-22-08:27">DRAFT</status_change>
        <status_change date="2006-03-09-12:19">INTERIM</status_change>
        <status_change date="2006-04-06-06:30">ACCEPTED</status_change>
      </dates>
      <description>The Javascript interpreter (jsinterp.c) in Mozilla and Firefox before 1.5.1 does not properly dereference objects, which allows remote attackers to cause a denial of service (crash) or execute arbitrary code via unknown attack vectors related to garbage collection.</description>
      <reference source="CVE">CVE-2006-0292</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-749" comment="Mozilla Thunderbird pre-1.5 is installed without an upgraded Firefox (1.5.0.1)" negate="false"/>
          <criterion test_ref="cmp-748" comment="Mozilla Firefox pre-1.5 is installed" negate="false"/>
          <criterion test_ref="cmp-744" comment="Mozilla Firefox version 1.5 is installed and has NOT been patched with version 1.5.0.1" negate="false"/>
          <criterion test_ref="cmp-746" comment="Mozilla Suite is installed" negate="false"/>
          <criterion test_ref="cmp-747" comment="A pre-release of SeaMonkey 1.0 is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL671" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2005-11-09-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-11-10-07:06">DRAFT</status_change>
        <status_change date="2005-12-01-06:00">INTERIM</status_change>
        <status_change date="2005-12-16-01:04">ACCEPTED</status_change>
      </dates>
      <description>The GetEnhMetaFilePaletteEntries API in GDI32.DLL in Windows 2000 allows remote attackers to cause a denial of service (application crash) via a crafted Enhanced Metafile (EMF) file that causes invalid (1) end, (2) emreof, or (3) palent offsets to be used, aka "Enhanced Metafile Vulnerability."</description>
      <reference source="CVE">CVE-2005-0803</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-647" comment="64-bit XP or Server 2003 is installed" negate="false"/>
          <criterion test_ref="wrt-10026" comment="Win2K/XP/2003 is patched" negate="true"/>
          <criterion test_ref="wft-702" comment="the version of Gdi32.dll is less than 5.2.3790.419" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL675" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 95</windows:platform>
        <windows:platform>Microsoft Windows 98</windows:platform>
        <windows:platform>Microsoft Windows ME</windows:platform>
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Excel 97</product>
      </affected>
      <dates>
        <submitted date="2003-11-19-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <status_change date="2004-03-09-12:00">INTERIM</status_change>
        <status_change date="2004-03-25-12:00">ACCEPTED</status_change>
        <modified date="2005-04-11-12:00" comment="modified wft-14 - wft-14 corrected literal string">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <status_change date="2005-04-11-08:48">INTERIM</status_change>
      </dates>
      <description>Microsoft Excel 97, 2000, and 2002 allows remote attackers to execute arbitrary code via a spreadsheet with a malicious XLM (Excel 4) macro that bypasses the macro security model.</description>
      <reference source="CVE">CVE-2003-0821</reference>
      <status>INTERIM</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="ukn-12" comment="Excel 97 is installed" negate="false"/>
          <criterion test_ref="wft-14" comment="the version of excel.exe is less than 8.00.01.9904" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL676" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>postgresql</product>
      </affected>
      <dates>
        <submitted date="2005-06-27-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2005-06-29-06:49">DRAFT</status_change>
        <status_change date="2005-07-27-10:37">INTERIM</status_change>
        <status_change date="2005-08-18-07:37">ACCEPTED</status_change>
      </dates>
      <description>PostgreSQL 7.3.x through 8.0.x gives public EXECUTE access to certain character conversion functions, which allows unprivileged users to call those functions with malicious values, with unknown impact, aka the "Character conversion vulnerability."</description>
      <reference source="CVE">CVE-2005-1409</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="rvt-9" comment="rh-postgresql-server is earlier than 0:7.3.10-1" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-1" comment="postmaster (the PostgreSQL master daemon) is running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL677" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>mozilla</product>
      </affected>
      <dates>
        <submitted date="2006-02-07-06:13">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-02-22-08:27">DRAFT</status_change>
        <status_change date="2006-03-09-12:19">INTERIM</status_change>
        <status_change date="2006-04-06-06:30">ACCEPTED</status_change>
      </dates>
      <description>The XML parser in Mozilla Firefox before 1.5.0.1 and SeaMonkey before 1.0 allows remote attackers to cause a denial of service (crash) and possibly read sensitive data via unknown attack vectors that trigger an out-of-bounds read.</description>
      <reference source="CVE">CVE-2006-0298</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-744" comment="Mozilla Firefox version 1.5 is installed and has NOT been patched with version 1.5.0.1" negate="false"/>
          <criterion test_ref="cmp-747" comment="A pre-release of SeaMonkey 1.0 is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL678" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2006-02-17-07:36">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-02-22-08:27">DRAFT</status_change>
        <status_change date="2006-03-09-12:19">INTERIM</status_change>
        <status_change date="2006-04-06-06:30">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Windows XP SP1 and SP2, and Server 2003 up to SP1, allows remote attackers to cause a denial of service (hang) via certain malformed IGMP packets, aka the "IGMP v3 DoS Vulnerability."</description>
      <reference source="CVE">CVE-2006-0021</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wrt-4" comment="Win2K/XP/2003 service pack 1 is installed" negate="false"/>
          <criterion test_ref="wft-758" comment="the version of Tcpip.sys is less than 5.2.3790.2617 (64-bit,SP1)" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL681" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>NetDDE Agent</product>
      </affected>
      <dates>
        <submitted date="2004-08-24-12:00">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </submitted>
        <status_change date="2004-08-25-03:00">DRAFT</status_change>
        <status_change date="2004-09-09-12:00">INTERIM</status_change>
        <status_change date="2004-09-29-12:00">ACCEPTED</status_change>
      </dates>
      <description>NetDDE Agent on Windows NT 4.0, 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows local users to execute arbitrary code as LocalSystem via "shatter" style attack by sending a WM_COPYDATA message followed by a WM_TIMER message, as demonstrated by GetAd, aka "Flaw in Windows WM_TIMER Message Handling Could Enable Privilege Elevation."</description>
      <reference source="CVE">CVE-2002-1230</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" negate="false"/>
          <criterion test_ref="wrt-43" comment="this is an NT Terminal Server" negate="true"/>
          <criterion test_ref="wft-474" comment="the version of user32.dll is less than 4.0.1381.7177" negate="false"/>
          <criterion test_ref="wft-475" comment="the version of gdi32.dll is less than 4.0.1381.7177" negate="false"/>
          <criterion test_ref="wft-476" comment="the version of winsrv.dll is less than 4.0.1381.7202" negate="false"/>
          <criterion test_ref="wft-477" comment="the version of win32k.sys is less than 4.0.1381.7207" negate="false"/>
          <criterion test_ref="wrt-502" comment="Patch Q328310 Installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL682" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Agent</product>
      </affected>
      <dates>
        <submitted date="2005-06-22-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2005-06-22-07:25">DRAFT</status_change>
        <modified date="2005-06-24-12:00" comment="added cve description">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </modified>
        <status_change date="2005-07-27-10:37">INTERIM</status_change>
        <status_change date="2005-08-18-07:37">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Agent allows remote attackers to spoof trusted Internet content and execute arbitrary code by disguising security prompts on a malicious Web page.</description>
      <reference source="CVE">CVE-2005-1214</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1106" comment="Windows 2000 (sp4 or earlier) is installed" negate="false"/>
          <criterion test_ref="wft-117" comment="the version of agentdpv.dll is less than 2.0.0.3423" negate="false"/>
          <criterion test_ref="wrt-64" comment="the patch kb890046 is installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL683" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2006-02-17-07:36">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-02-22-08:27">DRAFT</status_change>
        <status_change date="2006-03-09-12:19">INTERIM</status_change>
        <status_change date="2006-04-06-06:30">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the Web Client service (WebClnt.dll) for Microsoft Windows XP SP1 and SP2, and Server 2003 up to SP1, allows remote authenticated users or Guests to execute arbitrary code via crafted RPC requests, a different vulnerability than CVE-2005-1207.</description>
      <reference source="CVE">CVE-2006-0013</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-2" comment="Windows XP is installed" negate="false"/>
          <criterion test_ref="wrt-4" comment="Win2K/XP/2003 service pack 1 is installed" negate="false"/>
          <criterion test_ref="wrt-70" comment="64-Bit version of Windows is installed" negate="true"/>
          <criterion test_ref="wft-760" comment="the version of webclnt.dll is less than 5.1.2600.1790 (XP,SP1)" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL684" class="compliance">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Exchange Server 2003</product>
      </affected>
      <dates>
        <submitted date="2005-06-07-12:00">
          <contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
        </submitted>
        <status_change date="2005-06-08-03:24">DRAFT</status_change>
        <status_change date="2005-06-29-06:49">INTERIM</status_change>
        <status_change date="2005-07-27-10:37">ACCEPTED</status_change>
      </dates>
      <description>Review blocked recipient list</description>
      <reference source="MISC">1.2.7</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <notes>
        <note>Corresponds to item 1.2.7 in the Exchange 2003 Benchmark</note>
      </notes>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wat-6" comment="Review list of blocked recipients" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL685" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Microsoft Word for Windows 6.0 Converter</product>
      </affected>
      <dates>
        <submitted date="2005-01-05-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2005-01-12-12:00">DRAFT</status_change>
        <status_change date="2005-02-02-12:00">INTERIM</status_change>
        <modified date="2005-02-09-12:00" comment="modified cmp-35 - Corrected test comment">
          <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
        </modified>
        <modified date="2005-04-08-12:00" comment="modified wrt-35 - wrt-35 corrected literal string">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <status_change date="2005-04-27-12:07">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Word for Windows 6.0 Converter does not properly validate certain data lengths, which allows remote attackers to execute arbitrary code via a .wri, .rtf, and .doc file sent by email or malicious web site, aka "Table Conversion Vulnerability," a different vulnerability than CVE-2004-0901.</description>
      <reference source="CVE">CVE-2004-0571</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-35" comment="Windows XP 32 bit Service Pack 2" negate="false"/>
          <criterion test_ref="wft-300" comment="the version of mswrd6.wpc is less than 10.0.803.2" negate="false"/>
          <criterion test_ref="wrt-36" comment="the patch kb885835is installed (Hotfix key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-35" comment="Word for Windows 6.0 Converter is enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL686" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>TIP</product>
      </affected>
      <dates>
        <submitted date="2005-10-12-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-10-19-05:46">DRAFT</status_change>
        <status_change date="2005-11-16-08:02">INTERIM</status_change>
        <status_change date="2005-12-01-06:00">ACCEPTED</status_change>
      </dates>
      <description>Distributed Transaction Controller in Microsoft Windows allows remote servers to cause a denial of service (MSDTC service exception and exit) via an "unexpected protocol command during the reconnection request," which is not properly handled by the Transaction Internet Protocol (TIP) functionality.</description>
      <reference source="CVE">CVE-2005-1979</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wrt-4" comment="Win2K/XP/2003 service pack 1 is installed" negate="false"/>
          <criterion test_ref="cmp-608" comment="Either ole32.dll or rpcss.dll has a version less than 5.2.3790.2492" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL687" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Internet Explorer 5.01 Service Pack 4</product>
      </affected>
      <dates>
        <submitted date="2004-02-03-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <modified date="2004-03-04-12:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <status_change date="2004-03-09-12:00">INTERIM</status_change>
        <status_change date="2004-03-25-12:00">ACCEPTED</status_change>
        <modified date="2005-09-26-12:49" comment="modified wft-91 - Changed comment to match test">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-28-01:04">INTERIM</status_change>
        <status_change date="2005-10-19-05:47">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions via a javascript protocol URL in a sub-frame, which is added to the history list and executed in the top window's zone when the history.back (back) function is called, as demonstrated by BackToFramedJpu, aka the "Travel Log Cross Domain Vulnerability."</description>
      <reference source="CVE">CVE-2003-1026</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-54" comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false"/>
          <criterion test_ref="wft-91" comment="the version of mshtml.dll is less than 5.0.3813.800" negate="false"/>
          <criterion test_ref="wrt-141" comment="the patch q832894 is installed (Installed Components key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL688" class="compliance">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Exchange Server 2003</product>
      </affected>
      <dates>
        <submitted date="2005-06-07-12:00">
          <contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
        </submitted>
        <status_change date="2005-06-08-03:24">DRAFT</status_change>
        <status_change date="2005-06-29-06:49">INTERIM</status_change>
        <status_change date="2005-07-27-10:37">ACCEPTED</status_change>
      </dates>
      <description>Review the global accept and deny lists.</description>
      <reference source="MISC">1.2.1</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <notes>
        <note>Corresponds to item 1.2.1 in the Exchange 2003 Benchmark</note>
      </notes>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wat-2" comment="Review global accept list" negate="false"/>
          <criterion test_ref="wat-3" comment="Review global deny list" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL689" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows ME</windows:platform>
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Internet Explorer 5.5 Service Pack 2</product>
      </affected>
      <dates>
        <submitted date="2004-02-03-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <modified date="2004-03-04-12:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <status_change date="2004-03-09-12:00">INTERIM</status_change>
        <status_change date="2004-03-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions via a javascript protocol URL in a sub-frame, which is added to the history list and executed in the top window's zone when the history.back (back) function is called, as demonstrated by BackToFramedJpu, aka the "Travel Log Cross Domain Vulnerability."</description>
      <reference source="CVE">CVE-2003-1026</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-53" comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false"/>
          <criterion test_ref="wft-92" comment="the version of mshtml.dll is less than 5.50.4937.800" negate="false"/>
          <criterion test_ref="wrt-141" comment="the patch q832894 is installed (Installed Components key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL690" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Internet Explorer 5.5</product>
      </affected>
      <dates>
        <submitted date="2004-01-27-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2004-03-09-12:00">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 5.01 through 6.0 allows remote attackers to identify the path to the Temporary Internet Files folder and obtain user information such as cookies via certain uses of the OBJECT tag, which are not subjected to the proper security checks, aka "Temporary Internet Files folders Name Reading."</description>
      <reference source="CVE">CVE-2002-1188</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-271" comment="Internet Explorer 5.5 Installed" negate="false"/>
          <criterion test_ref="wft-262" comment="the version of mshtml.dll is less than 5.50.4922.900" negate="false"/>
          <criterion test_ref="wrt-206" comment="the patch q328970 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-207" comment="the patch q324929 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-208" comment="the patch q810847 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-209" comment="the patch q813489 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-210" comment="the patch q818529 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-211" comment="the patch q822925 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-212" comment="the patch q828750 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-19" comment="the patch q824145 is installed (Installed Components key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL695" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 95</windows:platform>
        <windows:platform>Microsoft Windows 98</windows:platform>
        <windows:platform>Microsoft Windows ME</windows:platform>
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Excel 2002</product>
      </affected>
      <dates>
        <submitted date="2003-11-19-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <status_change date="2004-03-09-12:00">INTERIM</status_change>
        <status_change date="2004-03-25-12:00">ACCEPTED</status_change>
        <modified date="2005-04-11-12:00" comment="modified wft-16 - wft-16 corrected literal string">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <status_change date="2005-04-11-08:48">INTERIM</status_change>
        <status_change date="2005-04-27-12:07">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Excel 97, 2000, and 2002 allows remote attackers to execute arbitrary code via a spreadsheet with a malicious XLM (Excel 4) macro that bypasses the macro security model.</description>
      <reference source="CVE">CVE-2003-0821</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-138" comment="Excel 2002 is installed" negate="false"/>
          <criterion test_ref="wft-16" comment="the version of excel.exe is less than 10.0.5815.0" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL697" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Microsoft Internet Explorer 6 Service Pack 1</product>
      </affected>
      <dates>
        <submitted date="2005-08-23-04:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2005-08-25-10:05">DRAFT</status_change>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
        <modified date="2005-12-26-09:40" comment="Removed reference to patch kb896727 from criteria.">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </modified>
        <status_change date="2006-01-12-08:59">ACCEPTED</status_change>
      </dates>
      <description>Unknown vulnerability in Internet Explorer 5.0, 5.5, and 6.0 allows remote attackers to obtain information and possibly execute code when browsing from a web site to a web folder view using WebDAV, aka "Web Folder Behaviors Cross-Domain Vulnerability".</description>
      <reference source="CVE">CVE-2005-1989</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-50" comment="Internet Explorer 6 Service Pack 1 is installed" negate="false"/>
          <criterion test_ref="cmp-317" comment="the version of mshtml.dll is less than 6.0.2800.1515 or 6.0.2800.1516 " negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL698" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2006-01-11-12:56">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-01-12-09:21">DRAFT</status_change>
        <status_change date="2006-02-01-09:08">INTERIM</status_change>
        <status_change date="2006-02-22-08:27">ACCEPTED</status_change>
      </dates>
      <description>Heap-based buffer overflow in T2EMBED.DLL in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 up to SP1, Windows 98, and Windows ME allows remote attackers to execute arbitrary code via an e-mail message or web page with a crafted Embedded Open Type (EOT) web font that triggers the overflow during decompression.</description>
      <reference source="CVE">CVE-2006-0010</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-2" comment="Windows XP is installed" negate="false"/>
          <criterion test_ref="wrt-250" comment="Win2K/XP/2003 service pack 2 is installed" negate="false"/>
          <criterion test_ref="cmp-709" comment="Fontsub.dll &lt; 5.1.2600.2777 or T2embed.dll &lt;5.1.2600.2777 (WinXP,SP2)" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL699" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>Microsoft FrontPage Server Extensions 2000</product>
      </affected>
      <dates>
        <submitted date="2003-03-04-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <modified date="2003-03-05-12:00" comment="Changed the definition to test for fp30reg.dll and fp4areg.dll instead of fp4awel.dll.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <status_change date="2004-03-09-12:00">INTERIM</status_change>
        <status_change date="2004-03-25-12:00">ACCEPTED</status_change>
        <modified date="2005-09-26-10:50" comment="modified wft-114 - Changed comment to match test">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <modified date="2005-09-27-01:22" comment="modified wft-31 - Changed comment to match test">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-28-01:04">INTERIM</status_change>
        <status_change date="2005-10-19-05:47">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the debug functionality in fp30reg.dll of Microsoft FrontPage Server Extensions (FPSE) 2000 and 2002 allows remote attackers to execute arbitrary code via a crafted chunked encoded request.</description>
      <reference source="CVE">CVE-2003-0822</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" negate="false"/>
          <criterion test_ref="cmp-112" comment="a vulnerable version of fp30reg.dll or fp4areg.dll exists" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-33" comment="FrontPage Server Extensions 2000 are enabled (WinNT)" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL701" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2005-11-09-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-11-10-07:06">DRAFT</status_change>
        <status_change date="2005-12-01-06:00">INTERIM</status_change>
        <status_change date="2005-12-16-01:04">ACCEPTED</status_change>
      </dates>
      <description>Multiple integer overflows in the Graphics Rendering Engine (GDI32.DLL) in Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allow remote attackers to execute arbitrary code via crafted Windows Metafile (WMF) and Enhanced Metafile (EMF) format images that lead to heap-based buffer overflows, as demonstrated using MRBP16::bCheckRecord.</description>
      <reference source="CVE">CVE-2005-2123</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-647" comment="64-bit XP or Server 2003 is installed" negate="false"/>
          <criterion test_ref="wrt-4" comment="Win2K/XP/2003 service pack 1 is installed" negate="false"/>
          <criterion test_ref="wft-703" comment="the version of Gdi32.dll is less than 5.2.3790.2542" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL702" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <solaris:platform>Sun Solaris 10</solaris:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2006-01-12-11:25">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-01-25-07:30">DRAFT</status_change>
        <status_change date="2006-02-22-08:27">INTERIM</status_change>
        <status_change date="2006-03-09-12:19">ACCEPTED</status_change>
      </dates>
      <description>Unspecified vulnerability in Sun Solaris 9 and 10 for the x86 platform allows local users to gain privileges or cause a denial of service (panic) via unspecified vectors, possibly involving functions from the mm driver.</description>
      <reference source="CVE">CVE-2006-0190</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-713" comment="Solaris 9 (x86) meets Sun Alert ID 102066 criteria." negate="false"/>
          <criterion test_ref="cmp-714" comment="Solaris 10 (x86) meets Sun Alert ID 102066 and 102108 criteria." negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL704" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Windows Internet Naming Service (WINS)</product>
      </affected>
      <dates>
        <submitted date="2004-02-12-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <status_change date="2004-03-09-12:00">INTERIM</status_change>
        <status_change date="2004-03-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>The Windows Internet Naming Service (WINS) for Microsoft Windows Server 2003, and possibly Windows NT and Server 2000, does not properly validate the length of certain packets, which allows attackers to cause a denial of service and possibly execute arbitrary code.</description>
      <reference source="CVE">CVE-2003-0825</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-60" comment="Windows 2000 Server is installed" negate="false"/>
          <criterion test_ref="wft-98" comment="the version of wins.exe is less than 5.0.2195.6870" negate="false"/>
          <criterion test_ref="wrt-97" comment="the patch kb830352 is installed (Hotfix key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-98" comment="the wins service is enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL708" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2005-10-12-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-10-19-05:46">DRAFT</status_change>
        <status_change date="2005-11-16-08:02">INTERIM</status_change>
        <status_change date="2005-12-01-06:00">ACCEPTED</status_change>
      </dates>
      <description>Windows Shell for Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 allows remote attackers to execute arbitrary commands via a shortcut (.lnk) file with long font properties that lead to a buffer overflow in the Client/Server Runtime Server Subsystem (CSRSS), a different vulnerability than CVE-2005-2118.</description>
      <reference source="CVE">CVE-2005-2122</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1112" comment="Windows XP 64-bit" negate="false"/>
          <criterion test_ref="wrt-4" comment="Win2K/XP/2003 service pack 1 is installed" negate="false"/>
          <criterion test_ref="wft-686" comment="shell32.dll is less than 6.0.3790.2521" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL710" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Internet Explorer 6</product>
      </affected>
      <dates>
        <submitted date="2005-03-17-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2005-03-23-12:00">DRAFT</status_change>
        <status_change date="2005-04-13-12:00">INTERIM</status_change>
        <modified date="2005-04-21-12:00" comment="modified wrt-159 - unchecked value">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </modified>
        <status_change date="2005-05-11-05:41">ACCEPTED</status_change>
        <modified date="2005-12-26-09:40" comment="Removed test to check kb867282.">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </modified>
        <status_change date="2006-01-12-08:59">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 5.01, 5.5, and 6 does not properly validate buffers when handling certain DHTML methods including the createControlRange Javascript function, which allows remote attackers to execute arbitrary code, aka the "DHTML Method Heap Memory Corruption Vulnerability."</description>
      <reference source="CVE">CVE-2005-0055</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-200" comment="Internet Explorer 6.0 Installed XP SP2" negate="false"/>
          <criterion test_ref="wft-500" comment="the version of mshtml.dll is less than 6.0.2900.2604" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL711" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>ImageMagick</product>
      </affected>
      <dates>
        <submitted date="2005-06-28-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2005-06-29-06:49">DRAFT</status_change>
        <status_change date="2005-07-27-10:37">INTERIM</status_change>
        <status_change date="2005-08-18-07:37">ACCEPTED</status_change>
      </dates>
      <description>Heap-based buffer overflow in the ReadPNMImage function in pnm.c for ImageMagick 6.2.1 and earlier allows remote attackers to cause a denial of service (application crash) via a PNM file with a small colors value.</description>
      <reference source="CVE">CVE-2005-1275</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="rvt-16" comment="ImageMagick RPM earlier than 0:5.5.6-14" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL712" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>Windows Animated Cursor</product>
      </affected>
      <dates>
        <submitted date="2005-01-14-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2005-01-20-02:31">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>The Windows Animated Cursor (ANI) capability in Windows NT, Windows 2000 through SP4, Windows XP through SP1, and Windows 2003 allow remote attackers to cause a denial of service via (1) the frame number set to zero, which causes an invalid memory address to be used and leads to a kernel crash, or (2) the rate number set to zero, which leads to resource exhaustion and hang.</description>
      <reference source="CVE">CVE-2004-1305</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-44" comment="Windows NT Server 4.0 is installed" negate="false"/>
          <criterion test_ref="wft-351" comment="the version of user32.dll is less than 4.0.1381.7342" negate="false"/>
          <criterion test_ref="wrt-68" comment="the patch kb891711 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL713" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Hyperlink Object Library</product>
      </affected>
      <dates>
        <submitted date="2005-02-10-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2005-02-11-09:34">DRAFT</status_change>
        <status_change date="2005-03-02-09:01">INTERIM</status_change>
        <status_change date="2005-03-23-08:09">ACCEPTED</status_change>
      </dates>
      <description>The Hyperlink Object Library for Windows 98, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary code via a crafted link that triggers an "unchecked buffer" in the library, possibly due to a buffer overflow.</description>
      <reference source="CVE">CVE-2005-0057</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
          <criterion test_ref="wft-369" comment="the version of hlink.dll is less than 5.2.3790.227" negate="false"/>
          <criterion test_ref="wrt-78" comment="the patch kb888113 is installed (Hotfix key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL714" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2006-01-11-12:56">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-01-12-09:18">DRAFT</status_change>
        <status_change date="2006-02-01-09:08">INTERIM</status_change>
        <status_change date="2006-02-22-08:27">ACCEPTED</status_change>
      </dates>
      <description>Heap-based buffer overflow in T2EMBED.DLL in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 up to SP1, Windows 98, and Windows ME allows remote attackers to execute arbitrary code via an e-mail message or web page with a crafted Embedded Open Type (EOT) web font that triggers the overflow during decompression.</description>
      <reference source="CVE">CVE-2006-0010</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-212" comment="Windows 2000 Service Pack 4 (or later) is installed" negate="false"/>
          <criterion test_ref="cmp-707" comment="Fontsub.dll &lt; 5.0.2195.7071 or T2embed.dll &lt;5.0.2195.7073 (Win2k,SP4)" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL716" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2006-02-17-07:36">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-02-22-08:27">DRAFT</status_change>
        <status_change date="2006-03-09-12:19">INTERIM</status_change>
        <status_change date="2006-04-06-06:30">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the Web Client service (WebClnt.dll) for Microsoft Windows XP SP1 and SP2, and Server 2003 up to SP1, allows remote authenticated users or Guests to execute arbitrary code via crafted RPC requests, a different vulnerability than CVE-2005-1207.</description>
      <reference source="CVE">CVE-2006-0013</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-2" comment="Windows XP is installed" negate="false"/>
          <criterion test_ref="wrt-4" comment="Win2K/XP/2003 service pack 1 is installed" negate="false"/>
          <criterion test_ref="wrt-70" comment="64-Bit version of Windows is installed" negate="false"/>
          <criterion test_ref="wft-762" comment="the version of webclnt.dll is less than 5.2.3790.2591 (64-bit,SP1)" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL717" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>gftp</product>
      </affected>
      <dates>
        <submitted date="2005-06-20-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2005-06-22-12:38">DRAFT</status_change>
        <status_change date="2005-07-27-10:37">INTERIM</status_change>
        <status_change date="2005-08-18-07:37">ACCEPTED</status_change>
        <modified date="2006-01-25-10:22" comment="modified upt-62 - Changed DATA operation to OR (to test for any exec bit set, not all).  Fixed typo in comment.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2006-01-25-07:27">INTERIM</status_change>
        <status_change date="2006-02-22-08:27">ACCEPTED</status_change>
      </dates>
      <description>Directory traversal vulnerability in gftp before 2.0.18 for GTK+ allows remote malicious FTP servers to read arbitrary files via .. (dot dot) sequences in filenames returned from a LIST command.</description>
      <reference source="CVE">CVE-2005-0372</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rvt-6" comment="gftp rpm is earlier than 1:2.0.14-4" negate="false"/>
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="upt-62" comment="gftp is executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL721" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Web Client Service</product>
      </affected>
      <dates>
        <submitted date="2005-07-15-12:00">
          <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
        </submitted>
        <status_change date="2005-07-27-10:36">DRAFT</status_change>
        <status_change date="2005-08-18-07:37">INTERIM</status_change>
        <status_change date="2005-09-21-01:33">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the Web Client service in Microsoft Windows XP and Windows Server 2003 allows remote authenticated users to execute arbitrary code via a crafted WebDAV request containing special parameters.</description>
      <reference source="CVE">CVE-2005-1207</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="cmp-23" comment="32-bit version of Windows or 64-bit (itanium architecture) version of Windows is installed" negate="false"/>
          <criterion test_ref="wrt-3" comment="a Win2K/XP/2003 service pack is installed" negate="true"/>
          <criterion test_ref="wft-161" comment="the version of webclnt.dll is less than 5.2.3790.316" negate="false"/>
          <criterion test_ref="wrt-124" comment="the patch kb896426 is installed (Hotfix key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL722" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Internet Explorer</product>
      </affected>
      <dates>
        <submitted date="2005-11-11-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-12-12-10:00">DRAFT</status_change>
        <modified date="2005-12-14-12:00" comment="Updated with newly available information.">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </modified>
        <status_change date="2006-01-04-08:04">INTERIM</status_change>
        <status_change date="2006-01-25-07:30">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Internet Explorer 6 SP2 6.0.2900.2180 and 6.0.2800.1106, and earlier versions, allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a Javascript BODY onload event that calls the window function, aka "Mismatched Document Object Model Objects Memory Corruption Vulnerability."</description>
      <reference source="CVE">CVE-2005-1790</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-613" comment="Win2K or XP,SP1 is installed" negate="false"/>
          <criterion test_ref="wrt-50" comment="Internet Explorer 6 Service Pack 1 is installed" negate="false"/>
          <criterion test_ref="wft-705" comment="the version of mshtml.dll is less than 6.0.2800.1528" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL727" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2006-02-17-07:36">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-02-22-08:27">DRAFT</status_change>
        <status_change date="2006-03-09-12:19">INTERIM</status_change>
        <status_change date="2006-04-06-06:30">ACCEPTED</status_change>
      </dates>
      <description>The ShellAbout API call in Korean Input Method Editor (IME) in Korean versions of Microsoft Windows XP SP1 and SP2, Windows Server 2003 up to SP1, and Office 2003, allows local users to gain privileges by launching the "shell about dialog box" and clicking the "End-User License Agreement" link, which executes Notepad with the privileges of the program that displays the about box.</description>
      <reference source="CVE">CVE-2006-0008</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wft-764" comment="the version of Imekr70.ime is less than 7.0.8002.0 (Office 2003 and Accessories)" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL729" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 4</redhat:platform>
        <product>mozilla</product>
      </affected>
      <dates>
        <submitted date="2005-08-15-04:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2005-08-19-10:05">DRAFT</status_change>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 does not properly verify the associated types of DOM node names within the context of their namespaces, which allows remote attackers to modify certain tag properties, possibly leading to execution of arbitrary script or code, as demonstrated using an XHTML document with IMG tags with custom properties ("XHTML node spoofing").</description>
      <reference source="CVE">CVE-2005-2269</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-1" comment="Red Hat Enterprise 4 is installed" negate="false"/>
          <criterion test_ref="rvt-32" comment="mozilla RPM is earlier than 37:1.7.10-1.4.1" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="upt-859" comment="/usr/bin/mozilla is executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL733" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Microsoft Internet Explorer 6</product>
        <product>Microsoft Internet Explorer 6 Service Pack 1</product>
      </affected>
      <dates>
        <submitted date="2003-12-18-05:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <modified date="2004-01-21-05:00" comment="Removed the test for Windows XP.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 6 patch.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <modified date="2004-03-04-05:00" comment="Removed the IE 6 SP 1 part of this definition as the SP 1 part is defined in a different OVAL.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <status_change date="2004-03-09-05:00">INTERIM</status_change>
        <status_change date="2004-03-25-05:00">ACCEPTED</status_change>
        <modified date="2005-09-20-04:00" comment="modified wrt-18 - Changed value element to include pattern match">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-21-01:27">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 6 SP1 and earlier allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by calling the window.moveBy method, aka HijackClick, a different vulnerability than CVE-2003-1027.</description>
      <reference source="CVE">CVE-2003-0823</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-18" comment="Internet Explorer 6 is installed" negate="false"/>
          <criterion test_ref="wft-26" comment="the version of mshtml.dll is less than 6.0.2734.1600" negate="false"/>
          <criterion test_ref="wrt-19" comment="the patch q824145 is installed (Installed Components key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL735" class="vulnerability">
      <affected family="hp-ux">
        <hpux:platform>HP-UX 11</hpux:platform>
        <product>Apache</product>
      </affected>
      <dates>
        <submitted date="2005-11-30-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-12-20-11:03">DRAFT</status_change>
        <status_change date="2006-01-04-08:04">INTERIM</status_change>
        <status_change date="2006-01-25-07:30">ACCEPTED</status_change>
      </dates>
      <description>Integer overflow in pcre_compile.c in Perl Compatible Regular Expressions (PCRE) before 6.2, as used in multiple products such as Python, Ethereal, and PHP, allows attackers to execute arbitrary code via quantifier values in regular expressions, which leads to a heap-based buffer overflow.</description>
      <reference source="CVE">CVE-2005-2491</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-684" comment="700 Series or 800 Series OS Release 11.00, 11.11, or 11.23" negate="false"/>
          <criterion test_ref="hst-29" comment="hpuxwsAPACHE is installed" negate="false"/>
          <criterion test_ref="hst-30" comment="hpuxwsAPACHE has a version greater than or equal (A|B).2.0.55.0" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL742" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>mozilla</product>
      </affected>
      <dates>
        <submitted date="2005-08-15-04:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2005-08-19-10:05">DRAFT</status_change>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>The browser user interface in Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 and 7.2 does not properly distinguish between user-generated events and untrusted synthetic events, which makes it easier for remote attackers to perform dangerous actions that normally could only be performed manually by the user.</description>
      <reference source="CVE">CVE-2005-2260</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-216" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="rvt-31" comment="mozilla RPM is earlier than 37:1.7.10-1.1.3.1" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="upt-859" comment="/usr/bin/mozilla is executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL743" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft FrontPage Server Extensions 2000</product>
      </affected>
      <dates>
        <submitted date="2003-03-04-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <modified date="2003-03-05-12:00" comment="Changed the definition to test for fp30reg.dll and fp4areg.dll instead of fp4awel.dll.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <status_change date="2004-03-09-12:00">INTERIM</status_change>
        <status_change date="2004-03-25-12:00">ACCEPTED</status_change>
        <modified date="2005-09-26-10:50" comment="modified wft-114 - Changed comment to match test">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <modified date="2005-09-27-01:22" comment="modified wft-31 - Changed comment to match test">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-28-01:04">INTERIM</status_change>
        <status_change date="2005-10-19-05:47">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the debug functionality in fp30reg.dll of Microsoft FrontPage Server Extensions (FPSE) 2000 and 2002 allows remote attackers to execute arbitrary code via a crafted chunked encoded request.</description>
      <reference source="CVE">CVE-2003-0822</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-65" comment="Windows 2000 (sp3 or earlier) is installed" negate="false"/>
          <criterion test_ref="cmp-112" comment="a vulnerable version of fp30reg.dll or fp4areg.dll exists" negate="false"/>
          <criterion test_ref="wrt-88" comment="the patch q810217 is installed (Hotfix key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-31" comment="FrontPage Server Extensions 2000 are enabled (2K, XP)" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL744" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>Gaim</product>
      </affected>
      <dates>
        <submitted date="2005-07-11-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2005-07-27-10:36">DRAFT</status_change>
        <status_change date="2005-08-18-07:37">INTERIM</status_change>
        <status_change date="2005-09-21-01:33">ACCEPTED</status_change>
      </dates>
      <description>Gaim before 1.3.1 allows remote attackers to cause a denial of service (application crash) via a Yahoo! message with non-ASCII characters in a file name.</description>
      <reference source="CVE">CVE-2005-1269</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="rvt-21" comment="gaim RPM earlier than 1:1.3.1-0.el3" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="upt-56" comment="/usr/bin/gaim is executable by any user" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL745" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Microsoft Internet Explorer 6</product>
      </affected>
      <dates>
        <submitted date="2004-02-03-05:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <modified date="2004-03-04-05:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <status_change date="2004-03-09-05:00">INTERIM</status_change>
        <status_change date="2004-03-25-05:00">ACCEPTED</status_change>
        <modified date="2005-09-20-04:00" comment="modified wrt-18 - Changed value element to include pattern match">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-21-01:27">INTERIM</status_change>
        <modified date="2005-09-26-12:51" comment="modified wft-93 - Changed comment to match test">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions via a javascript protocol URL in a sub-frame, which is added to the history list and executed in the top window's zone when the history.back (back) function is called, as demonstrated by BackToFramedJpu, aka the "Travel Log Cross Domain Vulnerability."</description>
      <reference source="CVE">CVE-2003-1026</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-18" comment="Internet Explorer 6 is installed" negate="false"/>
          <criterion test_ref="wft-93" comment="the version of mshtml.dll is less than 6.0.2737.800" negate="false"/>
          <criterion test_ref="wrt-141" comment="the patch q832894 is installed (Installed Components key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL749" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>bzip2</product>
      </affected>
      <dates>
        <submitted date="2005-07-11-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2005-07-27-10:36">DRAFT</status_change>
        <status_change date="2005-08-18-07:37">INTERIM</status_change>
        <status_change date="2005-09-21-01:33">ACCEPTED</status_change>
      </dates>
      <description>bzip2 allows remote attackers to cause a denial of service (hard drive consumption) via a crafted bzip2 file that causes an infinite loop (a.k.a "decompression bomb").</description>
      <reference source="CVE">CVE-2005-1260</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="rvt-20" comment="bzip2 RPM earlier than 0:1.0.2-11.EL3.4" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="upt-55" comment="/usr/bin/bzip2 is executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL751" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 98</windows:platform>
        <windows:platform>Microsoft Windows ME</windows:platform>
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Microsoft Data Access Compnents 2.7</product>
      </affected>
      <dates>
        <submitted date="2004-01-13-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2004-03-09-12:00">INTERIM</status_change>
        <status_change date="2004-03-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in a component of Microsoft Data Access Components (MDAC) 2.5 through 2.8 allows remote attackers to execute arbitrary code via a malformed UDP response to a broadcast request.</description>
      <reference source="CVE">CVE-2003-0903</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-100" comment="MDAC 2.7 is installed and a vulnerable version of sqlsrv32.dll and odbcbcp.dll exists" negate="false"/>
          <criterion test_ref="wrt-110" comment="the patch q832483 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL759" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 4</redhat:platform>
        <product>mozilla</product>
      </affected>
      <dates>
        <submitted date="2005-08-15-04:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2005-08-19-10:05">DRAFT</status_change>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>A regression error in Firefox 1.0.3 and Mozilla 1.7.7 allows remote attackers to inject arbitrary Javascript from one page into the frameset of another site, aka the frame injection spoofing vulnerability, a re-introduction of a vulnerability that was originally identified and addressed by CVE-2004-0718.</description>
      <reference source="CVE">CVE-2005-1937</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-1" comment="Red Hat Enterprise 4 is installed" negate="false"/>
          <criterion test_ref="rvt-32" comment="mozilla RPM is earlier than 37:1.7.10-1.4.1" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="upt-859" comment="/usr/bin/mozilla is executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL760" class="vulnerability">
      <affected family="hp-ux">
        <hpux:platform>HP-UX 11</hpux:platform>
        <product>Apache</product>
      </affected>
      <dates>
        <submitted date="2005-11-30-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-12-20-11:03">DRAFT</status_change>
        <status_change date="2006-01-04-08:04">INTERIM</status_change>
        <status_change date="2006-01-25-07:30">ACCEPTED</status_change>
      </dates>
      <description>The byte-range filter in Apache 2.0 before 2.0.54 allows remote attackers to cause a denial of service (memory consumption) via an HTTP header with a large Range field.</description>
      <reference source="CVE">CVE-2005-2728</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-684" comment="700 Series or 800 Series OS Release 11.00, 11.11, or 11.23" negate="false"/>
          <criterion test_ref="hst-29" comment="hpuxwsAPACHE is installed" negate="false"/>
          <criterion test_ref="hst-30" comment="hpuxwsAPACHE has a version greater than or equal (A|B).2.0.55.0" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL762" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft SharePoint Team Services</product>
      </affected>
      <dates>
        <submitted date="2003-12-09-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <modified date="2004-01-14-12:00" comment="Changed the definition to look at the file shtml.dll instead of fp5awel.dll.  It was determined that this is where the vulnerability (a buffer overflow) actually existed.  Also added the configuration test saying you are vulnerable if the SmartHTML interpreter is enabled.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <status_change date="2004-03-09-12:00">INTERIM</status_change>
        <status_change date="2004-03-25-12:00">ACCEPTED</status_change>
        <modified date="2004-09-14-09:53" comment="XP SP2 added">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2004-09-15-12:00">INTERIM</status_change>
      </dates>
      <description>Unknown vulnerability in the SmartHTML interpreter (shtml.dll) in Microsoft FrontPage Server Extensions 2000 and 2002, and Microsoft SharePoint Team Services 2002, allows remote attackers to cause a denial of service (response failure) via a certain request.</description>
      <reference source="CVE">CVE-2003-0824</reference>
      <status>INTERIM</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-78" comment="Windows 2000, XP, or 2003 is installed" negate="false"/>
          <criterion test_ref="ukn-13" comment="a vulnerable version of shtml.dll exists (FPSE 2002 or SPTS 2003)" negate="false"/>
          <criterion test_ref="wrt-29" comment="Win2K/XP/2003 service pack 2 (or later) is installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-34" comment="SharePoint Team Services are enabled (2K, XP, 2003)" negate="false"/>
          <criterion test_ref="wmt-2" comment="SmartHTML interpreter is enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL763" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Office</product>
      </affected>
      <dates>
        <submitted date="2006-03-15-10:53">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-03-15-07:17">DRAFT</status_change>
        <status_change date="2006-04-06-06:31">INTERIM</status_change>
        <status_change date="2006-05-03-10:06">ACCEPTED</status_change>
      </dates>
      <description>Stack-based buffer overflow in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-complicit attackers to execute arbitrary code via an Excel file with a malformed record with a modified length value, which leads to memory corruption.</description>
      <reference source="CVE">CVE-2006-0031</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-649" comment="Excel 2002 is installed" negate="false"/>
          <criterion test_ref="wft-771" comment="the version of excel.exe is less than 10.0.6789.0" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL766" class="vulnerability">
      <affected family="hp-ux">
        <hpux:platform>HP-UX 11</hpux:platform>
        <product>remshd</product>
      </affected>
      <dates>
        <submitted date="2005-11-30-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-12-20-11:03">DRAFT</status_change>
        <status_change date="2006-01-04-08:04">INTERIM</status_change>
        <status_change date="2006-01-25-07:30">ACCEPTED</status_change>
      </dates>
      <description>Unknown vulnerability in remshd daemon in HP-UX B.11.00, B.11.11, and B.11.23 while running in "Trusted Mode" allows remote attackers to gain unauthorized system access via unknown attack vectors.</description>
      <reference source="CVE">CVE-2005-3565</reference>
      <status>ACCEPTED</status>
      <version>5</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-619" comment="700 Series or 800 Series OS Release 11.00" negate="false"/>
          <criterion test_ref="cmp-666" comment="InternetSrvcs.INETSVCS-RUN or InternetSrvcs.INET-ENG-A-MAN (B.11.00) is installed" negate="false"/>
          <criterion test_ref="hpt-12" comment="Patch PHNE_33790 or later is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL767" class="vulnerability">
      <affected family="hp-ux">
        <hpux:platform>HP-UX 10</hpux:platform>
        <product>ftpd</product>
      </affected>
      <dates>
        <submitted date="2005-11-30-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-12-20-11:03">DRAFT</status_change>
        <status_change date="2006-01-04-08:04">INTERIM</status_change>
        <status_change date="2006-01-25-07:30">ACCEPTED</status_change>
      </dates>
      <description>The FTP server in HP-UX 10.20, B.11.00, and B.11.11, allows remote attackers to list arbitrary directories as root by running the LIST command before logging in.</description>
      <reference source="CVE">CVE-2005-3296</reference>
      <status>ACCEPTED</status>
      <version>5</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-669" comment="InternetSrvcs.INETSVCS-RUN or InternetSrvcs.INET-ENG-A-MAN (B.10.20) is installed" negate="false"/>
          <criterion test_ref="cmp-670" comment="700 Series or 800 Series OS Release 10.01 or 10.10" negate="false"/>
          <criterion test_ref="hpt-8" comment="Patch PHNE_23947 or later is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL768" class="compliance">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Exchange Server 2003</product>
      </affected>
      <dates>
        <submitted date="2005-06-08-12:00">
          <contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
        </submitted>
        <status_change date="2005-06-08-03:24">DRAFT</status_change>
        <status_change date="2005-06-29-06:49">INTERIM</status_change>
        <status_change date="2005-07-27-10:37">ACCEPTED</status_change>
      </dates>
      <description>Review whether anonymous HTTP access is allowed</description>
      <reference source="MISC">2.1.2</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <notes>
        <note>Corresponds to item 2.1.2 in the Exchange 2003 Benchmark</note>
      </notes>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wwt-2" comment="Review whether anonymous HTTP access is allowed through IIS" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL769" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Color Management Module</product>
      </affected>
      <dates>
        <submitted date="2005-08-02-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2005-08-03-11:30">DRAFT</status_change>
        <status_change date="2005-08-18-07:37">INTERIM</status_change>
        <status_change date="2005-09-21-01:33">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the Microsoft Color Management Module for Windows allows remote attackers to execute arbitrary code via an image with crafted ICC profile format tags.</description>
      <reference source="CVE">CVE-2005-1219</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-330" comment="Windows Server 2003 with Service Pack 1" negate="false"/>
          <criterion test_ref="wft-573" comment="the version of mscms.dll is less than 5.2.3790.2476" negate="false"/>
          <criterion test_ref="wrt-128" comment="the patch KB901214 is installed " negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL770" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Microsoft Internet Explorer 6 Service Pack 1</product>
      </affected>
      <dates>
        <submitted date="2005-06-22-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2005-06-22-09:24">DRAFT</status_change>
        <modified date="2005-06-24-12:00" comment="added description">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </modified>
        <status_change date="2005-07-27-10:37">INTERIM</status_change>
        <status_change date="2005-08-18-07:37">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the PNG image rendering component of Microsoft Internet Explorer allows remote attackers to execute arbitrary code via a crafted PNG file.</description>
      <reference source="CVE">CVE-2005-1211</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-50" comment="Internet Explorer 6 Service Pack 1 is installed" negate="false"/>
          <criterion test_ref="cmp-158" comment="the version of mshtml.dll is less than 6.0.2800.1505 or 6.0.2800.1506" negate="false"/>
          <criterion test_ref="wrt-62" comment="the patch kb883939 is installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-59" comment="PNG image rendering enabled in Internet Explorer" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL772" class="vulnerability">
      <affected family="hp-ux">
        <hpux:platform>HP-UX 11</hpux:platform>
        <product>Apache</product>
      </affected>
      <dates>
        <submitted date="2006-03-18-07:24">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-03-22-11:10">DRAFT</status_change>
        <status_change date="2006-04-06-06:31">INTERIM</status_change>
        <status_change date="2006-05-03-10:06">ACCEPTED</status_change>
      </dates>
      <description>'A security flaw in some versions of the HP-UX usermod command can result in recursively changing the ownership of all directories and files under a user\'s home directory.  Specifically, executing # usermod -d &lt;old home dir> -u &lt;new gid> -m &lt;username> or # usermod -d &lt;old home dir> -u &lt;new or old gid> -m &lt;username> incorrectly changes ownership recursively to &lt;username>.  If the home directory is \'/\', this action will render the system inoperable.'</description>
      <reference source="MISC">http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00614838</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-619" comment="700 Series or 800 Series OS Release 11.00" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL773" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>mozilla</product>
      </affected>
      <dates>
        <submitted date="2005-08-15-04:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2005-08-19-10:05">DRAFT</status_change>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Firefox before 1.0.5 and Mozilla before 1.7.9 allows a child frame to call top.focus and other methods in a parent frame, even when the parent is in a different domain, which violates the same origin policy and allows remote attackers to steal sensitive information such as cookies and passwords from web sites whose child frames do not verify that they are in the same domain as their parents.</description>
      <reference source="CVE">CVE-2005-2266</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-216" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="rvt-31" comment="mozilla RPM is earlier than 37:1.7.10-1.1.3.1" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="upt-859" comment="/usr/bin/mozilla is executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL774" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows ME</windows:platform>
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Microsoft Internet Explorer 6 Service Pack 1</product>
      </affected>
      <dates>
        <submitted date="2004-02-03-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <modified date="2004-03-04-12:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <status_change date="2004-03-09-12:00">INTERIM</status_change>
        <status_change date="2004-03-25-12:00">ACCEPTED</status_change>
        <modified date="2005-09-26-12:52" comment="modified wft-94 - Changed comment to match test">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-28-01:04">INTERIM</status_change>
        <status_change date="2005-10-19-05:47">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions via a javascript protocol URL in a sub-frame, which is added to the history list and executed in the top window's zone when the history.back (back) function is called, as demonstrated by BackToFramedJpu, aka the "Travel Log Cross Domain Vulnerability."</description>
      <reference source="CVE">CVE-2003-1026</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-50" comment="Internet Explorer 6 Service Pack 1 is installed" negate="false"/>
          <criterion test_ref="wft-94" comment="the version of mshtml.dll is less than 6.0.2800.1400" negate="false"/>
          <criterion test_ref="wrt-141" comment="the patch q832894 is installed (Installed Components key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL775" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 98</windows:platform>
        <windows:platform>Microsoft Windows ME</windows:platform>
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Data Access Compnents 2.8</product>
      </affected>
      <dates>
        <submitted date="2004-01-13-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2004-03-09-12:00">INTERIM</status_change>
        <status_change date="2004-03-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in a component of Microsoft Data Access Components (MDAC) 2.5 through 2.8 allows remote attackers to execute arbitrary code via a malformed UDP response to a broadcast request.</description>
      <reference source="CVE">CVE-2003-0903</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-104" comment="MDAC 2.8 (RTM) is installed" negate="false"/>
          <criterion test_ref="wft-44" comment="the version of odbcbcp.dll is less than 2000.85.1025.0" negate="false"/>
          <criterion test_ref="wft-39" comment="the version of sqlsrv32.dll is less than 2000.85.1025.0" negate="false"/>
          <criterion test_ref="cmp-103" comment="the patch q832483 is not installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL776" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Internet Explorer 5.01 Service Pack 4</product>
      </affected>
      <dates>
        <submitted date="2005-06-22-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2005-06-22-12:38">DRAFT</status_change>
        <status_change date="2005-07-27-10:37">INTERIM</status_change>
        <status_change date="2005-08-18-07:37">ACCEPTED</status_change>
      </dates>
      <description>The legacy &lt;script> data-island capability for XML in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to read arbitrary XML files, and portions of other files, via a URL whose "src" attribute redirects to a local file.</description>
      <reference source="CVE">CVE-2002-0648</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-54" comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false"/>
          <criterion test_ref="wft-116" comment="the version of mshtml.dll is less than 5.0.3828.2700" negate="false"/>
          <criterion test_ref="wrt-62" comment="the patch kb883939 is installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL777" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Client Server Runtime System (CSRSS)</product>
      </affected>
      <dates>
        <submitted date="2005-05-02-12:00">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </submitted>
        <status_change date="2005-05-04-12:00">DRAFT</status_change>
        <status_change date="2005-06-01-12:00">INTERIM</status_change>
        <modified date="2005-06-02-12:00" comment="Added product">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <modified date="2005-06-17-12:00" comment="modified cmp-1106 - Replaced the test that checks for the service pack level, instead of checking for sp4 or ealier (did not check for GOLD edition) it is now negating the test that checks for sp5 for later.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <status_change date="2005-07-27-10:37">ACCEPTED</status_change>
      </dates>
      <description>Stack-based buffer overflow in WINSRV.DLL in the Client Server Runtime System (CSRSS) process of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via a specially-designed application that provides console window information with a long FaceName value.</description>
      <reference source="CVE">CVE-2005-0551</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1106" comment="Windows 2000 (sp4 or earlier) is installed" negate="false"/>
          <criterion test_ref="wft-579" comment="The version of Ntoskrnl.exe is less than 5.0.2195.7035" negate="false"/>
          <criterion test_ref="wrt-427" comment="the patch KB890859 is installed (Hotfix key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL778" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Local Security Authority Subsystem Service (LSASS)</product>
      </affected>
      <dates>
        <submitted date="2004-12-28-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2005-01-12-12:00">DRAFT</status_change>
        <status_change date="2005-02-02-12:00">INTERIM</status_change>
        <status_change date="2005-02-23-12:00">ACCEPTED</status_change>
        <modified date="2005-06-17-12:00" comment="modified cmp-1106 - Replaced the test that checks for the service pack level, instead of checking for sp4 or ealier (did not check for GOLD edition) it is now negating the test that checks for sp5 for later.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <status_change date="2005-06-22-12:35">INTERIM</status_change>
        <status_change date="2005-07-27-10:37">ACCEPTED</status_change>
      </dates>
      <description>LSASS (Local Security Authority Subsystem Service) of Windows 2000 Server and Windows Server 2003 does not properly validate connection information, which allows local users to gain privileges via a specially-designed program.</description>
      <reference source="CVE">CVE-2004-0894</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1106" comment="Windows 2000 (sp4 or earlier) is installed" negate="false"/>
          <criterion test_ref="wft-328" comment="the version of lsasrv.dll is less than 5.0.2195.6987" negate="false"/>
          <criterion test_ref="wrt-36" comment="the patch kb885835is installed (Hotfix key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL779" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Windows kernel</product>
      </affected>
      <dates>
        <submitted date="2004-11-30-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2005-01-12-12:00">DRAFT</status_change>
        <status_change date="2005-02-02-12:00">INTERIM</status_change>
        <status_change date="2005-02-23-12:00">ACCEPTED</status_change>
        <modified date="2005-06-02-12:00" comment="Added product">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-06-08-03:17">INTERIM</status_change>
        <status_change date="2005-06-29-06:49">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in Windows Kernel allows local users to gain privileges by causing certain error messages to be passed to a debugger.</description>
      <reference source="CVE">CVE-2003-0112</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-478" comment="the patch Q811493 is installed" negate="true"/>
          <criterion test_ref="cmp-66" comment="Windows XP (sp1 or earlier) is installed" negate="false"/>
          <criterion test_ref="wrt-547" comment="the patch KB840987 is installed (Hotfix key)" negate="true"/>
          <criterion test_ref="wft-76" comment="The version of Ntoskrnl.exe is less than 5.1.2600.160" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL780" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Word 2003</product>
      </affected>
      <dates>
        <submitted date="2005-08-18-04:00">
          <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
        </submitted>
        <status_change date="2005-08-25-10:05">DRAFT</status_change>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Multiple TCP/IP and ICMP implementations, when using Path MTU (PMTU) discovery (PMTUD), allow remote attackers to cause a denial of service (network throughput reduction for TCP connections) via forged ICMP ("Fragmentation Needed and Don't Fragment was Set") packets with a low next-hop MTU value, aka the "Path MTU discovery attack."  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</description>
      <reference source="CVE">CVE-2004-1060</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="cmp-23" comment="32-bit version of Windows or 64-bit (itanium architecture) version of Windows is installed" negate="false"/>
          <criterion test_ref="wft-600" comment="the version of Tcpip.sys is less than 5.2.3790.336" negate="false"/>
          <criterion test_ref="wrt-3" comment="a Win2K/XP/2003 service pack is installed" negate="true"/>
          <criterion test_ref="wrt-443" comment="the patch KB893066 is installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-380" comment="Enable Path MTU Discovery is Disabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL781" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>mozilla</product>
      </affected>
      <dates>
        <submitted date="2005-08-15-04:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2005-08-19-10:05">DRAFT</status_change>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 and 7.2 allows remote attackers to cause a denial of service (access violation and crash), and possibly execute arbitrary code, by calling InstallVersion.compareTo with an object instead of a string.</description>
      <reference source="CVE">CVE-2005-2265</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-216" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="rvt-31" comment="mozilla RPM is earlier than 37:1.7.10-1.1.3.1" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="upt-859" comment="/usr/bin/mozilla is executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL782" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Internet Explorer 6</product>
      </affected>
      <dates>
        <submitted date="2005-06-22-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2005-06-22-04:52">DRAFT</status_change>
        <modified date="2005-06-24-12:00" comment="updated description ">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </modified>
        <status_change date="2005-07-27-10:37">INTERIM</status_change>
        <status_change date="2005-08-18-07:37">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the PNG image rendering component of Microsoft Internet Explorer allows remote attackers to execute arbitrary code via a crafted PNG file.</description>
      <reference source="CVE">CVE-2005-1211</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-51" comment="Internet Explorer 6  for Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="cmp-179" comment="a vulnerable version of mshtml.dll exisits" negate="false"/>
          <criterion test_ref="wrt-62" comment="the patch kb883939 is installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-59" comment="PNG image rendering enabled in Internet Explorer" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL784" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Services for UNIX</product>
      </affected>
      <dates>
        <submitted date="2005-06-22-12:00">
          <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
        </submitted>
        <status_change date="2005-06-22-12:38">DRAFT</status_change>
        <status_change date="2005-07-27-10:37">INTERIM</status_change>
        <status_change date="2005-08-18-07:37">ACCEPTED</status_change>
      </dates>
      <description>The Telnet client for Microsoft Windows XP, Windows Server 2003, and Windows Services for UNIX allows remote attackers to read sensitive environment variables via the NEW-ENVIRON option with a SEND ENV_USERVAR command.</description>
      <reference source="CVE">CVE-2005-1205</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
          <criterion test_ref="wrt-49" comment="the patch KB896428 for Services for UNIX is installed" negate="true"/>
          <criterion test_ref="cmp-47" comment="Services for UNIX is instaled and a vulnerable version of telnet.exe exists" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL785" class="vulnerability">
      <affected family="hp-ux">
        <hpux:platform>HP-UX 11</hpux:platform>
        <product>Apache</product>
      </affected>
      <dates>
        <submitted date="2006-03-18-07:24">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-03-22-11:10">DRAFT</status_change>
        <status_change date="2006-04-06-06:31">INTERIM</status_change>
        <status_change date="2006-05-03-10:06">ACCEPTED</status_change>
      </dates>
      <description>A security flaw in some versions of the HP-UX usermod command can result in recursively changing the ownership of all directories and files under a user's home directory.  Specifically, executing	# usermod -d &lt;old home dir> -u &lt;new gid> -m &lt;username> or	# usermod -d &lt;old home dir> -u &lt;new or old gid> -m &lt;username> incorrectly changes ownership recursively to &lt;username>.  If the home directory is '/', this action will render the system inoperable.</description>
      <reference source="MISC">http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00614838</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-618" comment="700 Series or 800 Series OS Release 11.11" negate="false"/>
          <criterion test_ref="cmp-782" comment="Patch PHCO_29269, PHCO_30275, or PHCO_32181 has been installed" negate="false"/>
          <criterion test_ref="hpt-44" comment="Patch PHSS_34169 or subsequent is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL786" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2005-10-12-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-10-19-05:46">DRAFT</status_change>
        <status_change date="2005-11-16-08:02">INTERIM</status_change>
        <status_change date="2005-12-01-06:00">ACCEPTED</status_change>
      </dates>
      <description>netman.dll in Microsoft Windows Connections Manager Library allows local users to cause a denial of service (Network Connections Service crash) via a large integer argument to a particular function.</description>
      <reference source="CVE">CVE-2005-2307</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wrt-4" comment="Win2K/XP/2003 service pack 1 is installed" negate="false"/>
          <criterion test_ref="wft-696" comment="netman.dll is less than 5.2.3790.2516" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL787" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Internet Explorer</product>
      </affected>
      <dates>
        <submitted date="2006-04-12-12:55">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-04-12-05:16">DRAFT</status_change>
        <status_change date="2006-05-03-10:06">INTERIM</status_change>
      </dates>
      <description>Unspecified vulnerability in Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via certain invalid HTML that causes memory corruption.</description>
      <reference source="CVE">CVE-2006-1185</reference>
      <status>INTERIM</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-692" comment="Windows XP (64-bit,SP1 or 32-bit,SP2) is installed" negate="false"/>
          <criterion test_ref="wft-777" comment="the version of mshtml.dll is less than 6.0.2900.2873" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL789" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Microsoft Internet Explorer 6 Service Pack 1</product>
      </affected>
      <dates>
        <submitted date="2005-05-10-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2005-05-11-05:38">DRAFT</status_change>
        <status_change date="2005-06-01-03:30">INTERIM</status_change>
        <status_change date="2005-06-22-12:38">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the URL processor of Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a URL with a long hostname, aka "URL Parsing Memory Corruption Vulnerability."</description>
      <reference source="CVE">CVE-2005-0554</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-50" comment="Internet Explorer 6 Service Pack 1 is installed" negate="false"/>
          <criterion test_ref="cmp-292" comment="a vulnerable version of mshtml.dll exisits GDR/QFE" negate="false"/>
          <criterion test_ref="wrt-440" comment="the patch kb890923  is installed (XP Win2K Hotfix key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL790" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Internet Explorer 6</product>
      </affected>
      <dates>
        <submitted date="2005-08-23-04:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2005-08-25-10:05">DRAFT</status_change>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
        <modified date="2005-12-26-09:40" comment="Removed reference to patch kb896727 from criteria.">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </modified>
        <status_change date="2006-01-12-08:59">ACCEPTED</status_change>
      </dates>
      <description>Unknown vulnerability in Internet Explorer 5.0, 5.5, and 6.0 allows remote attackers to obtain information and possibly execute code when browsing from a web site to a web folder view using WebDAV, aka "Web Folder Behaviors Cross-Domain Vulnerability".</description>
      <reference source="CVE">CVE-2005-1989</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-51" comment="Internet Explorer 6  for Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="cmp-315" comment="a vulnerable version of mshtml.dll exisits" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL791" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Internet Explorer</product>
      </affected>
      <dates>
        <submitted date="2006-04-12-12:55">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-04-12-05:16">DRAFT</status_change>
        <status_change date="2006-05-03-10:06">INTERIM</status_change>
      </dates>
      <description>Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via by instantiating the (1) Mdt2gddr.dll, (2) Mdt2dd.dll, and (3) Mdt2gddo.dll COM objects as ActiveX controls, which leads to memory corruption.</description>
      <reference source="CVE">CVE-2006-1186</reference>
      <status>INTERIM</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-692" comment="Windows XP (64-bit,SP1 or 32-bit,SP2) is installed" negate="false"/>
          <criterion test_ref="wft-777" comment="the version of mshtml.dll is less than 6.0.2900.2873" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL792" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Internet Explorer</product>
      </affected>
      <dates>
        <submitted date="2006-04-12-12:55">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-04-12-05:16">DRAFT</status_change>
        <status_change date="2006-05-03-10:06">INTERIM</status_change>
      </dates>
      <description>Unspecified vulnerability in Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via a crafted URL with double-byte characters, aka the "Double Byte Character Parsing Memory Corruption Vulnerability."</description>
      <reference source="CVE">CVE-2006-1189</reference>
      <status>INTERIM</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-613" comment="Win2K or XP,SP1 is installed" negate="false"/>
          <criterion test_ref="wrt-652" comment="Internet Explorer 6 (any patch level) is installed" negate="false"/>
          <criterion test_ref="wft-776" comment="the version of mshtml.dll is less than 6.0.2800.1543" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL793" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Internet Explorer</product>
      </affected>
      <dates>
        <submitted date="2005-12-26-09:36">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-01-04-08:04">DRAFT</status_change>
        <status_change date="2006-01-25-07:30">INTERIM</status_change>
        <status_change date="2006-02-22-08:27">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 5.01 SP4 up to 6 on various Windows operating systems, including IE 6.0.2900.2180 on Windows XP, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not ActiveX controls, as demonstrated using the JVIEW Profiler (Javaprxy.dll).  NOTE: the researcher says that the vendor could not reproduce this problem.</description>
      <reference source="CVE">CVE-2005-2087</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-200" comment="Internet Explorer 6.0 Installed XP SP2" negate="false"/>
          <criterion test_ref="wft-626" comment="the version of mshtml.dll is less than 6.0.2900.2722" negate="false"/>
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL794" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 98</windows:platform>
        <windows:platform>Microsoft Windows ME</windows:platform>
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Windows Script Engine for JScript v5.1</product>
      </affected>
      <dates>
        <submitted date="2004-03-03-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <modified date="2004-03-04-12:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </modified>
        <status_change date="2004-03-09-12:00">INTERIM</status_change>
        <status_change date="2004-03-25-12:00">ACCEPTED</status_change>
        <modified date="2004-08-24-11:02" comment="Added patch information to definition">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2004-08-26-12:00">INTERIM</status_change>
        <status_change date="2004-09-09-12:00">ACCEPTED</status_change>
      </dates>
      <description>Integer overflow in JsArrayFunctionHeapSort function used by Windows Script Engine for JScript (JScript.dll) on various Windows operating system allows remote attackers to execute arbitrary code via a malicious web page or HTML e-mail that uses a large array index value that enables a heap-based buffer overflow attack.</description>
      <reference source="CVE">CVE-2003-0010</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wft-120" comment="the version of jscript.dll is less than 5.1.0.8513" negate="false"/>
          <criterion test_ref="cmp-212" comment="Windows 2000 Service Pack 4 (or later) is installed" negate="true"/>
          <criterion test_ref="wrt-500" comment="the patch js56nen.exe (5.1.0.8513 version) is installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-76" comment="active scripting is enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL795" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 98</windows:platform>
        <windows:platform>Microsoft Windows ME</windows:platform>
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Windows Script Engine for JScript v5.5</product>
      </affected>
      <dates>
        <submitted date="2004-03-03-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <modified date="2004-03-04-12:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </modified>
        <status_change date="2004-03-09-12:00">INTERIM</status_change>
        <status_change date="2004-03-25-12:00">ACCEPTED</status_change>
        <modified date="2004-08-24-11:01" comment="Added patch information to definition">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2004-08-26-12:00">INTERIM</status_change>
        <status_change date="2004-09-09-12:00">ACCEPTED</status_change>
      </dates>
      <description>Integer overflow in JsArrayFunctionHeapSort function used by Windows Script Engine for JScript (JScript.dll) on various Windows operating system allows remote attackers to execute arbitrary code via a malicious web page or HTML e-mail that uses a large array index value that enables a heap-based buffer overflow attack.</description>
      <reference source="CVE">CVE-2003-0010</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wft-121" comment="the version of jscript.dll is less than 5.5.0.8513" negate="false"/>
          <criterion test_ref="cmp-212" comment="Windows 2000 Service Pack 4 (or later) is installed" negate="true"/>
          <criterion test_ref="wrt-501" comment="the patch js56nen.exe (5.5.0.8513 version) is installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-76" comment="active scripting is enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL796" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>Microsoft ASN.1 Library</product>
      </affected>
      <dates>
        <submitted date="2004-02-12-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <status_change date="2004-03-09-12:00">INTERIM</status_change>
        <status_change date="2004-03-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Multiple integer overflows in Microsoft ASN.1 library (MSASN1.DLL), as used in LSASS.EXE, CRYPT32.DLL, and other Microsoft executables and libraries on Windows NT 4.0, 2000, and XP, allow remote attackers to execute arbitrary code via ASN.1 BER encodings with (1) very large length fields that cause arbitrary heap data to be overwritten, or (2) modified bit strings.</description>
      <reference source="CVE">CVE-2003-0818</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" negate="false"/>
          <criterion test_ref="wft-108" comment="the version of msasn1.dll is less than 5.0.2195.6824" negate="false"/>
          <criterion test_ref="wrt-99" comment="the patch kb828028 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL797" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Microsoft ASN.1 Library</product>
      </affected>
      <dates>
        <submitted date="2004-02-12-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <status_change date="2004-03-09-12:00">INTERIM</status_change>
        <status_change date="2004-03-25-12:00">ACCEPTED</status_change>
        <modified date="2004-09-13-10:28" comment="">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2004-09-15-12:00">INTERIM</status_change>
        <status_change date="2004-09-29-12:00">ACCEPTED</status_change>
      </dates>
      <description>Multiple integer overflows in Microsoft ASN.1 library (MSASN1.DLL), as used in LSASS.EXE, CRYPT32.DLL, and other Microsoft executables and libraries on Windows NT 4.0, 2000, and XP, allow remote attackers to execute arbitrary code via ASN.1 BER encodings with (1) very large length fields that cause arbitrary heap data to be overwritten, or (2) modified bit strings.</description>
      <reference source="CVE">CVE-2003-0818</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-53" comment="a vulnerable version of msasn1.dll exists" negate="false"/>
          <criterion test_ref="wrt-99" comment="the patch kb828028 is installed" negate="true"/>
          <criterion test_ref="cmp-66" comment="Windows XP (sp1 or earlier) is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL798" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Office</product>
      </affected>
      <dates>
        <submitted date="2006-03-15-10:53">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-03-15-07:17">DRAFT</status_change>
        <status_change date="2006-04-06-06:30">INTERIM</status_change>
        <status_change date="2006-05-03-10:06">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in Microsoft Office 2000 SP3, XP SP3, and other versions and packages, allows user-complicit attackers to execute arbitrary code via a routing slip that is longer than specified by the provided length field.</description>
      <reference source="CVE">CVE-2006-0009</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-10013" comment="Microsoft Office XP is installed" negate="false"/>
          <criterion test_ref="wft-772" comment="the version of Winword.exe is less than 10.0.6775.0" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL799" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft ASN.1 Library</product>
      </affected>
      <dates>
        <submitted date="2004-02-12-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <status_change date="2004-03-09-12:00">INTERIM</status_change>
        <status_change date="2004-03-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Multiple integer overflows in Microsoft ASN.1 library (MSASN1.DLL), as used in LSASS.EXE, CRYPT32.DLL, and other Microsoft executables and libraries on Windows NT 4.0, 2000, and XP, allow remote attackers to execute arbitrary code via ASN.1 BER encodings with (1) very large length fields that cause arbitrary heap data to be overwritten, or (2) modified bit strings.</description>
      <reference source="CVE">CVE-2003-0818</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wft-106" comment="the version of msasn1.dll is less than 5.2.3790.88" negate="false"/>
          <criterion test_ref="wrt-99" comment="the patch kb828028 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL800" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>Windows Internet Naming Service (WINS)</product>
      </affected>
      <dates>
        <submitted date="2004-02-12-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <status_change date="2004-03-09-12:00">INTERIM</status_change>
        <status_change date="2004-03-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>The Windows Internet Naming Service (WINS) for Microsoft Windows Server 2003, and possibly Windows NT and Server 2000, does not properly validate the length of certain packets, which allows attackers to cause a denial of service and possibly execute arbitrary code.</description>
      <reference source="CVE">CVE-2003-0825</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-44" comment="Windows NT Server 4.0 is installed" negate="false"/>
          <criterion test_ref="wft-110" comment="the version of wins.exe is less than 4.0.1381.7255" negate="false"/>
          <criterion test_ref="wrt-97" comment="the patch kb830352 is installed (Hotfix key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-98" comment="the wins service is enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL801" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>Windows Internet Naming Service (WINS)</product>
      </affected>
      <dates>
        <submitted date="2004-02-12-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <status_change date="2004-03-09-12:00">INTERIM</status_change>
        <status_change date="2004-03-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>The Windows Internet Naming Service (WINS) for Microsoft Windows Server 2003, and possibly Windows NT and Server 2000, does not properly validate the length of certain packets, which allows attackers to cause a denial of service and possibly execute arbitrary code.</description>
      <reference source="CVE">CVE-2003-0825</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-45" comment="Windows NT Server 4.0, Terminal Server Edition is installed" negate="false"/>
          <criterion test_ref="wft-111" comment="the version of wins.exe is less than 4.0.1381.33554" negate="false"/>
          <criterion test_ref="wrt-97" comment="the patch kb830352 is installed (Hotfix key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-98" comment="the wins service is enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL802" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Windows Internet Naming Service (WINS)</product>
      </affected>
      <dates>
        <submitted date="2004-02-12-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <status_change date="2004-03-09-12:00">INTERIM</status_change>
        <status_change date="2004-03-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>The Windows Internet Naming Service (WINS) for Microsoft Windows Server 2003, and possibly Windows NT and Server 2000, does not properly validate the length of certain packets, which allows attackers to cause a denial of service and possibly execute arbitrary code.</description>
      <reference source="CVE">CVE-2003-0825</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wft-112" comment="the version of wins.exe is less than 5.2.3790.99" negate="false"/>
          <criterion test_ref="wrt-97" comment="the patch kb830352 is installed (Hotfix key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-98" comment="the wins service is enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL803" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>PWLib</product>
      </affected>
      <dates>
        <submitted date="2004-03-20-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <modified date="2004-05-05-12:00" comment="Added a program_name element to rlt-217">
          <contributor organization="The MITRE Corporation">Matt Busby</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Multiple vulnerabilities in PWLib before 1.6.0 allow remote attackers to cause a denial of service and possibly execute arbitrary code, as demonstrated by the NISCC/OUSPG PROTOS test suite for the H.225 protocol.</description>
      <reference source="CVE">CVE-2004-0097</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-257" comment="pwlib version is less than 1.4.7-4.1" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="rlt-217" comment="a program is listening on TCP or UDP port 1720" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL804" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>netpbm</product>
      </affected>
      <dates>
        <submitted date="2004-03-20-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Matt Busby</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>netpbm 9.25 and earlier does not properly create temporary files, which allows local users to overwrite arbitrary files.</description>
      <reference source="CVE">CVE-2003-0924</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="cmp-341" comment="Vulnerable Config" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-342" comment="Vulnerable configuration" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL805" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Internet Explorer 6 Service Pack 1 for Windows Server 2003</product>
      </affected>
      <dates>
        <submitted date="2004-02-03-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <modified date="2004-03-04-12:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <status_change date="2004-03-09-12:00">INTERIM</status_change>
        <status_change date="2004-03-25-12:00">ACCEPTED</status_change>
        <modified date="2005-05-10-12:00" comment="modified wrt-51 - Comment updated to indicate IE 6.">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </modified>
        <status_change date="2005-05-11-05:33">INTERIM</status_change>
        <status_change date="2005-06-01-03:30">ACCEPTED</status_change>
        <modified date="2005-09-26-12:54" comment="modified wft-95 - Changed comment to match test">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-28-01:04">INTERIM</status_change>
        <status_change date="2005-10-19-05:47">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions via a javascript protocol URL in a sub-frame, which is added to the history list and executed in the top window's zone when the history.back (back) function is called, as demonstrated by BackToFramedJpu, aka the "Travel Log Cross Domain Vulnerability."</description>
      <reference source="CVE">CVE-2003-1026</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-51" comment="Internet Explorer 6  for Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wft-95" comment="the version of mshtml.dll is less than 6.0.3790.118" negate="false"/>
          <criterion test_ref="wrt-140" comment="the patch q832894 is installed (Hotfix key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL806" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>XFree86</product>
      </affected>
      <dates>
        <submitted date="2004-03-20-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Matt Busby</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in ReadFontAlias from dirfile.c of XFree86 4.1.0 through 4.3.0 allows local users and remote attackers to execute arbitrary code via a font alias file (font.alias) with a long token, a different vulnerability than CVE-2004-0084 and CVE-2004-0106.</description>
      <reference source="CVE">CVE-2004-0083</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-261" comment="XFree86 version is less than 4.3.0-2.90.55" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-568" comment="/usr/X11R6/bin/XFree86 is SUID and executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL807" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>XFree86</product>
      </affected>
      <dates>
        <submitted date="2004-03-20-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Matt Busby</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the ReadFontAlias function in XFree86 4.1.0 to 4.3.0, when using the CopyISOLatin1Lowered function, allows local or remote authenticated users to execute arbitrary code via a malformed entry in the font alias (font.alias) file, a different vulnerability than CVE-2004-0083 and CVE-2004-0106.</description>
      <reference source="CVE">CVE-2004-0084</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-261" comment="XFree86 version is less than 4.3.0-2.90.55" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-568" comment="/usr/X11R6/bin/XFree86 is SUID and executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL808" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 4</redhat:platform>
        <product>mozilla</product>
      </affected>
      <dates>
        <submitted date="2005-08-15-04:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2005-08-19-10:05">DRAFT</status_change>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Firefox before 1.0.5, Thunderbird before 1.0.5, Mozilla before 1.7.9, Netscape 8.0.2, and K-Meleon 0.9 runs XBL scripts even when Javascript has been disabled, which makes it easier for remote attackers to bypass such protection.</description>
      <reference source="CVE">CVE-2005-2261</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-1" comment="Red Hat Enterprise 4 is installed" negate="false"/>
          <criterion test_ref="rvt-32" comment="mozilla RPM is earlier than 37:1.7.10-1.4.1" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="upt-859" comment="/usr/bin/mozilla is executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL809" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>XFree86</product>
      </affected>
      <dates>
        <submitted date="2004-03-20-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Matt Busby</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Multiple unknown vulnerabilities in XFree86 4.1.0 to 4.3.0, related to improper handling of font files, a different set of vulnerabilities than CVE-2004-0083 and CVE-2004-0084.</description>
      <reference source="CVE">CVE-2004-0106</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-261" comment="XFree86 version is less than 4.3.0-2.90.55" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-568" comment="/usr/X11R6/bin/XFree86 is SUID and executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL810" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>netpbm</product>
      </affected>
      <dates>
        <submitted date="2004-03-20-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Matt Busby</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>netpbm 9.25 and earlier does not properly create temporary files, which allows local users to overwrite arbitrary files.</description>
      <reference source="CVE">CVE-2003-0924</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="cmp-574" comment="Vulnerable Config" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-342" comment="Vulnerable configuration" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL811" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Mutt</product>
      </affected>
      <dates>
        <submitted date="2004-03-20-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-05-05-12:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the index menu code (menu_pad_string of menu.c) for Mutt 1.4.1 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via certain mail messages.</description>
      <reference source="CVE">CVE-2004-0078</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-265" comment="mutt version is less than 1.4.1-3.3" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-305" comment="/usr/bin/mutt is executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL812" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Outlook Express</product>
      </affected>
      <dates>
        <submitted date="2006-04-12-12:55">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-04-12-05:16">DRAFT</status_change>
        <status_change date="2006-05-03-10:06">INTERIM</status_change>
      </dates>
      <description>Buffer overflow in Microsoft Outlook Express 5.5 and 6 allows remote attackers to execute arbitrary code via a crafted Windows Address Book (WAB) file containing "certain Unicode strings" and modified length values.</description>
      <reference source="CVE">CVE-2006-0014</reference>
      <status>INTERIM</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wrt-10026" comment="Win2K/XP/2003 is patched" negate="true"/>
          <criterion test_ref="wrt-70" comment="64-Bit version of Windows is installed" negate="true"/>
          <criterion test_ref="wrt-10004" comment="Outlook Express 6.0 is installed" negate="false"/>
          <criterion test_ref="wft-797" comment="the version of inetcomm.dll is less than 6.0.3790.2663" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL813" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Mailman</product>
      </affected>
      <dates>
        <submitted date="2004-03-20-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-05-05-12:00">ACCEPTED</status_change>
      </dates>
      <description>Cross-site scripting (XSS) vulnerability in the admin CGI script for Mailman before 2.1.4 allows remote attackers to steal session cookies and conduct unauthorized activities.</description>
      <reference source="CVE">CVE-2003-0965</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-266" comment="mailman version is less than 2.1.1-5" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="rlt-218" comment="httpd is listening on the network" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL815" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Mailman</product>
      </affected>
      <dates>
        <submitted date="2004-03-20-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-05-05-12:00">ACCEPTED</status_change>
      </dates>
      <description>Cross-site scripting (XSS) vulnerability in the create CGI script for Mailman before 2.1.3 allows remote attackers to steal cookies of other users.</description>
      <reference source="CVE">CVE-2003-0992</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-266" comment="mailman version is less than 2.1.1-5" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="rlt-218" comment="httpd is listening on the network" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL816" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2005-10-12-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-10-19-05:46">DRAFT</status_change>
        <status_change date="2005-11-16-08:02">INTERIM</status_change>
        <status_change date="2005-12-01-06:00">ACCEPTED</status_change>
      </dates>
      <description>COM+ in Microsoft Windows does not properly "create and use memory structures," which allows local users or remote attackers to execute arbitrary code.</description>
      <reference source="CVE">CVE-2005-1978</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
          <criterion test_ref="wrt-432" comment="Win2K/XP/2003 service pack 4 is installed" negate="false"/>
          <criterion test_ref="cmp-605" comment="Either ole32.dll or rpcss.dll has a version less than 5.0.2195.7059" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL817" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>mozilla</product>
      </affected>
      <dates>
        <submitted date="2005-08-15-04:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2005-08-19-10:05">DRAFT</status_change>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Firefox before 1.0.5 and Mozilla before 1.7.9 does not properly clone base objects, which allows remote attackers to execute arbitrary code by navigating the prototype chain to reach a privileged object.</description>
      <reference source="CVE">CVE-2005-2270</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-216" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="rvt-31" comment="mozilla RPM is earlier than 37:1.7.10-1.1.3.1" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="upt-859" comment="/usr/bin/mozilla is executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL818" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Gaim</product>
      </affected>
      <dates>
        <submitted date="2004-03-20-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-05-05-12:00">ACCEPTED</status_change>
      </dates>
      <description>Multiple buffer overflows in Gaim 0.75 and earlier, and Ultramagnetic before 0.81, allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) cookies in a Yahoo web connection, (2) a long name parameter in the Yahoo login web page, (3) a long value parameter in the Yahoo login page, (4) a YMSG packet, (5) the URL parser, and (6) HTTP proxy connect.</description>
      <reference source="CVE">CVE-2004-0006</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-267" comment="gaim version is less than 0.75-0.9.0" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-802" comment="/usr/bin/gaim is executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL819" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Gaim</product>
      </affected>
      <dates>
        <submitted date="2004-03-20-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-05-05-12:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the Extract Info Field Function for (1) MSN and (2) YMSG protocol handlers in Gaim 0.74 and earlier, and Ultramagnetic before 0.81, allows remote attackers to cause a denial of service and possibly execute arbitrary code.</description>
      <reference source="CVE">CVE-2004-0007</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-267" comment="gaim version is less than 0.75-0.9.0" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-802" comment="/usr/bin/gaim is executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL820" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Gaim</product>
      </affected>
      <dates>
        <submitted date="2004-03-20-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-05-05-12:00">ACCEPTED</status_change>
      </dates>
      <description>Integer overflow in Gaim 0.74 and earlier, and Ultramagnetic before 0.81, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a directIM packet that triggers a heap-based buffer overflow.</description>
      <reference source="CVE">CVE-2004-0008</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-267" comment="gaim version is less than 0.75-0.9.0" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-802" comment="/usr/bin/gaim is executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL821" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>slocate</product>
      </affected>
      <dates>
        <submitted date="2004-03-20-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Matt Busby</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Heap-based buffer overflow in main.c of slocate 2.6, and possibly other versions, may allow local users to gain privileges via a modified slocate database that causes a negative "pathlen" value to be used.</description>
      <reference source="CVE">CVE-2003-0848</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-268" comment="slocate version is less than 2.7-2" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-805" comment="/usr/bin/slocate is setgid" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL822" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Midnight Commander</product>
      </affected>
      <dates>
        <submitted date="2004-03-21-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Matt Busby</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Stack-based buffer overflow in vfs_s_resolve_symlink of vfs/direntry.c for Midnight Commander (mc) 4.6.0 and earlier, and possibly later versions, allows remote attackers to execute arbitrary code during symlink conversion.</description>
      <reference source="CVE">CVE-2003-1023</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-269" comment="mc version is less than 4.6.0-7.9" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-806" comment="/usr/bin/mc is executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL823" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>KDE</product>
      </affected>
      <dates>
        <submitted date="2004-03-20-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-05-05-12:00">INTERIM</status_change>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Konqueror in KDE 3.1.3 and earlier (kdelibs) allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Konqueror to send the cookie outside the specified URL subsets, e.g. to a vulnerable application that runs on the same server as the target application.</description>
      <reference source="CVE">CVE-2003-0592</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-270" comment="kdelibs version is less than 3.1-13" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-304" comment="/usr/bin/konqueror is executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL825" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>mremap</product>
      </affected>
      <dates>
        <submitted date="2004-03-20-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Matt Busby</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>The do_mremap function for the mremap system call in Linux 2.2 to 2.2.25, 2.4 to 2.4.24, and 2.6 to 2.6.2, does not properly check the return value from the do_munmap function when the maximum number of VMA descriptors is exceeded, which allows local users to gain root privileges, a different vulnerability than CAN-2003-0985.</description>
      <reference source="CVE">CVE-2004-0077</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="cmp-808" comment="Vulnerable Config" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL826" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>PWLib</product>
      </affected>
      <dates>
        <submitted date="2004-03-20-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <modified date="2004-05-05-12:00" comment="Added a program_name element to rlt-217">
          <contributor organization="The MITRE Corporation">Matt Busby</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Multiple vulnerabilities in PWLib before 1.6.0 allow remote attackers to cause a denial of service and possibly execute arbitrary code, as demonstrated by the NISCC/OUSPG PROTOS test suite for the H.225 protocol.</description>
      <reference source="CVE">CVE-2004-0097</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-274" comment="pwlib version is less than 1.4.7-7.EL" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="rlt-217" comment="a program is listening on TCP or UDP port 1720" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL827" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>Samba 3.0.0 and 3.0.1</product>
      </affected>
      <dates>
        <submitted date="2004-03-20-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Matt Busby</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>The mksmbpasswd shell script (mksmbpasswd.sh) in Samba 3.0.0 and 3.0.1, when creating an account but marking it as disabled, may overwrite the user password with an uninitialized buffer, which could enable the account with a more easily guessable password.</description>
      <reference source="CVE">CVE-2004-0082</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-275" comment="samba version is less than 3.0.2-6.3E" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="rlt-210" comment="smbd is listening on the network" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL828" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>mod_python</product>
      </affected>
      <dates>
        <submitted date="2004-03-20-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Matt Busby</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Unknown vulnerability in mod_python 3.0.x before 3.0.4, and 2.7.x before 2.7.9, allows remote attackers to cause a denial of service (httpd crash) via a certain query string.</description>
      <reference source="CVE">CVE-2003-0973</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-276" comment="mod_python version is less than 3.0.1-4" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="rlt-220" comment="httpd is listening to the network" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL830" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>XFree86</product>
      </affected>
      <dates>
        <submitted date="2004-02-20-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Matt Busby</contributor>
        </modified>
        <modified date="2004-05-11-12:00" comment="Corrected pattern used in rrt-206">
          <contributor organization="The MITRE Corporation">Matt Busby</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in ReadFontAlias from dirfile.c of XFree86 4.1.0 through 4.3.0 allows local users and remote attackers to execute arbitrary code via a font alias file (font.alias) with a long token, a different vulnerability than CVE-2004-0084 and CVE-2004-0106.</description>
      <reference source="CVE">CVE-2004-0083</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-277" comment="XFree86 version is less than 4.3.0-55.EL" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-568" comment="/usr/X11R6/bin/XFree86 is SUID and executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL831" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>XFree86</product>
      </affected>
      <dates>
        <submitted date="2004-03-20-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Matt Busby</contributor>
        </modified>
        <modified date="2004-05-11-12:00" comment="Corrected pattern used in rrt-206">
          <contributor organization="The MITRE Corporation">Matt Busby</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the ReadFontAlias function in XFree86 4.1.0 to 4.3.0, when using the CopyISOLatin1Lowered function, allows local or remote authenticated users to execute arbitrary code via a malformed entry in the font alias (font.alias) file, a different vulnerability than CVE-2004-0083 and CVE-2004-0106.</description>
      <reference source="CVE">CVE-2004-0084</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-277" comment="XFree86 version is less than 4.3.0-55.EL" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-568" comment="/usr/X11R6/bin/XFree86 is SUID and executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL832" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>XFree86</product>
      </affected>
      <dates>
        <submitted date="2004-03-20-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Matt Busby</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Multiple unknown vulnerabilities in XFree86 4.1.0 to 4.3.0, related to improper handling of font files, a different set of vulnerabilities than CVE-2004-0083 and CVE-2004-0084.</description>
      <reference source="CVE">CVE-2004-0106</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-277" comment="XFree86 version is less than 4.3.0-55.EL" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-568" comment="/usr/X11R6/bin/XFree86 is SUID and executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL833" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>XMLSoft Libxml2</product>
      </affected>
      <dates>
        <submitted date="2004-03-20-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Matt Busby</contributor>
        </modified>
        <modified date="2004-05-11-12:00" comment="Corrected pattern used in rrt-206">
          <contributor organization="The MITRE Corporation">Matt Busby</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">INTERIM</status_change>
        <status_change date="2004-06-16-12:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the (1) nanohttp or (2) nanoftp modules in XMLSoft Libxml 2 (Libxml2) 2.6.0 through 2.6.5 allow remote attackers to execute arbitrary code via a long URL.</description>
      <reference source="CVE">CVE-2004-0110</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="cmp-815" comment="Vulnerable Config" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL834" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Linux kernel</product>
      </affected>
      <dates>
        <submitted date="2004-03-20-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Matt Busby</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Unknown vulnerability in Linux kernel before 2.4.22 allows local users to gain privileges, related to "R128 DRI limits checking."</description>
      <reference source="CVE">CVE-2004-0003</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="cmp-816" comment="Vulnerable Configuration" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL835" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Linux kernel</product>
      </affected>
      <dates>
        <submitted date="2004-03-20-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Matt Busby</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Stack-based buffer overflow in the ncp_lookup function for ncpfs in Linux kernel 2.4.x allows local users to gain privileges.</description>
      <reference source="CVE">CVE-2004-0010</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="cmp-816" comment="Vulnerable Configuration" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL836" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Vicam USB driver</product>
      </affected>
      <dates>
        <submitted date="2004-03-20-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Matt Busby</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>The Vicam USB driver in Linux before 2.4.25 does not use the copy_from_user function when copying data from userspace to kernel space, which crosses security boundaries and allows local users to cause a denial of service.</description>
      <reference source="CVE">CVE-2004-0075</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="cmp-816" comment="Vulnerable Configuration" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL837" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>mremap</product>
      </affected>
      <dates>
        <submitted date="2004-03-20-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Matt Busby</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>The do_mremap function for the mremap system call in Linux 2.2 to 2.2.25, 2.4 to 2.4.24, and 2.6 to 2.6.2, does not properly check the return value from the do_munmap function when the maximum number of VMA descriptors is exceeded, which allows local users to gain root privileges, a different vulnerability than CAN-2003-0985.</description>
      <reference source="CVE">CVE-2004-0077</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="cmp-816" comment="Vulnerable Configuration" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL838" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>Mutt</product>
      </affected>
      <dates>
        <submitted date="2004-03-20-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-05-05-12:00">ACCEPTED</status_change>
        <modified date="2004-05-11-12:00" comment="Corrected pattern used in rrt-206">
          <contributor organization="The MITRE Corporation">Matt Busby</contributor>
        </modified>
      </dates>
      <description>Buffer overflow in the index menu code (menu_pad_string of menu.c) for Mutt 1.4.1 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via certain mail messages.</description>
      <reference source="CVE">CVE-2004-0078</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-284" comment="mutt version is less than 1.4.1-3.4" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-305" comment="/usr/bin/mutt is executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL839" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>mod_python</product>
      </affected>
      <dates>
        <submitted date="2004-03-20-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Matt Busby</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Unknown vulnerability in mod_python 3.0.x before 3.0.4, and 2.7.x before 2.7.9, allows remote attackers to cause a denial of service (httpd crash) via a certain query string.</description>
      <reference source="CVE">CVE-2003-0973</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-276" comment="mod_python version is less than 3.0.1-4" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="rlt-220" comment="httpd is listening to the network" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL840" class="vulnerability">
      <affected family="hp-ux">
        <hpux:platform>HP-UX 11</hpux:platform>
        <product>Apache</product>
      </affected>
      <dates>
        <submitted date="2005-11-30-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-12-20-11:03">DRAFT</status_change>
        <status_change date="2006-01-04-08:04">INTERIM</status_change>
        <status_change date="2006-01-25-07:30">ACCEPTED</status_change>
      </dates>
      <description>The Apache HTTP server before 1.3.34, and 2.0.x before 2.0.55, when acting as an HTTP proxy, allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes Apache to incorrectly handle and forward the body of the request in a way that causes the receiving server to process it as a separate HTTP request, aka "HTTP Request Smuggling."</description>
      <reference source="CVE">CVE-2005-2088</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-684" comment="700 Series or 800 Series OS Release 11.00, 11.11, or 11.23" negate="false"/>
          <criterion test_ref="hst-29" comment="hpuxwsAPACHE is installed" negate="false"/>
          <criterion test_ref="hst-30" comment="hpuxwsAPACHE has a version greater than or equal (A|B).2.0.55.0" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL842" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Windows Media Services</product>
      </affected>
      <dates>
        <submitted date="2004-03-09-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
      </dates>
      <description>Unknown vulnerability in Windows Media Station Service and Windows Media Monitor Service components of Windows Media Services 4.1 allows remote attackers to cause a denial of service (disallowing new connections) via a certain sequence of TCP/IP packets.</description>
      <reference source="CVE">CVE-2003-0905</reference>
      <status>INTERIM</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-59" comment="Windows Media Services 4.1 is installed on Microsoft Windows 2000 Server" negate="false"/>
          <criterion test_ref="wft-46" comment="the version of nscm.exe is less than 4.1.0.3934" negate="false"/>
          <criterion test_ref="wft-47" comment="the version of nspmon.exe is less than 4.1.0.3934" negate="false"/>
          <criterion test_ref="wrt-149" comment="the patch kb832359 is installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="ukn-3" comment="configured to only offer streaming media over unicast" negate="true"/>
          <criterion test_ref="wrt-160" comment="the Windows Media Station service is disabled" negate="true"/>
          <criterion test_ref="wrt-161" comment="the Windows Media Monitor service is disabled" negate="true"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL843" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 95</windows:platform>
        <product>Microsoft Outlook</product>
      </affected>
      <dates>
        <submitted date="2004-03-09-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <status_change date="2004-05-05-12:00">ACCEPTED</status_change>
        <modified date="2005-01-13-12:00" comment="modified wft-130 - Added path to the end of the registry key specified in the first component of the file path">
          <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
        </modified>
        <status_change date="2005-01-20-12:57">INTERIM</status_change>
        <status_change date="2005-02-16-12:00">ACCEPTED</status_change>
      </dates>
      <description>Argument injection vulnerability in Microsoft Outlook 2002 does not sufficiently filter parameters of mailto: URLs when using them as arguments when calling OUTLOOK.EXE, which allows remote attackers to use script code in the Local Machine zone and execute arbitrary programs.</description>
      <reference source="CVE">CVE-2004-0121</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-197" comment="Outlook 2002 is installed" negate="false"/>
          <criterion test_ref="wft-130" comment="the version of outlook.exe is less than 10.00.5709.0000" negate="false"/>
          <criterion test_ref="wrt-198" comment="the patch kb828040 is installed" negate="true"/>
          <criterion test_ref="wrt-199" comment="Microsoft Office XP Service Pack 3 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL844" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 95</windows:platform>
        <windows:platform>Microsoft Windows 98</windows:platform>
        <windows:platform>Microsoft Windows ME</windows:platform>
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>MSN Messenger</product>
      </affected>
      <dates>
        <submitted date="2004-03-09-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2004-03-25-12:00">INTERIM</status_change>
        <modified date="2004-03-30-12:00" comment="Fixed the path for both versions of the file to look at the correct registry key to determine the location of the 'Program Files' folder..  ">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <status_change date="2004-05-05-12:00">ACCEPTED</status_change>
      </dates>
      <description>Microsoft MSN Messenger 6.0 and 6.1 does not properly handle certain requests, which allows remote attackers to read arbitrary files.</description>
      <reference source="CVE">CVE-2004-0122</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-68" comment="Microsoft MSN Messenger 6.0 or 6.1 (but less than 6.1.0211) is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL845" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>gdk-pixbuf</product>
      </affected>
      <dates>
        <submitted date="2004-03-20-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-05-05-12:00">INTERIM</status_change>
        <modified date="2004-05-11-12:00" comment="Corrected pattern used in rrt-206">
          <contributor organization="The MITRE Corporation">Matt Busby</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>gdk-pixbuf before 0.20 allows attackers to cause a denial of service (crash) via a malformed bitmap (BMP) file.</description>
      <reference source="CVE">CVE-2004-0111</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="cmp-821" comment="Vulnerable configuration" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL846" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>gdk-pixbuf</product>
      </affected>
      <dates>
        <submitted date="2004-03-20-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-05-05-12:00">INTERIM</status_change>
        <modified date="2004-05-11-12:00" comment="Corrected pattern used in rrt-206">
          <contributor organization="The MITRE Corporation">Matt Busby</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>gdk-pixbuf before 0.20 allows attackers to cause a denial of service (crash) via a malformed bitmap (BMP) file.</description>
      <reference source="CVE">CVE-2004-0111</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="cmp-822" comment="Vulnerable configuration" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL847" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>tcpdump</product>
      </affected>
      <dates>
        <submitted date="2004-03-20-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-05-05-12:00">ACCEPTED</status_change>
      </dates>
      <description>tcpdump before 3.8.1 allows remote attackers to cause a denial of service (infinite loop) via certain ISAKMP packets, a different vulnerability than CVE-2004-0057.</description>
      <reference source="CVE">CVE-2003-0989</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-291" comment="tcpdump version is less than 3.7.2-7.9.1" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-823" comment="/usr/sbin/tcpdump is executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL848" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2005-10-12-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-10-19-05:46">DRAFT</status_change>
        <status_change date="2005-11-16-08:02">INTERIM</status_change>
        <status_change date="2005-12-01-06:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in Collaboration Data Objects (CDO), as used in Microsoft Windows and Microsoft Exchange Server, allows remote attackers to execute arbitrary code when CDOSYS or CDOEX processes an e-mail message with a large header name, as demonstrated using the "Content-Type" string.</description>
      <reference source="CVE">CVE-2005-1987</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1112" comment="Windows XP 64-bit" negate="false"/>
          <criterion test_ref="wrt-4" comment="Win2K/XP/2003 service pack 1 is installed" negate="false"/>
          <criterion test_ref="wft-680" comment="cdosys.dll is less than 6.5.6756.0" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL849" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>sysstat</product>
      </affected>
      <dates>
        <submitted date="2004-03-20-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Matt Busby</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">INTERIM</status_change>
        <status_change date="2004-06-16-12:00">ACCEPTED</status_change>
      </dates>
      <description>The (1) post and (2) trigger scripts in sysstat 4.0.7 and earlier allow local users to overwrite arbitrary files via symlink attacks on temporary files, a different vulnerability than CVE-2004-0108.</description>
      <reference source="CVE">CVE-2004-0107</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-292" comment="sysstat version is less than 4.0.7-4.rhl9.1" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL850" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>tcpdump</product>
      </affected>
      <dates>
        <submitted date="2004-03-20-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-05-05-12:00">ACCEPTED</status_change>
      </dates>
      <description>The print_attr_string function in print-radius.c for tcpdump 3.8.1 and earlier allows remote attackers to cause a denial of service (segmentation fault) via a RADIUS attribute with a large length value.</description>
      <reference source="CVE">CVE-2004-0055</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-291" comment="tcpdump version is less than 3.7.2-7.9.1" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-823" comment="/usr/sbin/tcpdump is executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL851" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>tcpdump</product>
      </affected>
      <dates>
        <submitted date="2004-03-20-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-05-05-12:00">ACCEPTED</status_change>
      </dates>
      <description>The rawprint function in the ISAKMP decoding routines (print-isakmp.c) for tcpdump 3.8.1 and earlier allows remote attackers to cause a denial of service (segmentation fault) via malformed ISAKMP packets that cause invalid "len" or "loc" values to be used in a loop, a different vulnerability than CVE-2003-0989.</description>
      <reference source="CVE">CVE-2004-0057</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-291" comment="tcpdump version is less than 3.7.2-7.9.1" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-823" comment="/usr/sbin/tcpdump is executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL852" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>tcpdump</product>
      </affected>
      <dates>
        <submitted date="2004-03-20-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-05-05-12:00">ACCEPTED</status_change>
      </dates>
      <description>tcpdump before 3.8.1 allows remote attackers to cause a denial of service (infinite loop) via certain ISAKMP packets, a different vulnerability than CVE-2004-0057.</description>
      <reference source="CVE">CVE-2003-0989</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-293" comment="tcpdump version is less than 3.7.2-7.E3.1" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-823" comment="/usr/sbin/tcpdump is executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL853" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>tcpdump</product>
      </affected>
      <dates>
        <submitted date="2004-03-20-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-05-05-12:00">ACCEPTED</status_change>
      </dates>
      <description>The print_attr_string function in print-radius.c for tcpdump 3.8.1 and earlier allows remote attackers to cause a denial of service (segmentation fault) via a RADIUS attribute with a large length value.</description>
      <reference source="CVE">CVE-2004-0055</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-293" comment="tcpdump version is less than 3.7.2-7.E3.1" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-823" comment="/usr/sbin/tcpdump is executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL854" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>tcpdump</product>
      </affected>
      <dates>
        <submitted date="2004-03-20-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-05-05-12:00">ACCEPTED</status_change>
        <modified date="2004-05-11-12:00" comment="Corrected pattern used in rrt-206">
          <contributor organization="The MITRE Corporation">Matt Busby</contributor>
        </modified>
      </dates>
      <description>The rawprint function in the ISAKMP decoding routines (print-isakmp.c) for tcpdump 3.8.1 and earlier allows remote attackers to cause a denial of service (segmentation fault) via malformed ISAKMP packets that cause invalid "len" or "loc" values to be used in a loop, a different vulnerability than CVE-2003-0989.</description>
      <reference source="CVE">CVE-2004-0057</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-293" comment="tcpdump version is less than 3.7.2-7.E3.1" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-823" comment="/usr/sbin/tcpdump is executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL855" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>CVS server</product>
      </affected>
      <dates>
        <submitted date="2004-03-20-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Matt Busby</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>CVS server before 1.11.10 may allow attackers to cause the CVS server to create directories and files in the file system root directory via malformed module requests.</description>
      <reference source="CVE">CVE-2003-0977</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-294" comment="cvs version is less than 1.11.2-13" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="upt-799" comment="/ is world-writable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL856" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Ethereal</product>
      </affected>
      <dates>
        <submitted date="2004-03-20-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Matt Busby</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>The SMB dissector in Ethereal before 0.10.0 allows remote attackers to cause a denial of service via a malformed SMB packet that triggers a segmentation fault during processing of Selected packets.</description>
      <reference source="CVE">CVE-2003-1012</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="cmp-829" comment="Vulnerable Config" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-830" comment="Vulnerable Config" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL857" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Tethereal</product>
      </affected>
      <dates>
        <submitted date="2004-03-20-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Matt Busby</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>The Q.931 dissector in Ethereal before 0.10.0, and Tethereal, allows remote attackers to cause a denial of service (crash) via a malformed Q.931, which triggers a null dereference.</description>
      <reference source="CVE">CVE-2003-1013</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="cmp-829" comment="Vulnerable Config" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-830" comment="Vulnerable Config" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL858" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>KDE Personal Information Management (kdepim)</product>
      </affected>
      <dates>
        <submitted date="2004-03-20-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-05-05-12:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the VCF file information reader for KDE Personal Information Management (kdepim) suite in KDE 3.1.0 through 3.1.4 allows attackers to execute arbitrary code via a VCF file.</description>
      <reference source="CVE">CVE-2003-0988</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-297" comment="kdepim version is less than 3.1-6" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-839" comment="/usr/share/services/kfile_vcf.desktop is readable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL859" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Linux kernel</product>
      </affected>
      <dates>
        <submitted date="2004-03-20-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Matt Busby</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Real time clock (RTC) routines in Linux kernel 2.4.23 and earlier do not properly initialize their structures, which could leak kernel data to user space.</description>
      <reference source="CVE">CVE-2003-0984</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="cmp-840" comment="Vulnerable Configuration" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL860" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Linux kernel</product>
      </affected>
      <dates>
        <submitted date="2004-03-20-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Matt Busby</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>The mremap system call (do_mremap) in Linux kernel 2.4.x before 2.4.21 does not properly perform bounds checks, which allows local users to cause a denial of service and possibly gain privileges by causing a remapping of a virtual memory area (VMA) to create a zero length VMA, a different vulnerability than CAN-2004-0077.</description>
      <reference source="CVE">CVE-2003-0985</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="cmp-840" comment="Vulnerable Configuration" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL861" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>nfs-utils packages</product>
      </affected>
      <dates>
        <submitted date="2004-03-20-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Matt Busby</contributor>
        </modified>
        <modified date="2004-05-11-12:00" comment="Corrected pattern used in rrt-206">
          <contributor organization="The MITRE Corporation">Matt Busby</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">INTERIM</status_change>
        <status_change date="2004-06-16-12:00">ACCEPTED</status_change>
      </dates>
      <description>rpc.mountd in nfs-utils after 1.0.3 and before 1.0.6 allows attackers to cause a denial of service (crash) via an NFS mount of a directory from a client whose reverse DNS lookup name is different from the forward lookup name.</description>
      <reference source="CVE">CVE-2004-0154</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-301" comment="nfs-utils version is less than 1.0.6-7.EL" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="rlt-221" comment="rpc.mountd is listening to the network" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL862" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>Sysstat</product>
      </affected>
      <dates>
        <submitted date="2004-03-20-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Matt Busby</contributor>
        </modified>
        <modified date="2004-05-11-12:00" comment="Corrected pattern used in rrt-206">
          <contributor organization="The MITRE Corporation">Matt Busby</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">INTERIM</status_change>
        <status_change date="2004-06-16-12:00">ACCEPTED</status_change>
      </dates>
      <description>The (1) post and (2) trigger scripts in sysstat 4.0.7 and earlier allow local users to overwrite arbitrary files via symlink attacks on temporary files, a different vulnerability than CVE-2004-0108.</description>
      <reference source="CVE">CVE-2004-0107</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-302" comment="sysstat version is less than 4.0.7-4.EL3.2" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL863" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>httpd</product>
      </affected>
      <dates>
        <submitted date="2004-03-17-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Matt Busby</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">INTERIM</status_change>
        <status_change date="2004-06-16-12:00">ACCEPTED</status_change>
      </dates>
      <description>Multiple stack-based buffer overflows in (1) mod_alias and (2) mod_rewrite for Apache before 1.3.29 allow attackers to create configuration files to cause a denial of service (crash) or execute arbitrary code via a regular expression with more than 9 captures.</description>
      <reference source="CVE">CVE-2003-0542</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-303" comment="httpd version is less than 2.0.40-21.9" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="rlt-203" comment="httpd.worker is listening on the network" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL864" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>Apache</product>
      </affected>
      <dates>
        <submitted date="2004-03-20-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Matt Busby</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">INTERIM</status_change>
        <status_change date="2004-06-16-12:00">ACCEPTED</status_change>
      </dates>
      <description>Multiple stack-based buffer overflows in (1) mod_alias and (2) mod_rewrite for Apache before 1.3.29 allow attackers to create configuration files to cause a denial of service (crash) or execute arbitrary code via a regular expression with more than 9 captures.</description>
      <reference source="CVE">CVE-2003-0542</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-304" comment="httpd version is less than 2.0.46-26.ent" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="rlt-203" comment="httpd.worker is listening on the network" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL865" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>KDE Personal Information Management (kdepim)</product>
      </affected>
      <dates>
        <submitted date="2004-03-20-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-05-05-12:00">INTERIM</status_change>
        <modified date="2004-05-11-12:00" comment="Corrected pattern used in rrt-206">
          <contributor organization="The MITRE Corporation">Matt Busby</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the VCF file information reader for KDE Personal Information Management (kdepim) suite in KDE 3.1.0 through 3.1.4 allows attackers to execute arbitrary code via a VCF file.</description>
      <reference source="CVE">CVE-2003-0988</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-305" comment="kdepim version is less than 3.1.3-3.3" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-839" comment="/usr/share/services/kfile_vcf.desktop is readable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL866" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>CVS server</product>
      </affected>
      <dates>
        <submitted date="2004-03-20-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Matt Busby</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">INTERIM</status_change>
        <status_change date="2004-06-16-12:00">ACCEPTED</status_change>
      </dates>
      <description>CVS server before 1.11.10 may allow attackers to cause the CVS server to create directories and files in the file system root directory via malformed module requests.</description>
      <reference source="CVE">CVE-2003-0977</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-306" comment="cvs version is less than 1.11.2-14" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="upt-799" comment="/ is world-writable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL867" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>Linux kernel</product>
      </affected>
      <dates>
        <submitted date="2004-03-20-12:00">
          <contributor organization="The MITRE Corporation">Matt Busby</contributor>
        </submitted>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Matt Busby</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">INTERIM</status_change>
        <status_change date="2004-06-16-12:00">ACCEPTED</status_change>
      </dates>
      <description>The mremap system call (do_mremap) in Linux kernel 2.4.x before 2.4.21 does not properly perform bounds checks, which allows local users to cause a denial of service and possibly gain privileges by causing a remapping of a virtual memory area (VMA) to create a zero length VMA, a different vulnerability than CAN-2004-0077.</description>
      <reference source="CVE">CVE-2003-0985</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="cmp-843" comment="Vulnerable Configuration" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL868" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>Linux kernel</product>
      </affected>
      <dates>
        <submitted date="2004-03-20-12:00">
          <contributor organization="The MITRE Corporation">Matt Busby</contributor>
        </submitted>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Matt Busby</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">INTERIM</status_change>
        <status_change date="2004-06-16-12:00">ACCEPTED</status_change>
      </dates>
      <description>Unknown vulnerability in the eflags checking in the 32-bit ptrace emulation for the Linux kernel on AMD64 systems allows local users to gain privileges.</description>
      <reference source="CVE">CVE-2004-0001</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="uut-3" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-310" comment="kernel version is less than 2.4.21-9.EL" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL869" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>Net-SNMP</product>
      </affected>
      <dates>
        <submitted date="2004-03-20-12:00">
          <contributor organization="The MITRE Corporation">Matt Busby</contributor>
        </submitted>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Matt Busby</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">INTERIM</status_change>
        <status_change date="2004-06-16-12:00">ACCEPTED</status_change>
      </dates>
      <description>Net-SNMP before 5.0.9 allows a user or community to access data in MIB objects, even if that data is not allowed to be viewed.</description>
      <reference source="CVE">CVE-2003-0935</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-311" comment="net-snmp version is less than 5.0.9-2.30E.1" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="rlt-223" comment="snmpd is listening to the network" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL870" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>OpenSSL</product>
      </affected>
      <dates>
        <submitted date="2004-03-20-12:00">
          <contributor organization="The MITRE Corporation">Matt Busby</contributor>
        </submitted>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Matt Busby</contributor>
        </modified>
        <modified date="2004-05-11-12:00" comment="Corrected pattern used in rrt-206">
          <contributor organization="The MITRE Corporation">Matt Busby</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">INTERIM</status_change>
        <status_change date="2004-06-16-12:00">ACCEPTED</status_change>
      </dates>
      <description>The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that triggers a null dereference.</description>
      <reference source="CVE">CVE-2004-0079</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-312" comment="openssl version is less than 0.9.7a-33.4" negate="false"/>
          <criterion test_ref="rvt-313" comment="openssl-devel version is less than 0.9.7a-33.4" negate="false"/>
          <criterion test_ref="rvt-314" comment="openssl-perl version is less than 0.9.7a-33.4" negate="false"/>
          <criterion test_ref="rvt-315" comment="openssl096b version is less than 0.9.6b-16" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL871" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>OpenSSL</product>
      </affected>
      <dates>
        <submitted date="2004-03-20-12:00">
          <contributor organization="The MITRE Corporation">Matt Busby</contributor>
        </submitted>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Matt Busby</contributor>
        </modified>
        <modified date="2004-05-11-12:00" comment="Corrected pattern used in rrt-206">
          <contributor organization="The MITRE Corporation">Matt Busby</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">INTERIM</status_change>
        <status_change date="2004-06-16-12:00">ACCEPTED</status_change>
      </dates>
      <description>OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote attackers to cause a denial of service (infinite loop), as demonstrated using the Codenomicon TLS Test Tool.</description>
      <reference source="CVE">CVE-2004-0081</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-312" comment="openssl version is less than 0.9.7a-33.4" negate="false"/>
          <criterion test_ref="rvt-313" comment="openssl-devel version is less than 0.9.7a-33.4" negate="false"/>
          <criterion test_ref="rvt-314" comment="openssl-perl version is less than 0.9.7a-33.4" negate="false"/>
          <criterion test_ref="rvt-315" comment="openssl096b version is less than 0.9.6b-16" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL872" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>mozilla</product>
      </affected>
      <dates>
        <submitted date="2004-03-18-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-05-05-12:00">INTERIM</status_change>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Multiple vulnerabilities in multiple vendor implementations of the Secure/Multipurpose Internet Mail Extensions (S/MIME) protocol allow remote attackers to cause a denial of service and possibly execute arbitrary code via an S/MIME email message containing certain unexpected ASN.1 constructs, as demonstrated using the NISSC test suite.</description>
      <reference source="CVE">CVE-2003-0564</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-316" comment="mozilla-nss version is less than 1.4.2-0.9.0" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL873" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>mozilla</product>
      </affected>
      <dates>
        <submitted date="2004-03-18-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-05-05-12:00">INTERIM</status_change>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Mozilla allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Mozilla to send the cookie outside the specified URL subsets, e.g. to a vulnerable application that runs on the same server as the target application.</description>
      <reference source="CVE">CVE-2003-0594</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-317" comment="mozilla version is less than 1.4.2-0.9.0" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-844" comment="/usr/bin/mozilla is executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL874" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>mozilla</product>
      </affected>
      <dates>
        <submitted date="2004-03-18-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-05-05-12:00">INTERIM</status_change>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Mozilla before 1.4.2 executes Javascript events in the context of a new page while it is being loaded, allowing it to interact with the previous page (zombie document) and enable cross-domain and cross-site scripting (XSS) attacks, as demonstrated using onmousemove events.</description>
      <reference source="CVE">CVE-2004-0191</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-317" comment="mozilla version is less than 1.4.2-0.9.0" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-844" comment="/usr/bin/mozilla is executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL875" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>libxml2</product>
      </affected>
      <dates>
        <submitted date="2004-02-22-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">INTERIM</status_change>
        <status_change date="2004-06-16-12:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the (1) nanohttp or (2) nanoftp modules in XMLSoft Libxml 2 (Libxml2) 2.6.0 through 2.6.5 allow remote attackers to execute arbitrary code via a long URL.</description>
      <reference source="CVE">CVE-2004-0110</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="cmp-815" comment="Vulnerable Config" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL876" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>httpd</product>
      </affected>
      <dates>
        <submitted date="2004-03-26-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">INTERIM</status_change>
        <status_change date="2004-06-16-12:00">ACCEPTED</status_change>
      </dates>
      <description>Memory leak in ssl_engine_io.c for mod_ssl in Apache 2 before 2.0.49 allows remote attackers to cause a denial of service (memory consumption) via plain HTTP requests to the SSL port of an SSL-enabled server.</description>
      <reference source="CVE">CVE-2004-0113</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-323" comment="mod_ssl version is less than 2.0.46-32.ent" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="rlt-220" comment="httpd is listening to the network" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL877" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Red Hat 9</product>
      </affected>
      <dates>
        <submitted date="2004-04-07-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-05-05-12:00">INTERIM</status_change>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>The "%xx" URL decoding function in Squid 2.5STABLE4 and earlier allows remote attackers to bypass url_regex ACLs via a URL with a NULL ("%00") characterm, which causes Squid to use only a portion of the requested URL when comparing it against the access control lists.</description>
      <reference source="CVE">CVE-2004-0189</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-325" comment="squid version is less than 2.5STABLE1-3.9" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="rlt-225" comment="squid is listening on the network" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL878" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Red Hat 9</product>
      </affected>
      <dates>
        <submitted date="2004-04-07-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">INTERIM</status_change>
        <status_change date="2004-06-16-12:00">ACCEPTED</status_change>
      </dates>
      <description>Multiple buffer overflows in Ethereal 0.8.13 to 0.10.2 allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) NetFlow, (2) IGAP, (3) EIGRP, (4) PGM, (5) IrDA, (6) BGP, (7) ISUP, or (8) TCAP dissectors.</description>
      <reference source="CVE">CVE-2004-0176</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="cmp-848" comment="Vulnerable Config" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-849" comment="Vulnerable Config" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL879" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Red Hat 9</product>
      </affected>
      <dates>
        <submitted date="2004-04-07-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">INTERIM</status_change>
        <status_change date="2004-06-16-12:00">ACCEPTED</status_change>
      </dates>
      <description>The dissect_attribute_value_pairs function in packet-radius.c for Ethereal 0.8.13 to 0.10.2 allows remote attackers to cause a denial of service (crash) via a malformed RADIUS packet that triggers a null dereference.</description>
      <reference source="CVE">CVE-2004-0365</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="cmp-848" comment="Vulnerable Config" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-849" comment="Vulnerable Config" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL880" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>Red Hat 9</product>
      </affected>
      <dates>
        <submitted date="2004-04-07-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">INTERIM</status_change>
        <status_change date="2004-06-16-12:00">ACCEPTED</status_change>
      </dates>
      <description>Ethereal 0.10.1 to 0.10.2 allows remote attackers to cause a denial of service (crash) via a zero-length Presentation protocol selector.</description>
      <reference source="CVE">CVE-2004-0367</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="cmp-848" comment="Vulnerable Config" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-849" comment="Vulnerable Config" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL881" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <solaris:platform>Sun Solaris 10</solaris:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2006-04-14-06:41">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-04-19-10:08">DRAFT</status_change>
      </dates>
      <description>The Bourne shell (sh) in Solaris 8, 9, and 10 allows local users to cause a denial of service (sh crash) via an unspecified attack vector that causes sh processes to crash during creation of temporary files.</description>
      <reference source="CVE">CVE-2006-1780</reference>
      <status>DRAFT</status>
      <version>0</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-845" comment="Solaris 8 (SPARC) meets Sun Alert ID 102282 criteria." negate="false"/>
          <criterion test_ref="cmp-846" comment="Solaris 9 (SPARC) meets Sun Alert ID 102282 criteria." negate="false"/>
          <criterion test_ref="cmp-847" comment="Solaris 10 (SPARC) meets Sun Alert ID 102282 criteria." negate="false"/>
          <criterion test_ref="cmp-853" comment="Solaris 8 (x86) meets Sun Alert ID 102282 criteria." negate="false"/>
          <criterion test_ref="cmp-854" comment="Solaris 9 (x86) meets Sun Alert ID 102282 criteria." negate="false"/>
          <criterion test_ref="cmp-855" comment="Solaris 10 (x86) meets Sun Alert ID 102282 criteria." negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL882" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 98</windows:platform>
        <windows:platform>Microsoft Windows ME</windows:platform>
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Outlook Express</product>
      </affected>
      <dates>
        <submitted date="2004-04-13-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <status_change date="2004-05-05-12:00">INTERIM</status_change>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>The MHTML protocol handler in Microsoft Outlook Express 5.5 SP2 through Outlook Express 6 SP1 allows remote attackers to bypass domain restrictions and execute arbitrary code, as demonstrated on Internet Explorer using script in a compiled help (CHM) file that references the InfoTech Storage (ITS) protocol handlers such as (1) ms-its, (2) ms-itss, (3) its, or (4) mk:@MSITStore, aka the "MHTML URL Processing Vulnerability."</description>
      <reference source="CVE">CVE-2004-0380</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-170" comment="Outlook Express 5.5 SP2 is installed" negate="false"/>
          <criterion test_ref="wft-182" comment="the version of inetcomm.dll is less than 5.50.4939.300" negate="false"/>
          <criterion test_ref="wrt-188" comment="the patch kb837009 is installed (installed components key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL883" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Local Security Authority Subsystem Service (LSASS)</product>
      </affected>
      <dates>
        <submitted date="2004-04-13-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <status_change date="2004-05-05-12:00">INTERIM</status_change>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Stack-based buffer overflow in certain Active Directory service functions in LSASRV.DLL of the Local Security Authority Subsystem Service (LSASS) in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows 98, and Windows ME, allows remote attackers to execute arbitrary code via a packet that causes the DsRolerUpgradeDownlevelServer function to create long debug entries for the DCPROMO.LOG log file, as exploited by the Sasser worm.</description>
      <reference source="CVE">CVE-2003-0533</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
          <criterion test_ref="wft-192" comment="the version of lsasrv.dll is less than 5.0.2195.6902" negate="false"/>
          <criterion test_ref="wrt-187" comment="the patch kb835732 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL885" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Secure Sockets Layer (SSL)</product>
      </affected>
      <dates>
        <submitted date="2004-04-13-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
        <status_change date="2004-05-05-12:00">INTERIM</status_change>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>The Microsoft Secure Sockets Layer (SSL) library, as used in Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service via malformed SSL messages.</description>
      <reference source="CVE">CVE-2004-0120</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wft-172" comment="the version of schannel.dll is less than 5.2.3790.132" negate="false"/>
          <criterion test_ref="wrt-187" comment="the patch kb835732 is installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wmt-5" comment="SSL is enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL886" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Secure Sockets Layer (SSL)</product>
      </affected>
      <dates>
        <submitted date="2004-04-13-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
        <status_change date="2004-05-05-12:00">INTERIM</status_change>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
        <modified date="2004-09-13-10:29" comment="cmp-66 added">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2004-09-15-12:00">INTERIM</status_change>
        <status_change date="2004-09-29-12:00">ACCEPTED</status_change>
      </dates>
      <description>The Microsoft Secure Sockets Layer (SSL) library, as used in Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service via malformed SSL messages.</description>
      <reference source="CVE">CVE-2004-0120</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-130" comment="a vulnerable version of schannel.dll exists" negate="false"/>
          <criterion test_ref="wrt-187" comment="the patch kb835732 is installed" negate="true"/>
          <criterion test_ref="cmp-66" comment="Windows XP (sp1 or earlier) is installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wmt-5" comment="SSL is enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL887" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>Red Hat Enteprise Linux 3</product>
      </affected>
      <dates>
        <submitted date="2004-04-08-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <modified date="2004-05-11-12:00" comment="Corrected pattern used in rrt-206">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">INTERIM</status_change>
        <status_change date="2004-06-16-12:00">ACCEPTED</status_change>
      </dates>
      <description>Multiple buffer overflows in Ethereal 0.8.13 to 0.10.2 allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) NetFlow, (2) IGAP, (3) EIGRP, (4) PGM, (5) IrDA, (6) BGP, (7) ISUP, or (8) TCAP dissectors.</description>
      <reference source="CVE">CVE-2004-0176</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="cmp-863" comment="Vulnerable Config" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-849" comment="Vulnerable Config" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL888" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Internet Explorer 5.01 Service Pack 4</product>
      </affected>
      <dates>
        <submitted date="2005-08-23-04:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2005-08-25-10:05">DRAFT</status_change>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
        <modified date="2005-12-26-09:40" comment="Removed reference to patch kb896727 from criteria.">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </modified>
        <status_change date="2006-01-12-08:59">ACCEPTED</status_change>
      </dates>
      <description>Unknown vulnerability in Internet Explorer 5.0, 5.5, and 6.0 allows remote attackers to obtain information and possibly execute code when browsing from a web site to a web folder view using WebDAV, aka "Web Folder Behaviors Cross-Domain Vulnerability".</description>
      <reference source="CVE">CVE-2005-1989</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-54" comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false"/>
          <criterion test_ref="wft-629" comment="the version of mshtml.dll is less than 5.0.3831.1800" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL889" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Private Communications Transport (PCT)</product>
      </affected>
      <dates>
        <submitted date="2004-04-13-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <status_change date="2004-05-05-12:00">INTERIM</status_change>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
        <modified date="2004-09-13-11:21" comment="added cmp-66">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2004-09-15-12:00">INTERIM</status_change>
        <status_change date="2004-09-29-12:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the Private Communications Transport (PCT) protocol implementation in the Microsoft SSL library, as used in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows 98, and Windows ME, allows remote attackers to execute arbitrary code via PCT 1.0 handshake packets.</description>
      <reference source="CVE">CVE-2003-0719</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-130" comment="a vulnerable version of schannel.dll exists" negate="false"/>
          <criterion test_ref="wrt-187" comment="the patch kb835732 is installed" negate="true"/>
          <criterion test_ref="cmp-66" comment="Windows XP (sp1 or earlier) is installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wmt-5" comment="SSL is enabled" negate="false"/>
          <criterion test_ref="wrt-165" comment="PCT support is disabled" negate="true"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL890" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Local Descriptor Table (LDT)</product>
      </affected>
      <dates>
        <submitted date="2004-04-13-12:00">
          <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
        </submitted>
        <status_change date="2004-05-05-12:00">INTERIM</status_change>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>The NtSetLdtEntries function in the programming interface for the Local Descriptor Table (LDT) in Windows NT 4.0 and Windows 2000 allows local attackers to gain access to kernel memory and execute arbitrary code via an expand-down data segment descriptor descriptor that points to protected memory.</description>
      <reference source="CVE">CVE-2003-0910</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
          <criterion test_ref="wft-191" comment="the version of wintrust.dll is less than 5.131.2195.6824" negate="false"/>
          <criterion test_ref="wrt-187" comment="the patch kb835732 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL891" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>Red Hat Enteprise Linux 3</product>
      </affected>
      <dates>
        <submitted date="2004-04-08-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <modified date="2004-05-11-12:00" comment="Corrected pattern used in rrt-206">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">INTERIM</status_change>
        <status_change date="2004-06-16-12:00">ACCEPTED</status_change>
      </dates>
      <description>The dissect_attribute_value_pairs function in packet-radius.c for Ethereal 0.8.13 to 0.10.2 allows remote attackers to cause a denial of service (crash) via a malformed RADIUS packet that triggers a null dereference.</description>
      <reference source="CVE">CVE-2004-0365</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="cmp-863" comment="Vulnerable Config" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-849" comment="Vulnerable Config" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL892" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Secure Sockets Layer (SSL)</product>
      </affected>
      <dates>
        <submitted date="2004-04-13-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
        <status_change date="2004-05-05-12:00">INTERIM</status_change>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>The Microsoft Secure Sockets Layer (SSL) library, as used in Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service via malformed SSL messages.</description>
      <reference source="CVE">CVE-2004-0120</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
          <criterion test_ref="wft-171" comment="the version of schannel.dll is less than 5.1.2195.6899" negate="false"/>
          <criterion test_ref="wrt-187" comment="the patch kb835732 is installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wmt-5" comment="SSL is enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL893" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Remote Procedure Call (RPC)</product>
      </affected>
      <dates>
        <submitted date="2004-04-20-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2004-05-25-12:00">INTERIM</status_change>
        <status_change date="2004-06-16-12:00">ACCEPTED</status_change>
      </dates>
      <description>A multi-threaded race condition in the Windows RPC DCOM functionality with the MS03-039 patch installed allows remote attackers to cause a denial of service (crash or reboot) by causing two threads to process the same RPC request, which causes one thread to use memory after it has been freed, a different vulnerability than CVE-2003-0352 (Blaster/Nachi), CVE-2003-0715, and CVE-2003-0528, and as demonstrated by certain exploits against those vulnerabilities.</description>
      <reference source="CVE">CVE-2003-0813</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
          <criterion test_ref="wft-186" comment="the version of rpcrt4.dll is less than 5.0.2195.6904" negate="false"/>
          <criterion test_ref="wrt-189" comment="the patch kb828741 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL894" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Remote Procedure Call (RPC)</product>
      </affected>
      <dates>
        <submitted date="2004-04-20-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
      </dates>
      <description>A multi-threaded race condition in the Windows RPC DCOM functionality with the MS03-039 patch installed allows remote attackers to cause a denial of service (crash or reboot) by causing two threads to process the same RPC request, which causes one thread to use memory after it has been freed, a different vulnerability than CVE-2003-0352 (Blaster/Nachi), CVE-2003-0715, and CVE-2003-0528, and as demonstrated by certain exploits against those vulnerabilities.</description>
      <reference source="CVE">CVE-2003-0813</reference>
      <status>DRAFT</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="cmp-17" comment="a vulnerable version of rpcrt4.dll exists on Server 2003" negate="false"/>
          <criterion test_ref="wrt-189" comment="the patch kb828741 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL895" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>Windows logon process (winlogon)</product>
      </affected>
      <dates>
        <submitted date="2004-04-13-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <status_change date="2004-05-05-12:00">INTERIM</status_change>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the Windows logon process (winlogon) in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, and XP SP1, when a member of a domain, allows remote attackers to execute arbitrary code.</description>
      <reference source="CVE">CVE-2003-0806</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" negate="false"/>
          <criterion test_ref="cmp-136" comment="a vulnerable version of msgina.dll exists on NT" negate="false"/>
          <criterion test_ref="wrt-187" comment="the patch kb835732 is installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-196" comment="machine is a member of a domain" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL896" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Windows logon process (winlogon)</product>
      </affected>
      <dates>
        <submitted date="2004-04-13-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <status_change date="2004-05-05-12:00">INTERIM</status_change>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
        <modified date="2005-09-26-10:54" comment="modified wft-133 - Changed comment to match test">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-28-01:04">INTERIM</status_change>
        <status_change date="2005-10-19-05:47">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the Windows logon process (winlogon) in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, and XP SP1, when a member of a domain, allows remote attackers to execute arbitrary code.</description>
      <reference source="CVE">CVE-2003-0806</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
          <criterion test_ref="wft-133" comment="the version of msgina.dll is less than 5.0.2195.6895" negate="false"/>
          <criterion test_ref="wrt-187" comment="the patch kb835732 is installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-196" comment="machine is a member of a domain" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL897" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>Enhanced Metafile (EMF)</product>
        <product>Windows Metafile (WMF)</product>
      </affected>
      <dates>
        <submitted date="2004-04-13-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <status_change date="2004-05-05-12:00">INTERIM</status_change>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the rendering for (1) Windows Metafile (WMF) or (2) Enhanced Metafile (EMF) image formats in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, and XP SP1 allows remote attackers to execute arbitrary code via a malformed WMF or EMF image.</description>
      <reference source="CVE">CVE-2003-0906</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" negate="false"/>
          <criterion test_ref="cmp-89" comment="a vulnerable version of mf3216.dll exists on NT" negate="false"/>
          <criterion test_ref="wrt-187" comment="the patch kb835732 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL898" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Local Security Authority Subsystem Service (LSASS)</product>
      </affected>
      <dates>
        <submitted date="2004-04-13-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <status_change date="2004-05-05-12:00">INTERIM</status_change>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
        <modified date="2004-09-13-11:22" comment="cmp-66 added">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2004-09-15-12:00">INTERIM</status_change>
        <status_change date="2004-09-29-12:00">ACCEPTED</status_change>
      </dates>
      <description>Stack-based buffer overflow in certain Active Directory service functions in LSASRV.DLL of the Local Security Authority Subsystem Service (LSASS) in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows 98, and Windows ME, allows remote attackers to execute arbitrary code via a packet that causes the DsRolerUpgradeDownlevelServer function to create long debug entries for the DCPROMO.LOG log file, as exploited by the Sasser worm.</description>
      <reference source="CVE">CVE-2003-0533</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-143" comment="a vulnerable version of lsasrv.dll exists on XP" negate="false"/>
          <criterion test_ref="wrt-187" comment="the patch kb835732 is installed" negate="true"/>
          <criterion test_ref="cmp-66" comment="Windows XP (sp1 or earlier) is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL900" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Remote Procedure Call (RPC)</product>
      </affected>
      <dates>
        <submitted date="2004-04-20-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2004-05-25-12:00">INTERIM</status_change>
        <status_change date="2004-06-16-12:00">ACCEPTED</status_change>
      </dates>
      <description>A multi-threaded race condition in the Windows RPC DCOM functionality with the MS03-039 patch installed allows remote attackers to cause a denial of service (crash or reboot) by causing two threads to process the same RPC request, which causes one thread to use memory after it has been freed, a different vulnerability than CVE-2003-0352 (Blaster/Nachi), CVE-2003-0715, and CVE-2003-0528, and as demonstrated by certain exploits against those vulnerabilities.</description>
      <reference source="CVE">CVE-2003-0813</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-2" comment="Windows XP is installed" negate="false"/>
          <criterion test_ref="cmp-1" comment="a vulnerable version of rpcrt4.dll exists on XP" negate="false"/>
          <criterion test_ref="wrt-189" comment="the patch kb828741 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL901" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>COM Internet Services</product>
      </affected>
      <dates>
        <submitted date="2005-02-15-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <modified date="2005-02-16-12:00" comment="Added compound statement to include three platforms">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-02-23-08:48">DRAFT</status_change>
        <status_change date="2005-03-23-08:09">INTERIM</status_change>
        <status_change date="2005-04-13-12:15">ACCEPTED</status_change>
      </dates>
      <description>Windows 2000, XP, and Server 2003 does not properly "validate the use of memory regions" for COM structured storage files, which allows attackers to execute arbitrary code, aka the "COM Structured Storage Vulnerability."</description>
      <reference source="CVE">CVE-2005-0047</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wft-389" comment="the version of ole32.dll is less than 5.2.3790.250" negate="false"/>
          <criterion test_ref="wrt-91" comment="the patch KB873333 is installed" negate="true"/>
          <criterion test_ref="cmp-187" comment="Windows Server 2003 32-bit OR 64-bit OR Windows XP 64-bit Version 2003 is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL902" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>OpenSSL</product>
      </affected>
      <dates>
        <submitted date="2004-03-20-12:00">
          <contributor organization="The MITRE Corporation">Matt Busby</contributor>
        </submitted>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Matt Busby</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">INTERIM</status_change>
        <status_change date="2004-06-16-12:00">ACCEPTED</status_change>
      </dates>
      <description>OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote attackers to cause a denial of service (infinite loop), as demonstrated using the Codenomicon TLS Test Tool.</description>
      <reference source="CVE">CVE-2004-0081</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-318" comment="openssl version is less than 0.9.7a-20" negate="false"/>
          <criterion test_ref="rvt-319" comment="openssl-devel version is less than 0.9.7a-20" negate="false"/>
          <criterion test_ref="rvt-320" comment="openssl-perl version is less than 0.9.7a-20" negate="false"/>
          <criterion test_ref="rvt-321" comment="openssl096 version is less than 0.9.6-25.9" negate="false"/>
          <criterion test_ref="rvt-322" comment="openssl096b version is less than 0.9.6b-15" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL903" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>Private Communications Transport (PCT)</product>
      </affected>
      <dates>
        <submitted date="2004-04-13-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <status_change date="2004-05-05-12:00">INTERIM</status_change>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the Private Communications Transport (PCT) protocol implementation in the Microsoft SSL library, as used in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows 98, and Windows ME, allows remote attackers to execute arbitrary code via PCT 1.0 handshake packets.</description>
      <reference source="CVE">CVE-2003-0719</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" negate="false"/>
          <criterion test_ref="wft-170" comment="the version of schannel.dll is less than 4.87.1964.1880" negate="false"/>
          <criterion test_ref="wrt-187" comment="the patch kb835732 is installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wmt-5" comment="SSL is enabled" negate="false"/>
          <criterion test_ref="wrt-165" comment="PCT support is disabled" negate="true"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL904" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Help and Support Center (HSC)</product>
      </affected>
      <dates>
        <submitted date="2004-04-14-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <modified date="2004-05-12-12:00" comment="Added a criterion to the configuration section to see if the HCP protocol is registered.">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </modified>
        <status_change date="2004-06-16-12:00">INTERIM</status_change>
        <status_change date="2004-06-30-12:00">ACCEPTED</status_change>
      </dates>
      <description>Help and Support Center in Microsoft Windows XP SP1 does not properly validate HCP URLs, which allows remote attackers to execute arbitrary code via quotation marks in an hcp:// URL, which are not quoted when constructing the argument list to HelpCtr.exe.</description>
      <reference source="CVE">CVE-2003-0907</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wft-303" comment="the version of helpctr.exe is less than 5.2.3790.125" negate="false"/>
          <criterion test_ref="wrt-187" comment="the patch kb835732 is installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-12" comment="the HCP Protocol is registered" negate="true"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL905" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>Red Hat Enteprise Linux 3</product>
      </affected>
      <dates>
        <submitted date="2004-04-08-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <modified date="2004-05-11-12:00" comment="Corrected pattern used in rrt-206">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">INTERIM</status_change>
        <status_change date="2004-06-16-12:00">ACCEPTED</status_change>
      </dates>
      <description>Ethereal 0.10.1 to 0.10.2 allows remote attackers to cause a denial of service (crash) via a zero-length Presentation protocol selector.</description>
      <reference source="CVE">CVE-2004-0367</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="cmp-863" comment="Vulnerable Config" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-849" comment="Vulnerable Config" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL906" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Agent</product>
      </affected>
      <dates>
        <submitted date="2005-06-22-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2005-06-22-08:32">DRAFT</status_change>
        <modified date="2005-06-24-12:00" comment="added description">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </modified>
        <status_change date="2005-07-27-10:37">INTERIM</status_change>
        <status_change date="2005-08-18-07:37">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Agent allows remote attackers to spoof trusted Internet content and execute arbitrary code by disguising security prompts on a malicious Web page.</description>
      <reference source="CVE">CVE-2005-1214</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="cmp-200" comment=" a vulnerable version of agentdpv exists" negate="false"/>
          <criterion test_ref="wrt-64" comment="the patch kb890046 is installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL907" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>H.323</product>
      </affected>
      <dates>
        <submitted date="2004-04-13-12:00">
          <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
        </submitted>
        <status_change date="2004-05-05-12:00">INTERIM</status_change>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Unknown vulnerability in the H.323 protocol implementation in Windows 98, Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code.</description>
      <reference source="CVE">CVE-2004-0117</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
          <criterion test_ref="wft-150" comment="the version of h323.tsp is less than 5.0.2195.6901" negate="false"/>
          <criterion test_ref="wrt-187" comment="the patch kb835732 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL909" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>IIS 4.0</product>
      </affected>
      <dates>
        <submitted date="2004-05-04-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2004-05-25-12:00">INTERIM</status_change>
        <status_change date="2004-06-16-12:00">ACCEPTED</status_change>
      </dates>
      <description>IIS 5.0 uses relative paths to find system files that will run in-process, which allows local users to gain privileges via a Trojan horse file, aka the "System file listing privilege elevation" vulnerability.</description>
      <reference source="CVE">CVE-2001-0507</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-214" comment="IIS 4.0 Major Version" negate="false"/>
          <criterion test_ref="wrt-215" comment="IIS minor version equals 0" negate="false"/>
          <criterion test_ref="wft-304" comment="File %windir%\System32\w3svc.dll is less than 4.2.769.1" negate="false"/>
          <criterion test_ref="wrt-242" comment="Patch Q301625 Installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL910" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>NetWare</product>
      </affected>
      <dates>
        <submitted date="2005-10-12-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-10-19-05:46">DRAFT</status_change>
        <status_change date="2005-11-16-08:02">INTERIM</status_change>
        <status_change date="2005-12-01-06:00">ACCEPTED</status_change>
      </dates>
      <description>The Client Service for NetWare (CSNW) on Microsoft Windows 2000 SP4, XP SP1 and Sp2, and Server 2003 SP1 and earlier, allows remote attackers to execute arbitrary code due to an "unchecked buffer" when processing certain crafted network messages.</description>
      <reference source="CVE">CVE-2005-1985</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wrt-4" comment="Win2K/XP/2003 service pack 1 is installed" negate="false"/>
          <criterion test_ref="wft-673" comment="nwwks.dll is less than 5.2.3790.2506" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL911" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>Local Descriptor Table (LDT)</product>
      </affected>
      <dates>
        <submitted date="2004-04-13-12:00">
          <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
        </submitted>
        <status_change date="2004-05-05-12:00">INTERIM</status_change>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>The NtSetLdtEntries function in the programming interface for the Local Descriptor Table (LDT) in Windows NT 4.0 and Windows 2000 allows local attackers to gain access to kernel memory and execute arbitrary code via an expand-down data segment descriptor descriptor that points to protected memory.</description>
      <reference source="CVE">CVE-2003-0910</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" negate="false"/>
          <criterion test_ref="wft-190" comment="the version of wintrust.dll is less than 5.131.1880.14" negate="false"/>
          <criterion test_ref="wrt-187" comment="the patch kb835732 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL912" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>IIS 5.0</product>
      </affected>
      <dates>
        <submitted date="2004-05-04-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2004-05-25-12:00">INTERIM</status_change>
        <status_change date="2004-06-16-12:00">ACCEPTED</status_change>
        <modified date="2005-01-11-12:00" comment="modified wft-305 - changed the version of msw3prt.dll to test against from 5.5.2195.3649 to 5.0.2195.3649">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-01-20-01:05">INTERIM</status_change>
        <status_change date="2005-02-16-12:00">ACCEPTED</status_change>
      </dates>
      <description>IIS 5.0 uses relative paths to find system files that will run in-process, which allows local users to gain privileges via a Trojan horse file, aka the "System file listing privilege elevation" vulnerability.</description>
      <reference source="CVE">CVE-2001-0507</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-223" comment="IIS major version equals 5" negate="false"/>
          <criterion test_ref="wrt-215" comment="IIS minor version equals 0" negate="false"/>
          <criterion test_ref="wft-305" comment="File %windir%\System32\Msw3prt.dll is less than 5.0.2195.3649" negate="false"/>
          <criterion test_ref="wrt-242" comment="Patch Q301625 Installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL913" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>IIS 4.0</product>
      </affected>
      <dates>
        <submitted date="2004-05-04-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2004-05-25-12:00">INTERIM</status_change>
        <status_change date="2004-06-16-12:00">ACCEPTED</status_change>
      </dates>
      <description>In IIS, remote attackers can obtain source code for ASP files by appending "::$DATA" to the URL.</description>
      <reference source="CVE">CVE-1999-0278</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-214" comment="IIS 4.0 Major Version" negate="false"/>
          <criterion test_ref="wrt-215" comment="IIS minor version equals 0" negate="false"/>
          <criterion test_ref="wft-306" comment="File %windir%\System32\w3svc.dll is less than 4.0.1381.164" negate="false"/>
          <criterion test_ref="wrt-347" comment="Win2K/XP/2003 service pack 6 (or later) is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL914" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>Red Hat Enteprise Linux 3</product>
      </affected>
      <dates>
        <submitted date="2004-04-08-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-05-05-12:00">INTERIM</status_change>
        <modified date="2004-05-11-12:00" comment="Corrected pattern used in rrt-206">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Multiple vulnerabilities in multiple vendor implementations of the Secure/Multipurpose Internet Mail Extensions (S/MIME) protocol allow remote attackers to cause a denial of service and possibly execute arbitrary code via an S/MIME email message containing certain unexpected ASN.1 constructs, as demonstrated using the NISSC test suite.</description>
      <reference source="CVE">CVE-2003-0564</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-330" comment="mozilla-nss version is less than 1.4.2-3.0.2" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL915" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>IIS 4.0</product>
      </affected>
      <dates>
        <submitted date="2004-05-04-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2004-05-25-12:00">INTERIM</status_change>
        <status_change date="2004-06-16-12:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in IIS 4.0 allows remote attackers to cause a denial of service via a malformed request for files with .HTR, .IDC, or .STM extensions.</description>
      <reference source="CVE">CVE-1999-0874</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-214" comment="IIS 4.0 Major Version" negate="false"/>
          <criterion test_ref="wrt-215" comment="IIS minor version equals 0" negate="false"/>
          <criterion test_ref="wft-306" comment="File %windir%\System32\w3svc.dll is less than 4.0.1381.164" negate="false"/>
          <criterion test_ref="wrt-347" comment="Win2K/XP/2003 service pack 6 (or later) is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL916" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Exchange Server 2003</product>
      </affected>
      <dates>
        <submitted date="2005-06-06-12:00">
          <contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
        </submitted>
        <status_change date="2005-06-08-03:24">DRAFT</status_change>
        <status_change date="2005-06-29-06:49">INTERIM</status_change>
        <status_change date="2005-07-27-10:37">ACCEPTED</status_change>
      </dates>
      <description>IIS HTTP service uses Integrated Windows authentication.</description>
      <reference source="MISC">2.1.4</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <notes>
        <note>Corresponds to item 2.1.4 in the Exchange 2003 Benchmark</note>
      </notes>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wwt-1" comment="Integrated Windows Authentication is used for all directories" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL917" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>Red Hat Enteprise Linux 3</product>
      </affected>
      <dates>
        <submitted date="2004-04-08-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-05-05-12:00">INTERIM</status_change>
        <modified date="2004-05-11-12:00" comment="Corrected pattern used in rrt-206">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Mozilla allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Mozilla to send the cookie outside the specified URL subsets, e.g. to a vulnerable application that runs on the same server as the target application.</description>
      <reference source="CVE">CVE-2003-0594</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-330" comment="mozilla-nss version is less than 1.4.2-3.0.2" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL919" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Local Security Authority Subsystem Service (LSASS)</product>
      </affected>
      <dates>
        <submitted date="2004-04-13-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <status_change date="2004-05-05-12:00">INTERIM</status_change>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Stack-based buffer overflow in certain Active Directory service functions in LSASRV.DLL of the Local Security Authority Subsystem Service (LSASS) in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows 98, and Windows ME, allows remote attackers to execute arbitrary code via a packet that causes the DsRolerUpgradeDownlevelServer function to create long debug entries for the DCPROMO.LOG log file, as exploited by the Sasser worm.</description>
      <reference source="CVE">CVE-2003-0533</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wft-157" comment="the version of lsasrv.dll is less than 5.2.3790.134" negate="false"/>
          <criterion test_ref="wrt-187" comment="the patch kb835732 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL920" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 98</windows:platform>
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Internet Explorer 5.5, Internet Explorer 5.5 Service Pack 1</product>
      </affected>
      <dates>
        <submitted date="2004-04-29-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <status_change date="2004-05-25-12:00">INTERIM</status_change>
        <status_change date="2004-06-16-12:00">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 5.5 and earlier allows remote attackers to obtain the physical location of cached content and open the content in the Local Computer Zone, then use compiled HTML help (.chm) files to execute arbitrary programs.</description>
      <reference source="CVE">CVE-2001-0002</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-901" comment="Internet Explorer 5.5 Installed" negate="false"/>
          <criterion test_ref="wft-307" comment="File %windir%\system32\mshtml.dll version is less than 5.50.4613.1700" negate="false"/>
          <criterion test_ref="wrt-351" comment="Patch Q286045 Installed" negate="true"/>
          <criterion test_ref="wrt-352" comment="Patch Q295106 Installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL921" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 98</windows:platform>
        <windows:platform>Microsoft Windows ME</windows:platform>
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Internet Explorer 6</product>
      </affected>
      <dates>
        <submitted date="2004-04-29-04:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <status_change date="2004-05-25-04:00">INTERIM</status_change>
        <status_change date="2004-06-16-04:00">ACCEPTED</status_change>
        <status_change date="2004-09-22-04:00">INTERIM</status_change>
        <modified date="2004-09-22-04:01" comment="Replaced IE cumulative patch IDs to correspond to the original IDs">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </modified>
        <status_change date="2004-10-06-04:00">ACCEPTED</status_change>
        <modified date="2005-09-20-04:00" comment="Changed IE registry test to wrt-18">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-21-01:27">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 6.0 allows remote attackers to execute arbitrary code by modifying the Content-Disposition and Content-Type header fields in a way that causes Internet Explorer to believe that the file is safe to open without prompting the user, aka the "File Execution Vulnerability."</description>
      <reference source="CVE">CVE-2001-0727</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wft-308" comment="the version of mshtml.dll is less than 6.0.2712.0300" negate="false"/>
          <criterion test_ref="wrt-354" comment="Patch Q313675 Installed" negate="true"/>
          <criterion test_ref="wrt-355" comment="Patch Q316059.exe Installed" negate="true"/>
          <criterion test_ref="wrt-356" comment="Patch Q319282 Installed" negate="true"/>
          <criterion test_ref="wrt-204" comment="the patch q321232 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-205" comment="the patch q323759 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-206" comment="the patch q328970 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-207" comment="the patch q324929 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-208" comment="the patch q810847 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-209" comment="the patch q813489 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-210" comment="the patch q818529 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-211" comment="the patch q822925 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-212" comment="the patch q828750 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-19" comment="the patch q824145 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-141" comment="the patch q832894 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-18" comment="Internet Explorer 6 is installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-902" comment="File Downloads Not Disabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL922" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 98</windows:platform>
        <windows:platform>Microsoft Windows ME</windows:platform>
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Internet Explorer 5.5</product>
      </affected>
      <dates>
        <submitted date="2004-04-29-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <status_change date="2004-05-25-12:00">INTERIM</status_change>
        <status_change date="2004-06-16-12:00">ACCEPTED</status_change>
        <status_change date="2004-09-22-12:00">INTERIM</status_change>
        <modified date="2004-09-22-11:10" comment="Replaced IE cumulative patch IDs to correspond to the original IDs">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </modified>
        <status_change date="2004-10-06-12:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to execute arbitrary code via / (slash) characters in the Type property of an Object tag in a web page.</description>
      <reference source="CVE">CVE-2003-0344</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-53" comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false"/>
          <criterion test_ref="wft-309" comment="the version of mshtml.dll is less than 5.50.4926.2500" negate="false"/>
          <criterion test_ref="wrt-210" comment="the patch q818529 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-211" comment="the patch q822925 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-212" comment="the patch q828750 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-19" comment="the patch q824145 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-141" comment="the patch q832894 is installed (Installed Components key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL923" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 98</windows:platform>
        <windows:platform>Microsoft Windows ME</windows:platform>
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Internet Explorer 6</product>
      </affected>
      <dates>
        <submitted date="2004-04-30-04:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <status_change date="2004-05-25-04:00">INTERIM</status_change>
        <status_change date="2004-06-16-04:00">ACCEPTED</status_change>
        <status_change date="2004-09-22-04:00">INTERIM</status_change>
        <modified date="2004-09-22-04:01" comment="Replaced IE cumulative patch IDs to correspond to the original IDs">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </modified>
        <status_change date="2004-10-06-04:00">ACCEPTED</status_change>
        <modified date="2005-09-20-04:00" comment="Changed IE registry test to wrt-18">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-21-01:27">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to execute arbitrary code under fewer security restrictions via a malformed web page that requires NetBIOS connectivity, aka "Zone Spoofing through Malformed Web Page" vulnerability.</description>
      <reference source="CVE">CVE-2002-0190</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wft-310" comment="File %windir%\system32\mshtml.dll version is less than 6.0.2716.2200" negate="false"/>
          <criterion test_ref="wrt-204" comment="the patch q321232 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-205" comment="the patch q323759 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-206" comment="the patch q328970 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-207" comment="the patch q324929 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-208" comment="the patch q810847 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-209" comment="the patch q813489 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-210" comment="the patch q818529 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-211" comment="the patch q822925 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-212" comment="the patch q828750 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-19" comment="the patch q824145 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-141" comment="the patch q832894 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-18" comment="Internet Explorer 6 is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL924" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft ASN.1 Library</product>
      </affected>
      <dates>
        <submitted date="2004-04-13-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
        <status_change date="2004-05-05-12:00">INTERIM</status_change>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Double-free vulnerability in the ASN.1 library as used in Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service and possibly execute arbitrary code.</description>
      <reference source="CVE">CVE-2004-0123</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wft-194" comment="the version of msasn1.dll is less than 5.2.3790.139" negate="false"/>
          <criterion test_ref="wrt-187" comment="the patch kb835732 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL925" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 98</windows:platform>
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Internet Explorer 6</product>
      </affected>
      <dates>
        <submitted date="2004-04-29-04:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <status_change date="2004-05-25-04:00">INTERIM</status_change>
        <status_change date="2004-06-16-04:00">ACCEPTED</status_change>
        <status_change date="2004-09-22-04:00">INTERIM</status_change>
        <modified date="2004-09-22-04:01" comment="Replaced IE cumulative patch IDs to correspond to the original IDs">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </modified>
        <status_change date="2004-10-06-04:00">ACCEPTED</status_change>
        <modified date="2005-09-20-04:00" comment="Changed IE registry test to wrt-18">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-21-01:27">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the implementation of an HTML directive in mshtml.dll in Internet Explorer 5.5 and 6.0 allows remote attackers to execute arbitrary code via a web page that specifies embedded ActiveX controls in a way that causes 2 Unicode strings to be concatenated.</description>
      <reference source="CVE">CVE-2002-0022</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wft-311" comment="File %windir%\system32\mshtml.dll version is less than 6.0.2713.1100" negate="false"/>
          <criterion test_ref="wrt-355" comment="Patch Q316059.exe Installed" negate="true"/>
          <criterion test_ref="wrt-356" comment="Patch Q319282 Installed" negate="true"/>
          <criterion test_ref="wrt-204" comment="the patch q321232 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-205" comment="the patch q323759 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-206" comment="the patch q328970 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-207" comment="the patch q324929 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-208" comment="the patch q810847 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-209" comment="the patch q813489 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-210" comment="the patch q818529 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-211" comment="the patch q822925 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-212" comment="the patch q828750 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-19" comment="the patch q824145 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-141" comment="the patch q832894 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-18" comment="Internet Explorer 6 is installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-903" comment="Run ActiveX Controls and Plugins Not Disabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL926" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 98</windows:platform>
        <windows:platform>Microsoft Windows ME</windows:platform>
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Internet Explorer 5.5</product>
      </affected>
      <dates>
        <submitted date="2004-04-30-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <status_change date="2004-05-25-12:00">INTERIM</status_change>
        <status_change date="2004-06-16-12:00">ACCEPTED</status_change>
        <status_change date="2004-09-22-12:00">INTERIM</status_change>
        <modified date="2004-09-22-11:10" comment="Replaced IE cumulative patch IDs to correspond to the original IDs">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </modified>
        <status_change date="2004-10-06-12:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in URLMON.DLL in Microsoft Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to execute arbitrary code via an HTTP response containing long values in (1) Content-type and (2) Content-encoding fields.</description>
      <reference source="CVE">CVE-2003-0113</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-53" comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false"/>
          <criterion test_ref="wft-309" comment="the version of mshtml.dll is less than 5.50.4926.2500" negate="false"/>
          <criterion test_ref="wft-312" comment="File %windir%\system32\urlmon.dll version is less than 5.50.4927.2100" negate="false"/>
          <criterion test_ref="wrt-209" comment="the patch q813489 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-210" comment="the patch q818529 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-211" comment="the patch q822925 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-212" comment="the patch q828750 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-19" comment="the patch q824145 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-141" comment="the patch q832894 is installed (Installed Components key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL927" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>IIS 5.0</product>
      </affected>
      <dates>
        <submitted date="2004-05-04-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2004-05-25-12:00">INTERIM</status_change>
        <status_change date="2004-06-16-12:00">ACCEPTED</status_change>
      </dates>
      <description>IIS 5.0 allows remote attackers to obtain source code for .ASP files and other scripts via an HTTP GET request with a "Translate: f" header, aka the "Specialized Header" vulnerability.</description>
      <reference source="CVE">CVE-2000-0778</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-223" comment="IIS major version equals 5" negate="false"/>
          <criterion test_ref="wrt-215" comment="IIS minor version equals 0" negate="false"/>
          <criterion test_ref="wrt-4" comment="Win2K/XP/2003 service pack 1 is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL928" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>OpenSSL</product>
      </affected>
      <dates>
        <submitted date="2004-03-20-12:00">
          <contributor organization="The MITRE Corporation">Matt Busby</contributor>
        </submitted>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Matt Busby</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">INTERIM</status_change>
        <status_change date="2004-06-16-12:00">ACCEPTED</status_change>
      </dates>
      <description>The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, which allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that causes an out-of-bounds read.</description>
      <reference source="CVE">CVE-2004-0112</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-312" comment="openssl version is less than 0.9.7a-33.4" negate="false"/>
          <criterion test_ref="rvt-313" comment="openssl-devel version is less than 0.9.7a-33.4" negate="false"/>
          <criterion test_ref="rvt-314" comment="openssl-perl version is less than 0.9.7a-33.4" negate="false"/>
          <criterion test_ref="rvt-315" comment="openssl096b version is less than 0.9.6b-16" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL929" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>IIS 4.0</product>
      </affected>
      <dates>
        <submitted date="2004-05-12-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2004-06-16-12:00">INTERIM</status_change>
        <status_change date="2004-06-30-12:00">ACCEPTED</status_change>
      </dates>
      <description>Unknown vulnerability in the hosting process (dllhost.exe) for Microsoft Internet Information Server (IIS) 4.0 through 5.1 allows remote attackers to gain privileges by executing an out of process application that acquires LocalSystem privileges, aka "Out of Process Privilege Elevation."</description>
      <reference source="CVE">CVE-2002-0869</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-214" comment="IIS 4.0 Major Version" negate="false"/>
          <criterion test_ref="wrt-215" comment="IIS minor version equals 0" negate="false"/>
          <criterion test_ref="wft-329" comment="File %windir%\System32\w3svc.dll is less than 4.2.780.1" negate="false"/>
          <criterion test_ref="wrt-218" comment="Patch Q327696 Installed" negate="true"/>
          <criterion test_ref="wrt-219" comment="Patch Q811114 Installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL930" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>IIS 5.0</product>
      </affected>
      <dates>
        <submitted date="2004-05-12-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2004-06-16-12:00">INTERIM</status_change>
        <status_change date="2004-06-30-12:00">ACCEPTED</status_change>
        <modified date="2005-01-11-12:00" comment="modified wft-330 - changed the version of msw3prt.dll to test against from 5.5.2195.58075 to 5.0.2195.5807">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-01-20-01:08">INTERIM</status_change>
        <status_change date="2005-02-16-12:00">ACCEPTED</status_change>
      </dates>
      <description>Unknown vulnerability in the hosting process (dllhost.exe) for Microsoft Internet Information Server (IIS) 4.0 through 5.1 allows remote attackers to gain privileges by executing an out of process application that acquires LocalSystem privileges, aka "Out of Process Privilege Elevation."</description>
      <reference source="CVE">CVE-2002-0869</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-223" comment="IIS major version equals 5" negate="false"/>
          <criterion test_ref="wrt-215" comment="IIS minor version equals 0" negate="false"/>
          <criterion test_ref="wft-330" comment="File %windir%\System32\msw3prt.dll is less than 5.0.2195.5807" negate="false"/>
          <criterion test_ref="wrt-218" comment="Patch Q327696 Installed" negate="true"/>
          <criterion test_ref="wrt-219" comment="Patch Q811114 Installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL931" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>IIS 5.0</product>
      </affected>
      <dates>
        <submitted date="2004-05-12-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2004-06-16-12:00">INTERIM</status_change>
        <status_change date="2004-06-30-12:00">ACCEPTED</status_change>
        <modified date="2005-01-11-12:00" comment="modified wft-330 - changed the version of msw3prt.dll to test against from 5.5.2195.58075 to 5.0.2195.5807">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-01-20-01:08">INTERIM</status_change>
        <status_change date="2005-02-16-12:00">ACCEPTED</status_change>
      </dates>
      <description>A typographical error in the script source access permissions for Internet Information Server (IIS) 5.0 does not properly exclude .COM files, which allows attackers with only write permissions to upload malicious .COM files, aka "Script Source Access Vulnerability."</description>
      <reference source="CVE">CVE-2002-1180</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-223" comment="IIS major version equals 5" negate="false"/>
          <criterion test_ref="wrt-215" comment="IIS minor version equals 0" negate="false"/>
          <criterion test_ref="wft-330" comment="File %windir%\System32\msw3prt.dll is less than 5.0.2195.5807" negate="false"/>
          <criterion test_ref="wrt-218" comment="Patch Q327696 Installed" negate="true"/>
          <criterion test_ref="wrt-219" comment="Patch Q811114 Installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL932" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>IIS 4.0</product>
      </affected>
      <dates>
        <submitted date="2004-05-17-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2004-06-16-12:00">INTERIM</status_change>
        <status_change date="2004-06-30-12:00">ACCEPTED</status_change>
      </dates>
      <description>The showcode.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files.</description>
      <reference source="CVE">CVE-1999-0736</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-214" comment="IIS 4.0 Major Version" negate="false"/>
          <criterion test_ref="wrt-215" comment="IIS minor version equals 0" negate="false"/>
          <criterion test_ref="wft-331" comment="File %windir%\System32\code.asp is less than 4.0.1381.279" negate="false"/>
          <criterion test_ref="wrt-386" comment="Patch Q232449 Installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL933" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>IIS 5.0</product>
      </affected>
      <dates>
        <submitted date="2004-05-17-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2004-06-16-12:00">INTERIM</status_change>
        <status_change date="2004-06-30-12:00">ACCEPTED</status_change>
        <modified date="2005-09-27-10:43" comment="modified wft-332 - Changed test to match comment">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-28-01:04">INTERIM</status_change>
        <status_change date="2005-10-19-05:47">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Internet Information Services (IIS) 5.0 and 5.1 allows remote attackers to cause a denial of service via a long WebDAV request with a (1) PROPFIND or (2) SEARCH method, which generates an error condition that is not properly handled.</description>
      <reference source="CVE">CVE-2003-0226</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-223" comment="IIS major version equals 5" negate="false"/>
          <criterion test_ref="wrt-215" comment="IIS minor version equals 0" negate="false"/>
          <criterion test_ref="wft-332" comment="File %windir%\System32\w3svc.dll is less than 5.0.2195.6672" negate="false"/>
          <criterion test_ref="wrt-387" comment="Patch Q811114 Installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL934" class="compliance">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Exchange Server 2003</product>
      </affected>
      <dates>
        <submitted date="2005-06-07-12:00">
          <contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
        </submitted>
        <status_change date="2005-06-08-03:24">DRAFT</status_change>
        <status_change date="2005-06-29-06:49">INTERIM</status_change>
        <status_change date="2005-07-27-10:37">ACCEPTED</status_change>
      </dates>
      <description>Review block-list Exception list entries</description>
      <reference source="MISC">1.2.3</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wat-4" comment="Review block-list exception values" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL935" class="vulnerability">
      <affected family="hp-ux">
        <hpux:platform>HP-UX 11</hpux:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2006-02-01-11:45">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-03-09-12:19">DRAFT</status_change>
        <status_change date="2006-04-06-06:30">INTERIM</status_change>
        <status_change date="2006-05-03-10:06">ACCEPTED</status_change>
      </dates>
      <description>Unknown vulnerability in HP-UX B.11.00, B.11.04, B.11.11, B.11.22, and B.11.23, when running TCP/IP on IPv4, allows remote attackers to cause a denial of service via certain packets, related to the PMTU, a different vulnerability than CVE-2004-1060.</description>
      <reference source="CVE">CVE-2005-1192</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-682" comment="700 Series or 800 Series OS Release 11.23" negate="false"/>
          <criterion test_ref="hst-57" comment="Networking.NET2-KRN is installed" negate="false"/>
          <criterion test_ref="hpt-23" comment="Patch PHNE_32606 or later is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL936" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>IIS 5.0</product>
      </affected>
      <dates>
        <submitted date="2004-05-18-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2004-06-16-12:00">INTERIM</status_change>
        <status_change date="2004-06-30-12:00">ACCEPTED</status_change>
      </dates>
      <description>The logging capability for unicast and multicast transmissions in the ISAPI extension for Microsoft Windows Media Services in Microsoft Windows NT 4.0 and 2000, nsiislog.dll, allows remote attackers to cause a denial of service in Internet Information Server (IIS) and execute arbitrary code via a certain network request.</description>
      <reference source="CVE">CVE-2003-0227</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-223" comment="IIS major version equals 5" negate="false"/>
          <criterion test_ref="wrt-215" comment="IIS minor version equals 0" negate="false"/>
          <criterion test_ref="wft-333" comment="File %windir%\System32\nsiislog.dll is less than 4.1.0.3931" negate="false"/>
          <criterion test_ref="wrt-388" comment="Patch KB817772 Installed" negate="true"/>
          <criterion test_ref="wrt-389" comment="Patch KB822343 Installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL937" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>Red Hat Enteprise Linux 3</product>
      </affected>
      <dates>
        <submitted date="2004-04-08-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-05-05-12:00">INTERIM</status_change>
        <modified date="2004-05-11-12:00" comment="Corrected pattern used in rrt-206">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Mozilla before 1.4.2 executes Javascript events in the context of a new page while it is being loaded, allowing it to interact with the previous page (zombie document) and enable cross-domain and cross-site scripting (XSS) attacks, as demonstrated using onmousemove events.</description>
      <reference source="CVE">CVE-2004-0191</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-330" comment="mozilla-nss version is less than 1.4.2-3.0.2" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL938" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>IIS 5.0</product>
      </affected>
      <dates>
        <submitted date="2004-05-18-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2004-06-16-12:00">INTERIM</status_change>
        <status_change date="2004-06-30-12:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the streaming media component for logging multicast requests in the ISAPI for the logging capability of Microsoft Windows Media Services (nsiislog.dll), as installed in IIS 5.0, allows remote attackers to execute arbitrary code via a large POST request to nsiislog.dll.</description>
      <reference source="CVE">CVE-2003-0349</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-223" comment="IIS major version equals 5" negate="false"/>
          <criterion test_ref="wrt-215" comment="IIS minor version equals 0" negate="false"/>
          <criterion test_ref="wft-334" comment="File %windir%\System32\nsiislog.dll is less than 4.1.0.3932" negate="false"/>
          <criterion test_ref="wrt-389" comment="Patch KB822343 Installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL939" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>Red Hat Enteprise Linux 3</product>
      </affected>
      <dates>
        <submitted date="2004-05-10-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-05-25-12:00">INTERIM</status_change>
        <status_change date="2004-06-16-12:00">ACCEPTED</status_change>
      </dates>
      <description>Integer overflow in the ip_setsockopt function in Linux kernel 2.4.22 through 2.4.25 and 2.6.1 through 2.6.3 allows local users to cause a denial of service (crash) or execute arbitrary code via the MCAST_MSFILTER socket option.</description>
      <reference source="CVE">CVE-2004-0424</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="cmp-921" comment="kernel versions" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL940" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>Red Hat Enteprise Linux 3</product>
      </affected>
      <dates>
        <submitted date="2004-05-10-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-05-25-12:00">INTERIM</status_change>
        <status_change date="2004-06-16-12:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the ISO9660 file system component for Linux kernel 2.4.x, 2.5.x and 2.6.x , allows local users with physical access to overflow kernel memory and execute arbitrary code via a malformed CD containing a long symbolic link entry.</description>
      <reference source="CVE">CVE-2004-0109</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="cmp-921" comment="kernel versions" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-923" comment="/bin/mount is world-executable AND Set-UID" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL941" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>Red Hat Enteprise Linux 3</product>
      </affected>
      <dates>
        <submitted date="2004-05-10-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-05-25-12:00">INTERIM</status_change>
        <status_change date="2004-06-16-12:00">ACCEPTED</status_change>
      </dates>
      <description>The "%xx" URL decoding function in Squid 2.5STABLE4 and earlier allows remote attackers to bypass url_regex ACLs via a URL with a NULL ("%00") characterm, which causes Squid to use only a portion of the requested URL when comparing it against the access control lists.</description>
      <reference source="CVE">CVE-2004-0189</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-337" comment="squid version is less than 2.5.STABLE3-5.3E" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="rlt-225" comment="squid is listening on the network" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL942" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>IIS 5.0</product>
      </affected>
      <dates>
        <submitted date="2004-05-12-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2004-06-16-12:00">INTERIM</status_change>
        <status_change date="2004-06-30-12:00">ACCEPTED</status_change>
        <modified date="2005-01-11-12:00" comment="modified wft-330 - changed the version of msw3prt.dll to test against from 5.5.2195.58075 to 5.0.2195.5807">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-01-20-01:13">INTERIM</status_change>
        <status_change date="2005-02-16-12:00">ACCEPTED</status_change>
      </dates>
      <description>Multiple cross-site scripting (XSS) vulnerabilities in the administrative web pages for Microsoft Internet Information Server (IIS) 4.0 through 5.1 allow remote attackers to execute HTML script as other users through (1) a certain ASP file in the IISHELP virtual directory, or (2) possibly other unknown attack vectors.</description>
      <reference source="CVE">CVE-2002-1181</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-223" comment="IIS major version equals 5" negate="false"/>
          <criterion test_ref="wrt-215" comment="IIS minor version equals 0" negate="false"/>
          <criterion test_ref="wft-330" comment="File %windir%\System32\msw3prt.dll is less than 5.0.2195.5807" negate="false"/>
          <criterion test_ref="wrt-218" comment="Patch Q327696 Installed" negate="true"/>
          <criterion test_ref="wrt-219" comment="Patch Q811114 Installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL944" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>IIS 4.0</product>
      </affected>
      <dates>
        <submitted date="2004-05-12-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2004-06-16-12:00">INTERIM</status_change>
        <status_change date="2004-06-30-12:00">ACCEPTED</status_change>
      </dates>
      <description>Multiple cross-site scripting (XSS) vulnerabilities in the administrative web pages for Microsoft Internet Information Server (IIS) 4.0 through 5.1 allow remote attackers to execute HTML script as other users through (1) a certain ASP file in the IISHELP virtual directory, or (2) possibly other unknown attack vectors.</description>
      <reference source="CVE">CVE-2002-1181</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-214" comment="IIS 4.0 Major Version" negate="false"/>
          <criterion test_ref="wrt-215" comment="IIS minor version equals 0" negate="false"/>
          <criterion test_ref="wft-329" comment="File %windir%\System32\w3svc.dll is less than 4.2.780.1" negate="false"/>
          <criterion test_ref="wrt-218" comment="Patch Q327696 Installed" negate="true"/>
          <criterion test_ref="wrt-219" comment="Patch Q811114 Installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL945" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>Red Hat Enteprise Linux 3</product>
      </affected>
      <dates>
        <submitted date="2004-05-12-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-06-16-12:00">INTERIM</status_change>
        <status_change date="2004-06-30-12:00">ACCEPTED</status_change>
      </dates>
      <description>The KAME IKE Daemon Racoon, when authenticating a peer during Phase 1, validates the X.509 certificate but does not verify the RSA signature authentication, which allows remote attackers to establish unauthorized IP connections or conduct man-in-the-middle attacks using a valid, trusted X.509 certificate.</description>
      <reference source="CVE">CVE-2004-0155</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-338" comment="ipsec-tools version is less than 0.2.5-0.4" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="rlt-230" comment="racoon is listening on the network" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL946" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>H.323</product>
      </affected>
      <dates>
        <submitted date="2004-04-13-12:00">
          <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
        </submitted>
        <status_change date="2004-05-05-12:00">INTERIM</status_change>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Unknown vulnerability in the H.323 protocol implementation in Windows 98, Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code.</description>
      <reference source="CVE">CVE-2004-0117</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wft-151" comment="the version of h323.tsp is less than 5.2.3790.132" negate="false"/>
          <criterion test_ref="wrt-187" comment="the patch kb835732 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL947" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>Red Hat Enteprise Linux 3</product>
      </affected>
      <dates>
        <submitted date="2004-05-12-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-06-16-12:00">INTERIM</status_change>
        <status_change date="2004-06-30-12:00">ACCEPTED</status_change>
      </dates>
      <description>KAME IKE daemon (racoon) does not properly handle hash values, which allows remote attackers to delete certificates via (1) a certain delete message that is not properly handled in isakmp.c or isakmp_inf.c, or (2) a certain INITIAL-CONTACT message that is not properly handled in isakmp_inf.c.</description>
      <reference source="CVE">CVE-2004-0164</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-338" comment="ipsec-tools version is less than 0.2.5-0.4" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="rlt-230" comment="racoon is listening on the network" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL948" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 98</windows:platform>
        <windows:platform>Microsoft Windows ME</windows:platform>
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Internet Explorer 5.5</product>
      </affected>
      <dates>
        <submitted date="2004-04-29-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <status_change date="2004-05-25-12:00">INTERIM</status_change>
        <status_change date="2004-06-16-12:00">ACCEPTED</status_change>
        <status_change date="2004-09-22-12:00">INTERIM</status_change>
        <modified date="2004-09-22-11:10" comment="Replaced IE cumulative patch IDs to correspond to the original IDs">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </modified>
        <status_change date="2004-10-06-12:00">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to bypass security zone restrictions and execute arbitrary programs via a web document with a large number of duplicate file:// or other requests that point to the program and open multiple file download dialogs, which eventually cause Internet Explorer to execute the program, as demonstrated using a large number of FRAME or IFRAME tags, aka the "File Download Dialog Vulnerability."</description>
      <reference source="CVE">CVE-2003-0309</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-53" comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false"/>
          <criterion test_ref="wft-309" comment="the version of mshtml.dll is less than 5.50.4926.2500" negate="false"/>
          <criterion test_ref="wrt-210" comment="the patch q818529 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-211" comment="the patch q822925 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-212" comment="the patch q828750 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-19" comment="the patch q824145 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-141" comment="the patch q832894 is installed (Installed Components key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL951" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Private Communications Transport (PCT)</product>
      </affected>
      <dates>
        <submitted date="2004-04-13-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <status_change date="2004-05-05-12:00">INTERIM</status_change>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the Private Communications Transport (PCT) protocol implementation in the Microsoft SSL library, as used in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows 98, and Windows ME, allows remote attackers to execute arbitrary code via PCT 1.0 handshake packets.</description>
      <reference source="CVE">CVE-2003-0719</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
          <criterion test_ref="wft-171" comment="the version of schannel.dll is less than 5.1.2195.6899" negate="false"/>
          <criterion test_ref="wrt-187" comment="the patch kb835732 is installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wmt-5" comment="SSL is enabled" negate="false"/>
          <criterion test_ref="wrt-165" comment="PCT support is disabled" negate="true"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL952" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>SNMP</product>
      </affected>
      <dates>
        <submitted date="2004-05-04-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2004-05-25-12:00">INTERIM</status_change>
        <status_change date="2004-06-16-12:00">ACCEPTED</status_change>
        <modified date="2005-03-14-12:00" comment="Switched the service pack test from wrt-373 to wrt-539.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <status_change date="2005-04-11-08:48">INTERIM</status_change>
        <status_change date="2005-04-27-12:07">ACCEPTED</status_change>
      </dates>
      <description>Memory leak in SNMP agent in Windows NT 4.0 before SP5 allows remote attackers to conduct a denial of service (memory exhaustion) via a large number of queries.</description>
      <reference source="CVE">CVE-1999-0815</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" negate="false"/>
          <criterion test_ref="wft-313" comment="File %windir%\system32\snmp.exe is less than 4.0.1381.133" negate="false"/>
          <criterion test_ref="wrt-539" comment="Win2K/XP/2003 service pack 5 (or later) is installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-264" comment="the SNMP service is enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL954" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>Red Hat Enteprise Linux 3</product>
      </affected>
      <dates>
        <submitted date="2004-05-19-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-06-16-12:00">INTERIM</status_change>
        <status_change date="2004-06-30-12:00">ACCEPTED</status_change>
      </dates>
      <description>The URI handlers in Konqueror for KDE 3.2.2 and earlier do not properly filter "-" characters that begin a hostname in a (1) telnet, (2) rlogin, (3) ssh, or (4) mailto URI, which allows remote attackers to manipulate the options that are passed to the associated programs, possibly to read arbitrary files or execute arbitrary code.</description>
      <reference source="CVE">CVE-2004-0411</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-339" comment="kdelibs version is less than 3.1.3-6.4" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-924" comment="telnet, rlogin, ssh or kmail is executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL955" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Remote Procedure Call (RPC)</product>
      </affected>
      <dates>
        <submitted date="2004-04-20-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2004-05-25-12:00">INTERIM</status_change>
        <status_change date="2004-06-16-12:00">ACCEPTED</status_change>
      </dates>
      <description>An Activation function in the RPCSS Service involved with DCOM activation for Microsoft Windows 2000, XP, and 2003 allows remote attackers to cause a denial of service (memory consumption) via an activation request with a large length field.</description>
      <reference source="CVE">CVE-2004-0116</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
          <criterion test_ref="wft-189" comment="the version of rpcss.dll is less than 5.0.2195.6906" negate="false"/>
          <criterion test_ref="wrt-189" comment="the patch kb828741 is installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-7" comment="DCOM is enabled on systems with SP3 or later" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL956" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>HTML Help Facility</product>
      </affected>
      <dates>
        <submitted date="2004-07-14-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <status_change date="2004-08-04-12:00">INTERIM</status_change>
        <status_change date="2004-08-25-12:00">ACCEPTED</status_change>
        <modified date="2005-05-10-12:00" comment="modified wrt-51 - Comment updated to indicate IE 6.">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </modified>
        <status_change date="2005-05-11-05:33">INTERIM</status_change>
        <status_change date="2005-06-01-03:30">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 5.x and 6.0 allows remote attackers to execute arbitrary programs via a modified directory traversal attack using a URL containing ".." (dot dot) sequences and a filename that ends in "::" which is treated as a .chm file even if it does not have a .chm extension.  NOTE: this bug may overlap CVE-2004-0475.</description>
      <reference source="CVE">CVE-2003-1041</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" negate="false"/>
          <criterion test_ref="cmp-1071" comment="Internet Explorer 5.5 SP2 or Internet Explorer 6.0 SP1 is installed" negate="false"/>
          <criterion test_ref="wft-444" comment="the version of itss.dll is less than 5.2.3790.185" negate="false"/>
          <criterion test_ref="wrt-482" comment="the patch kb840315 is installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-491" comment="HTML Help is registered" negate="true"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL957" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Remote Procedure Call (RPC)</product>
      </affected>
      <dates>
        <submitted date="2004-04-20-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <modified date="2005-09-27-11:12" comment="modified wft-199 - Changed comment to match test">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
      </dates>
      <description>An Activation function in the RPCSS Service involved with DCOM activation for Microsoft Windows 2000, XP, and 2003 allows remote attackers to cause a denial of service (memory consumption) via an activation request with a large length field.</description>
      <reference source="CVE">CVE-2004-0116</reference>
      <status>DRAFT</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="cmp-16" comment="a vulnerable version of rpcss.dll exists on Server 2003" negate="false"/>
          <criterion test_ref="wrt-189" comment="the patch kb828741 is installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-283" comment="DCOM is enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL958" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Remote Procedure Call (RPC)</product>
      </affected>
      <dates>
        <submitted date="2004-04-20-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2004-05-25-12:00">INTERIM</status_change>
        <status_change date="2004-06-16-12:00">ACCEPTED</status_change>
        <modified date="2004-09-13-11:22" comment="cmp-66 added">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2004-09-15-12:00">INTERIM</status_change>
        <status_change date="2004-09-29-12:00">ACCEPTED</status_change>
      </dates>
      <description>An Activation function in the RPCSS Service involved with DCOM activation for Microsoft Windows 2000, XP, and 2003 allows remote attackers to cause a denial of service (memory consumption) via an activation request with a large length field.</description>
      <reference source="CVE">CVE-2004-0116</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-10" comment="a vulnerable version of rpcss.dll exists on XP" negate="false"/>
          <criterion test_ref="wrt-189" comment="the patch kb828741 is installed" negate="true"/>
          <criterion test_ref="cmp-66" comment="Windows XP (sp1 or earlier) is installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-283" comment="DCOM is enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL959" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Enhanced Metafile (EMF)</product>
        <product>Windows Metafile (WMF)</product>
      </affected>
      <dates>
        <submitted date="2004-04-13-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <status_change date="2004-05-05-12:00">INTERIM</status_change>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the rendering for (1) Windows Metafile (WMF) or (2) Enhanced Metafile (EMF) image formats in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, and XP SP1 allows remote attackers to execute arbitrary code via a malformed WMF or EMF image.</description>
      <reference source="CVE">CVE-2003-0906</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
          <criterion test_ref="wft-138" comment="the version of mf3216.dll is less than 5.0.2195.6898" negate="false"/>
          <criterion test_ref="wrt-187" comment="the patch kb835732 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL960" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>ImageMagick</product>
      </affected>
      <dates>
        <submitted date="2005-07-11-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2005-07-27-10:36">DRAFT</status_change>
        <status_change date="2005-08-18-07:37">INTERIM</status_change>
        <status_change date="2005-09-21-01:33">ACCEPTED</status_change>
      </dates>
      <description>The XWD Decoder in ImageMagick before 6.2.2.3, and GraphicsMagick before 1.1.6-r1, allows remote attackers to cause a denial of service (infinite loop) via an image with a zero color mask.</description>
      <reference source="CVE">CVE-2005-1739</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="rvt-23" comment="ImageMagick RPM earlier than 0:5.5.6-15" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL961" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 95</windows:platform>
        <windows:platform>Microsoft Windows 98</windows:platform>
        <windows:platform>Microsoft Windows ME</windows:platform>
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>MDAC 2.5</product>
      </affected>
      <dates>
        <submitted date="2004-05-04-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2004-05-25-12:00">INTERIM</status_change>
        <status_change date="2004-06-16-12:00">ACCEPTED</status_change>
        <modified date="2005-02-28-12:00" comment="split out the MDAC and file version tests from the compound test">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-03-02-08:52">INTERIM</status_change>
        <status_change date="2005-03-23-08:09">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in a component of SQL-DMO for Microsoft Data Access Components (MDAC) 2.5 through 2.7 allows remote attackers to execute arbitrary code via a long response to a broadcast request to UDP port 1434.</description>
      <reference source="CVE">CVE-2003-0353</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-100" comment="MDAC 2.5 is installed" negate="false"/>
          <criterion test_ref="wft-314" comment="File %windir%\System32\odbcbcp.dll is less than 3.70.11.40" negate="false"/>
          <criterion test_ref="wrt-376" comment="Patch Q823718 Installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL962" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Microsoft Data Access Components 2.6</product>
      </affected>
      <dates>
        <submitted date="2004-05-04-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2004-05-25-12:00">INTERIM</status_change>
        <status_change date="2004-06-16-12:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in a component of SQL-DMO for Microsoft Data Access Components (MDAC) 2.5 through 2.7 allows remote attackers to execute arbitrary code via a long response to a broadcast request to UDP port 1434.</description>
      <reference source="CVE">CVE-2003-0353</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-377" comment="DataAccess Installed" negate="false"/>
          <criterion test_ref="wft-315" comment="File %windir%\System32\odbcbcp.dll is less than 2000.80.746.0" negate="false"/>
          <criterion test_ref="wrt-376" comment="Patch Q823718 Installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL963" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 98</windows:platform>
        <windows:platform>Microsoft Windows ME</windows:platform>
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Internet Explorer 5.5</product>
      </affected>
      <dates>
        <submitted date="2004-04-30-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <status_change date="2004-05-25-12:00">INTERIM</status_change>
        <status_change date="2004-06-16-12:00">ACCEPTED</status_change>
        <status_change date="2004-09-22-12:00">INTERIM</status_change>
        <modified date="2004-09-22-11:10" comment="Replaced IE cumulative patch IDs to correspond to the original IDs">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </modified>
        <status_change date="2004-10-06-12:00">ACCEPTED</status_change>
      </dates>
      <description>The file upload control in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to automatically upload files from the local system via a web page containing a script to upload the files.</description>
      <reference source="CVE">CVE-2003-0114</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-53" comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false"/>
          <criterion test_ref="wft-309" comment="the version of mshtml.dll is less than 5.50.4926.2500" negate="false"/>
          <criterion test_ref="wrt-209" comment="the patch q813489 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-210" comment="the patch q818529 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-211" comment="the patch q822925 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-212" comment="the patch q828750 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-19" comment="the patch q824145 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-141" comment="the patch q832894 is installed (Installed Components key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL964" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>H.323</product>
      </affected>
      <dates>
        <submitted date="2004-04-13-12:00">
          <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
        </submitted>
        <status_change date="2004-05-05-12:00">INTERIM</status_change>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Unknown vulnerability in the H.323 protocol implementation in Windows 98, Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code.</description>
      <reference source="CVE">CVE-2004-0117</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-2" comment="Windows XP is installed" negate="false"/>
          <criterion test_ref="cmp-160" comment="a vulnerable version of h323.tsp exists" negate="false"/>
          <criterion test_ref="wrt-187" comment="the patch kb835732 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL965" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Internet Explorer</product>
      </affected>
      <dates>
        <submitted date="2006-04-12-12:55">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-04-12-05:16">DRAFT</status_change>
        <status_change date="2006-05-03-10:06">INTERIM</status_change>
      </dates>
      <description>Microsoft Internet Explorer 5.01 through 6 does not always return the correct IOleClientSite information when dynamically creating an embedded object, which could cause Internet Explorer to run the object in the wrong security context or zone, and allow remote attackers to execute arbitrary code.</description>
      <reference source="CVE">CVE-2006-1190</reference>
      <status>INTERIM</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-613" comment="Win2K or XP,SP1 is installed" negate="false"/>
          <criterion test_ref="wrt-652" comment="Internet Explorer 6 (any patch level) is installed" negate="false"/>
          <criterion test_ref="wft-776" comment="the version of mshtml.dll is less than 6.0.2800.1543" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL966" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>IIS 4.0</product>
      </affected>
      <dates>
        <submitted date="2004-05-18-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2004-06-16-12:00">INTERIM</status_change>
        <status_change date="2004-06-30-12:00">ACCEPTED</status_change>
      </dates>
      <description>The logging capability for unicast and multicast transmissions in the ISAPI extension for Microsoft Windows Media Services in Microsoft Windows NT 4.0 and 2000, nsiislog.dll, allows remote attackers to cause a denial of service in Internet Information Server (IIS) and execute arbitrary code via a certain network request.</description>
      <reference source="CVE">CVE-2003-0227</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-214" comment="IIS 4.0 Major Version" negate="false"/>
          <criterion test_ref="wrt-215" comment="IIS minor version equals 0" negate="false"/>
          <criterion test_ref="wft-335" comment="File %windir%\System32\nsiislog.dll is less than 4.1.0.3861" negate="false"/>
          <criterion test_ref="wrt-388" comment="Patch KB817772 Installed" negate="true"/>
          <criterion test_ref="wrt-389" comment="Patch KB822343 Installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL967" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>Red Hat Enteprise Linux 3</product>
      </affected>
      <dates>
        <submitted date="2004-05-19-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-06-16-12:00">INTERIM</status_change>
        <status_change date="2004-06-30-12:00">ACCEPTED</status_change>
      </dates>
      <description>rsync before 2.6.1 does not properly sanitize paths when running a read/write daemon without using chroot, which allows remote attackers to write files outside of the module's path.</description>
      <reference source="CVE">CVE-2004-0426</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-340" comment="rsync version is less than 2.5.7-4.3E" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL968" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 98</windows:platform>
        <windows:platform>Microsoft Windows ME</windows:platform>
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Jet Database Engine</product>
      </affected>
      <dates>
        <submitted date="2004-04-13-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <status_change date="2004-05-05-12:00">INTERIM</status_change>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in Microsoft Jet Database Engine 4.0 allows remote attackers to execute arbitrary code via a specially-crafted database query.</description>
      <reference source="CVE">CVE-2004-0197</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-140" comment="a vulnerable version of Microsoft Jet 4.0 is installed" negate="false"/>
          <criterion test_ref="wrt-185" comment="the patch kb837001 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL969" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>COM Internet Services</product>
      </affected>
      <dates>
        <submitted date="2004-05-25-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2004-06-18-12:00">INTERIM</status_change>
        <status_change date="2004-07-02-12:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the COM Internet Services and in the RPC over HTTP Proxy components for Microsoft Windows NT Server 4.0, NT 4.0 Terminal Server Edition, 2000, XP, and Server 2003 allows remote attackers to cause a denial of service via a crafted request.</description>
      <reference source="CVE">CVE-2003-0807</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-8" comment="Windows NT 4.0 Server or Terminal Server is installed" negate="false"/>
          <criterion test_ref="cmp-21" comment="a vulnerable version of rpcproxy.dll exists on NT" negate="false"/>
          <criterion test_ref="wrt-189" comment="the patch kb828741 is installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-385" comment="COM Internet Services are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL970" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>Red Hat Enteprise Linux 3</product>
      </affected>
      <dates>
        <submitted date="2004-05-20-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-06-16-12:00">INTERIM</status_change>
        <status_change date="2004-06-30-12:00">ACCEPTED</status_change>
      </dates>
      <description>Heap-based buffer overflow in CVS 1.11.x up to 1.11.15, and 1.12.x up to 1.12.7, when using the pserver mechanism allows remote attackers to execute arbitrary code via Entry lines.</description>
      <reference source="CVE">CVE-2004-0396</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-341" comment="cvs version is less than 1.11.2-22" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-931" comment="/usr/bin/cvs is executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL971" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>Red Hat Enteprise Linux 3</product>
      </affected>
      <dates>
        <submitted date="2004-05-20-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-06-16-12:00">INTERIM</status_change>
        <status_change date="2004-06-30-12:00">ACCEPTED</status_change>
      </dates>
      <description>The Portable Network Graphics library (libpng) 1.0.15 and earlier allows attackers to cause a denial of service (crash) via a malformed PNG image file that triggers an error that causes an out-of-bounds read when creating the error message.</description>
      <reference source="CVE">CVE-2004-0421</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="cmp-932" comment="libpng/libpng-devel is less than 1.2.2-21 or libpng10/libpng-devel less than 1.0.13 is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL972" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>Red Hat Enteprise Linux 3</product>
      </affected>
      <dates>
        <submitted date="2004-06-10-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-06-30-12:00">INTERIM</status_change>
        <status_change date="2004-07-12-12:00">ACCEPTED</status_change>
      </dates>
      <description>TCPDUMP 3.8.1 and earlier allows remote attackers to cause a denial of service (crash) via ISAKMP packets containing a Delete payload with a large number of SPI's, which causes an out-of-bounds read, as demonstrated by the Striker ISAKMP Protocol Test Suite.</description>
      <reference source="CVE">CVE-2004-0183</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-216" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="rvt-353" comment="tcpdump version is less than 3.7.2-7.E3.2" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-1017" comment="/usr/sbin/tcpdump is executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL974" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 98</windows:platform>
        <windows:platform>Microsoft Windows ME</windows:platform>
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Internet Explorer 6</product>
      </affected>
      <dates>
        <submitted date="2004-04-29-04:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <status_change date="2004-05-25-04:00">INTERIM</status_change>
        <status_change date="2004-06-16-04:00">ACCEPTED</status_change>
        <status_change date="2004-09-22-04:00">INTERIM</status_change>
        <modified date="2004-09-22-04:01" comment="Replaced IE cumulative patch IDs to correspond to the original IDs">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </modified>
        <status_change date="2004-10-06-04:00">ACCEPTED</status_change>
        <modified date="2005-09-20-04:00" comment="Changed IE registry test to wrt-18">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <modified date="2005-09-20-04:04" comment="Changed IE registry test to wrt-18">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-21-01:27">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 5.5 and 6.0 allows remote attackers to read certain files and spoof the URL in the address bar by using the Document.open function to pass information between two frames from different domains, a new variant of the "Frame Domain Verification" vulnerability described in MS:MS01-058/CAN-2001-0874.</description>
      <reference source="CVE">CVE-2002-0027</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wft-311" comment="File %windir%\system32\mshtml.dll version is less than 6.0.2713.1100" negate="false"/>
          <criterion test_ref="wrt-355" comment="Patch Q316059.exe Installed" negate="true"/>
          <criterion test_ref="wrt-356" comment="Patch Q319282 Installed" negate="true"/>
          <criterion test_ref="wrt-204" comment="the patch q321232 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-205" comment="the patch q323759 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-206" comment="the patch q328970 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-207" comment="the patch q324929 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-208" comment="the patch q810847 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-209" comment="the patch q813489 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-210" comment="the patch q818529 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-211" comment="the patch q822925 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-212" comment="the patch q828750 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-19" comment="the patch q824145 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-141" comment="the patch q832894 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-18" comment="Internet Explorer 6 is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL975" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>OpenSSL</product>
      </affected>
      <dates>
        <submitted date="2004-03-20-12:00">
          <contributor organization="The MITRE Corporation">Matt Busby</contributor>
        </submitted>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Matt Busby</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">INTERIM</status_change>
        <status_change date="2004-06-16-12:00">ACCEPTED</status_change>
      </dates>
      <description>The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that triggers a null dereference.</description>
      <reference source="CVE">CVE-2004-0079</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-318" comment="openssl version is less than 0.9.7a-20" negate="false"/>
          <criterion test_ref="rvt-319" comment="openssl-devel version is less than 0.9.7a-20" negate="false"/>
          <criterion test_ref="rvt-320" comment="openssl-perl version is less than 0.9.7a-20" negate="false"/>
          <criterion test_ref="rvt-321" comment="openssl096 version is less than 0.9.6-25.9" negate="false"/>
          <criterion test_ref="rvt-322" comment="openssl096b version is less than 0.9.6b-15" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL976" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>Red Hat Enteprise Linux 3</product>
      </affected>
      <dates>
        <submitted date="2004-06-10-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-06-30-12:00">INTERIM</status_change>
        <status_change date="2004-07-12-12:00">ACCEPTED</status_change>
      </dates>
      <description>Integer underflow in the isakmp_id_print for TCPDUMP 3.8.1 and earlier allows remote attackers to cause a denial of service (crash) via an ISAKMP packet with an Identification payload with a length that becomes less than 8 during byte order conversion, which causes an out-of-bounds read, as demonstrated by the Striker ISAKMP Protocol Test Suite.</description>
      <reference source="CVE">CVE-2004-0184</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-216" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="rvt-353" comment="tcpdump version is less than 3.7.2-7.E3.2" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-1017" comment="/usr/sbin/tcpdump is executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL977" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>Red Hat Enteprise Linux 3</product>
      </affected>
      <dates>
        <submitted date="2004-06-10-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-06-30-12:00">INTERIM</status_change>
        <status_change date="2004-07-12-12:00">ACCEPTED</status_change>
      </dates>
      <description>Multiple stack-based buffer overflows in the get_header function in header.c for LHA 1.14, as used in products such as Barracuda Spam Firewall, allow remote attackers or local users to execute arbitrary code via long directory or file names in an LHA archive, which triggers the overflow when testing or extracting the archive.</description>
      <reference source="CVE">CVE-2004-0234</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="rvt-354" comment="lha version is less than 1.14i-10.2" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-1019" comment="/usr/bin/lha is executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL978" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>Red Hat Enteprise Linux 3</product>
      </affected>
      <dates>
        <submitted date="2004-06-10-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-06-30-12:00">INTERIM</status_change>
        <status_change date="2004-07-12-12:00">ACCEPTED</status_change>
      </dates>
      <description>Multiple directory traversal vulnerabilities in LHA 1.14 allow remote attackers or local users to create arbitrary files via an LHA archive containing filenames with (1) .. sequences or (2) absolute pathnames with double leading slashes ("//absolute/path").</description>
      <reference source="CVE">CVE-2004-0235</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="rvt-354" comment="lha version is less than 1.14i-10.2" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-1019" comment="/usr/bin/lha is executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL979" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>Red Hat Enteprise Linux 3</product>
      </affected>
      <dates>
        <submitted date="2004-06-10-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-06-30-12:00">INTERIM</status_change>
        <status_change date="2004-07-12-12:00">ACCEPTED</status_change>
      </dates>
      <description>Utempter allows device names that contain .. (dot dot) directory traversal sequences, which allows local users to overwrite arbitrary files via a symlink attack on device names in combination with an application that trusts the utmp or wtmp files.</description>
      <reference source="CVE">CVE-2004-0233</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="rvt-355" comment="utempter version is less than 0.5.5-1.3EL.0" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-1020" comment="/usr/sbin/utempter is executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL980" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>Red Hat Enteprise Linux 3</product>
      </affected>
      <dates>
        <submitted date="2004-06-10-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-06-30-12:00">INTERIM</status_change>
        <status_change date="2004-07-12-12:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the ntlm_check_auth (NTLM authentication) function for Squid Web Proxy Cache 2.5.x and 3.x, when compiled with NTLM handlers enabled, allows remote attackers to execute arbitrary code via a long password ("pass" variable).</description>
      <reference source="CVE">CVE-2004-0541</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="rvt-356" comment="squid version is less than 2.5.STABLE3-6.3E" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="rlt-233" comment="squid is listening on the network" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL982" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>Red Hat Enteprise Linux 3</product>
      </affected>
      <dates>
        <submitted date="2004-06-10-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-06-30-12:00">INTERIM</status_change>
        <status_change date="2004-07-12-12:00">ACCEPTED</status_change>
      </dates>
      <description>Ethereal 0.10.3 allows remote attackers to cause a denial of service (crash) via certain SIP messages between Hotsip servers and clients.</description>
      <reference source="CVE">CVE-2004-0504</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="cmp-1022" comment="Vulnerable Config" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-849" comment="Vulnerable Config" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL983" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>IIS 5.1</product>
      </affected>
      <dates>
        <submitted date="2004-05-19-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2004-06-16-12:00">INTERIM</status_change>
        <status_change date="2004-06-30-12:00">ACCEPTED</status_change>
      </dates>
      <description>Unknown vulnerability in the hosting process (dllhost.exe) for Microsoft Internet Information Server (IIS) 4.0 through 5.1 allows remote attackers to gain privileges by executing an out of process application that acquires LocalSystem privileges, aka "Out of Process Privilege Elevation."</description>
      <reference source="CVE">CVE-2002-0869</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-223" comment="IIS major version equals 5" negate="false"/>
          <criterion test_ref="wrt-390" comment="IIS 5.1 Minor Version" negate="false"/>
          <criterion test_ref="wft-336" comment="File %windir%\System32\w3svc.dll is less than 5.1.2600.1125" negate="false"/>
          <criterion test_ref="wrt-218" comment="Patch Q327696 Installed" negate="true"/>
          <criterion test_ref="wrt-219" comment="Patch Q811114 Installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL984" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>Red Hat Enteprise Linux 3</product>
      </affected>
      <dates>
        <submitted date="2004-05-12-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-06-16-12:00">INTERIM</status_change>
        <status_change date="2004-06-30-12:00">ACCEPTED</status_change>
      </dates>
      <description>Racoon before 20040408a allows remote attackers to cause a denial of service (memory consumption) via an ISAKMP packet with a large length field.</description>
      <reference source="CVE">CVE-2004-0403</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-338" comment="ipsec-tools version is less than 0.2.5-0.4" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="rlt-230" comment="racoon is listening on the network" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL985" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Internet Explorer</product>
      </affected>
      <dates>
        <submitted date="2006-04-12-12:55">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-04-12-05:16">DRAFT</status_change>
        <status_change date="2006-05-03-10:06">INTERIM</status_change>
      </dates>
      <description>Microsoft Internet Explorer 6 and 7 Beta 2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a certain createTextRange call on a checkbox object, which results in a dereference of an invalid table pointer.</description>
      <reference source="CVE">CVE-2006-1359</reference>
      <status>INTERIM</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-692" comment="Windows XP (64-bit,SP1 or 32-bit,SP2) is installed" negate="false"/>
          <criterion test_ref="wft-777" comment="the version of mshtml.dll is less than 6.0.2900.2873" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL986" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>Red Hat Enteprise Linux 3</product>
      </affected>
      <dates>
        <submitted date="2004-06-10-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-06-30-12:00">INTERIM</status_change>
        <status_change date="2004-07-12-12:00">ACCEPTED</status_change>
      </dates>
      <description>The AIM dissector in Ethereal 0.10.3 allows remote attackers to cause a denial of service (assert error) via unknown attack vectors.</description>
      <reference source="CVE">CVE-2004-0505</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="cmp-1022" comment="Vulnerable Config" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-849" comment="Vulnerable Config" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL987" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>Red Hat Enteprise Linux 3</product>
      </affected>
      <dates>
        <submitted date="2004-06-10-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-06-30-12:00">INTERIM</status_change>
        <status_change date="2004-07-12-12:00">ACCEPTED</status_change>
      </dates>
      <description>The SPNEGO dissector in Ethereal 0.9.8 to 0.10.3 allows remote attackers to cause a denial of service (crash) via unknown attack vectors that cause a null pointer dereference.</description>
      <reference source="CVE">CVE-2004-0506</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="cmp-1022" comment="Vulnerable Config" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-849" comment="Vulnerable Config" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL988" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>Red Hat Enteprise Linux 3</product>
      </affected>
      <dates>
        <submitted date="2004-06-10-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-06-30-12:00">INTERIM</status_change>
        <status_change date="2004-07-12-12:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the MMSE dissector for Ethereal 0.10.1 to 0.10.3 allows remote attackers to cause a denial of service and possibly execute arbitrary code.</description>
      <reference source="CVE">CVE-2004-0507</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="cmp-1022" comment="Vulnerable Config" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-849" comment="Vulnerable Config" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL989" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Microsoft Outlook Express</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-04:00">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </submitted>
        <status_change date="2005-08-19-10:05">DRAFT</status_change>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Stack-based buffer overflow in the news reader for Microsoft Outlook Express (MSOE.DLL) 5.5 SP2, 6, and 6 SP1 allows remote malicious NNTP servers to execute arbitrary code via a LIST response with a long second field.</description>
      <reference source="CVE">CVE-2005-1213</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-173" comment="Outlook Express 6 SP1 is installed" negate="false"/>
          <criterion test_ref="wft-84" comment="the version of inetcomm.dll is less than 6.0.2800.1506" negate="false"/>
          <criterion test_ref="wrt-58" comment="Patch KB897715 Installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL990" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 98</windows:platform>
        <windows:platform>Microsoft Windows ME</windows:platform>
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Microsoft Outlook Express</product>
      </affected>
      <dates>
        <submitted date="2004-04-13-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <status_change date="2004-05-05-12:00">INTERIM</status_change>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>The MHTML protocol handler in Microsoft Outlook Express 5.5 SP2 through Outlook Express 6 SP1 allows remote attackers to bypass domain restrictions and execute arbitrary code, as demonstrated on Internet Explorer using script in a compiled help (CHM) file that references the InfoTech Storage (ITS) protocol handlers such as (1) ms-its, (2) ms-itss, (3) its, or (4) mk:@MSITStore, aka the "MHTML URL Processing Vulnerability."</description>
      <reference source="CVE">CVE-2004-0380</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-171" comment="Outlook Express 6 is installed" negate="false"/>
          <criterion test_ref="wft-183" comment="the version of inetcomm.dll is less than 6.00.2739.300" negate="false"/>
          <criterion test_ref="wrt-188" comment="the patch kb837009 is installed (installed components key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL991" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>MIT Kerberos 5 (krb5)</product>
      </affected>
      <dates>
        <submitted date="2004-06-29-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-07-21-12:00">INTERIM</status_change>
        <status_change date="2004-08-04-12:00">ACCEPTED</status_change>
      </dates>
      <description>Multiple buffer overflows in krb5_aname_to_localname for MIT Kerberos 5 (krb5) 1.3.3 and earlier allow remote attackers to execute arbitrary code as root.</description>
      <reference source="CVE">CVE-2004-0523</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="rvt-361" comment="krb5-libs rpm version prior to 1.2.7-24 is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL992" class="vulnerability">
      <affected family="hp-ux">
        <hpux:platform>HP-UX 11</hpux:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2006-01-11-12:55">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-01-12-09:18">DRAFT</status_change>
        <modified date="2006-01-31-12:19" comment="Updated reference to CVE-2005-3295.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2006-02-22-08:27">INTERIM</status_change>
        <status_change date="2006-03-09-12:19">ACCEPTED</status_change>
      </dates>
      <description>Unspecified vulnerability in HP-UX B.11.23 on Itanium platforms allows local users to cause a denial of service due to a "specific stack size."</description>
      <reference source="CVE">CVE-2005-3295</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-682" comment="700 Series or 800 Series OS Release 11.23" negate="false"/>
          <criterion test_ref="hst-33" comment="OS-Core.CORE2-KRN is installed" negate="false"/>
          <criterion test_ref="cmp-702" comment="Either PHKL_33713 or PHKL_33714 or later is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL993" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>CVS</product>
      </affected>
      <dates>
        <submitted date="2004-06-29-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-07-21-12:00">INTERIM</status_change>
        <status_change date="2004-08-04-12:00">ACCEPTED</status_change>
      </dates>
      <description>CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle malformed "Entry" lines, which prevents a NULL terminator from being used and may lead to a denial of service (crash), modification of critical program data, or arbitrary code execution.</description>
      <reference source="CVE">CVE-2004-0414</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="rvt-362" comment="cvs rpm version prior to 1.11.2-24 is installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-931" comment="/usr/bin/cvs is executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL994" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>CVS</product>
      </affected>
      <dates>
        <submitted date="2004-06-29-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-07-21-12:00">INTERIM</status_change>
        <status_change date="2004-08-04-12:00">ACCEPTED</status_change>
      </dates>
      <description>Double-free vulnerability for the error_prog_name string in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may allow remote attackers to execute arbitrary code.</description>
      <reference source="CVE">CVE-2004-0416</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="rvt-362" comment="cvs rpm version prior to 1.11.2-24 is installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-931" comment="/usr/bin/cvs is executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL995" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>COM Internet Services</product>
      </affected>
      <dates>
        <submitted date="2004-05-25-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2004-06-18-12:00">INTERIM</status_change>
        <status_change date="2004-07-02-12:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the COM Internet Services and in the RPC over HTTP Proxy components for Microsoft Windows NT Server 4.0, NT 4.0 Terminal Server Edition, 2000, XP, and Server 2003 allows remote attackers to cause a denial of service via a crafted request.</description>
      <reference source="CVE">CVE-2003-0807</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
          <criterion test_ref="wft-289" comment="the version of rpcproxy.dll is less than 5.0.2195.6904" negate="false"/>
          <criterion test_ref="wrt-189" comment="the patch kb828741 is installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-385" comment="COM Internet Services are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL996" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 98</windows:platform>
        <product>File and Print Sharing</product>
      </affected>
      <dates>
        <submitted date="2004-05-18-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <status_change date="2004-06-16-12:00">INTERIM</status_change>
        <status_change date="2004-06-30-12:00">ACCEPTED</status_change>
        <modified date="2005-09-26-12:32" comment="modified wft-337 - Changed comment to match test">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-28-01:04">INTERIM</status_change>
        <status_change date="2005-10-19-05:47">ACCEPTED</status_change>
      </dates>
      <description>File and Print Sharing service in Windows 95, Windows 98, and Windows Me does not properly check the password for a file share, which allows remote attackers to bypass share access controls by sending a 1-byte password that matches the first character of the real password, aka the "Share Level Password" vulnerability.</description>
      <reference source="CVE">CVE-2000-0979</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-391" comment="Windows 98 Installed" negate="false"/>
          <criterion test_ref="wft-337" comment="File %windir%\system\vserver.vxd version is less than 4.10.2001.0" negate="false"/>
          <criterion test_ref="wrt-392" comment="Patch 273991USA8.EXE Installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL997" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>Red Hat Enteprise Linux 3</product>
      </affected>
      <dates>
        <submitted date="2004-05-12-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-06-16-12:00">INTERIM</status_change>
        <status_change date="2004-06-30-12:00">INTERIM</status_change>
        <status_change date="2004-07-12-12:00">ACCEPTED</status_change>
      </dates>
      <description>/proc/tty/driver/serial in Linux 2.4.x reveals the exact number of characters used in serial links, which could allow local users to obtain potentially sensitive information such as the length of passwords.</description>
      <reference source="CVE">CVE-2003-0461</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-346" comment="kernel version is less than 2.4.21-15.EL" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="upt-26" comment="/proc/tty/driver/serial is world-readable" negate="false"/>
          <criterion test_ref="upt-27" comment="/proc/tty/driver/ is world-executable" negate="false"/>
          <criterion test_ref="upt-28" comment="/proc/tty/ is world-executable" negate="false"/>
          <criterion test_ref="upt-29" comment="/proc/ is world-executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL998" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <solaris:platform>Sun Solaris 10</solaris:platform>
        <product>X</product>
      </affected>
      <dates>
        <submitted date="2006-02-12-01:16">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-03-09-12:19">DRAFT</status_change>
        <status_change date="2006-04-06-06:30">INTERIM</status_change>
        <status_change date="2006-05-03-10:06">ACCEPTED</status_change>
      </dates>
      <description>Multiple integer overflows in XFree86 before 4.3.0 allow user-complicit attackers to execute arbitrary code via a crafted pixmap image.</description>
      <reference source="CVE">CVE-2005-2495</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-755" comment="Solaris 9 (x86,Xorg) meets Sun Alert ID 101926 criteria." negate="false"/>
          <criterion test_ref="cmp-757" comment="Solaris 10 (x86,Xorg) meets Sun Alert ID 101926 criteria." negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-23" comment="The Xorg X server is running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL999" class="compliance">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Exchange Server 2003</product>
      </affected>
      <dates>
        <submitted date="2005-06-07-12:00">
          <contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
        </submitted>
        <status_change date="2005-06-08-03:24">DRAFT</status_change>
        <status_change date="2005-06-29-06:49">INTERIM</status_change>
        <status_change date="2005-07-27-10:37">ACCEPTED</status_change>
      </dates>
      <description>Review blocked sender list</description>
      <reference source="MISC">1.2.8</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <notes>
        <note>Corresponds to item 1.2.8 in the Exchange 2003 Benchmark</note>
      </notes>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wat-5" comment="Review blocked senders" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1000" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Help and Support Center (HSC)</product>
      </affected>
      <dates>
        <submitted date="2004-04-14-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <modified date="2004-05-12-12:00" comment="Added a criterion to the configuration section to see if the HCP protocol is registered.">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </modified>
        <status_change date="2004-06-16-12:00">INTERIM</status_change>
        <status_change date="2004-06-30-12:00">ACCEPTED</status_change>
        <modified date="2004-09-13-11:23" comment="cmp-66 added">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2004-09-15-12:00">INTERIM</status_change>
        <status_change date="2004-09-29-12:00">ACCEPTED</status_change>
      </dates>
      <description>Help and Support Center in Microsoft Windows XP SP1 does not properly validate HCP URLs, which allows remote attackers to execute arbitrary code via quotation marks in an hcp:// URL, which are not quoted when constructing the argument list to HelpCtr.exe.</description>
      <reference source="CVE">CVE-2003-0907</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-905" comment="a vulnerable version of helpctr.exe exists on XP" negate="false"/>
          <criterion test_ref="wrt-187" comment="the patch kb835732 is installed" negate="true"/>
          <criterion test_ref="cmp-66" comment="Windows XP (sp1 or earlier) is installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-12" comment="the HCP Protocol is registered" negate="true"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1001" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>CVS</product>
      </affected>
      <dates>
        <submitted date="2004-06-29-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-07-21-12:00">INTERIM</status_change>
        <status_change date="2004-08-04-12:00">ACCEPTED</status_change>
      </dates>
      <description>Integer overflow in the "Max-dotdot" CVS protocol command (serve_max_dotdot) for CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may allow remote attackers to cause a server crash, which could cause temporary data to remain undeleted and consume disk space.</description>
      <reference source="CVE">CVE-2004-0417</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="rvt-362" comment="cvs rpm version prior to 1.11.2-24 is installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-931" comment="/usr/bin/cvs is executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1003" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>CVS</product>
      </affected>
      <dates>
        <submitted date="2004-06-29-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-07-21-12:00">INTERIM</status_change>
        <status_change date="2004-08-04-12:00">ACCEPTED</status_change>
      </dates>
      <description>serve_notify in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle empty data lines, which may allow remote attackers to perform an "out-of-bounds" write for a single byte to execute arbitrary code or modify critical program data.</description>
      <reference source="CVE">CVE-2004-0418</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="rvt-362" comment="cvs rpm version prior to 1.11.2-24 is installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-931" comment="/usr/bin/cvs is executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1004" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Windows XP</product>
      </affected>
      <dates>
        <submitted date="2004-04-14-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2004-05-25-12:00">INTERIM</status_change>
        <status_change date="2004-06-16-12:00">ACCEPTED</status_change>
        <modified date="2004-09-13-11:24" comment="cmp-66 added">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2004-09-15-12:00">INTERIM</status_change>
        <status_change date="2004-09-29-12:00">ACCEPTED</status_change>
      </dates>
      <description>Windows XP allows local users to execute arbitrary programs by creating a task at an elevated privilege level through the eventtriggers.exe command-line tool or the Task Scheduler service, aka "Windows Management Vulnerability."</description>
      <reference source="CVE">CVE-2003-0909</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-908" comment="A vulnerable version of evtgprov.dll exists on XP" negate="false"/>
          <criterion test_ref="wrt-187" comment="the patch kb835732 is installed" negate="true"/>
          <criterion test_ref="cmp-66" comment="Windows XP (sp1 or earlier) is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1005" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Microsoft Internet Explorer 6 Service Pack 1</product>
      </affected>
      <dates>
        <submitted date="2005-03-17-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2005-03-23-08:09">DRAFT</status_change>
        <status_change date="2005-04-13-12:15">INTERIM</status_change>
        <status_change date="2005-05-04-12:33">ACCEPTED</status_change>
        <modified date="2005-12-26-09:40" comment="Removed test to check kb867282.">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </modified>
        <status_change date="2006-01-12-08:59">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 5.01, 5.5, and 6 does not properly validate buffers when handling certain DHTML methods including the createControlRange Javascript function, which allows remote attackers to execute arbitrary code, aka the "DHTML Method Heap Memory Corruption Vulnerability."</description>
      <reference source="CVE">CVE-2005-0055</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-50" comment="Internet Explorer 6 Service Pack 1 is installed" negate="false"/>
          <criterion test_ref="cmp-257" comment="a vulnerable version of mshtml.dll exisits GDR/QFE" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1006" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>SquirrelMail</product>
      </affected>
      <dates>
        <submitted date="2004-06-29-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-07-21-12:00">INTERIM</status_change>
        <status_change date="2004-08-11-12:00">ACCEPTED</status_change>
      </dates>
      <description>Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail 1.4.2 allow remote attackers to execute arbitrary script as other users and possibly steal authentication information via multiple attack vectors, including the mailbox parameter in compose.php.</description>
      <reference source="CVE">CVE-2004-0519</reference>
      <status>ACCEPTED</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="rvt-363" comment="squirrelmail rpm version prior to 1.4.3-0.e3.1 is installed" negate="false"/>
          <criterion test_ref="rrt-217" comment="php rpm is installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="rlt-218" comment="httpd is listening on the network" negate="false"/>
          <criterion test_ref="uft-1" comment="/etc/httpd/modules/libphp4.so exists" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1007" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Microsoft ASN.1 Library</product>
      </affected>
      <dates>
        <submitted date="2004-04-13-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
        <status_change date="2004-05-05-12:00">INTERIM</status_change>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
        <modified date="2004-09-13-11:24" comment="cmp-66 added">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2004-09-15-12:00">INTERIM</status_change>
        <status_change date="2004-09-29-12:00">ACCEPTED</status_change>
      </dates>
      <description>Double-free vulnerability in the ASN.1 library as used in Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service and possibly execute arbitrary code.</description>
      <reference source="CVE">CVE-2004-0123</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-150" comment="a vulnerable version of msasn1.dll exists" negate="false"/>
          <criterion test_ref="wrt-187" comment="the patch kb835732 is installed" negate="true"/>
          <criterion test_ref="cmp-66" comment="Windows XP (sp1 or earlier) is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1008" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Help and Support Center (HSC)</product>
      </affected>
      <dates>
        <submitted date="2004-05-12-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2004-06-16-12:00">INTERIM</status_change>
        <status_change date="2004-06-30-12:00">ACCEPTED</status_change>
        <modified date="2004-09-13-11:25" comment="cmp-66 added">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2004-09-15-12:00">INTERIM</status_change>
        <status_change date="2004-09-29-12:00">ACCEPTED</status_change>
      </dates>
      <description>Help and Support Center in Microsoft Windows XP and Windows Server 2003 SP1 does not properly validate HCP URLs, which allows remote attackers to execute arbitrary code, as demonstrated using certain hcp:// URLs that access the DVD Upgrade capability (dvdupgrd.htm).</description>
      <reference source="CVE">CVE-2004-0199</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-114" comment="a vulnerable version of helpctr.exe exists on XP" negate="false"/>
          <criterion test_ref="wrt-10" comment="the patch kb840374 is installed" negate="true"/>
          <criterion test_ref="cmp-66" comment="Windows XP (sp1 or earlier) is installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-12" comment="the HCP Protocol is registered" negate="true"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1009" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>IIS 5.1</product>
      </affected>
      <dates>
        <submitted date="2004-05-19-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2004-06-16-12:00">INTERIM</status_change>
        <status_change date="2004-06-30-12:00">ACCEPTED</status_change>
      </dates>
      <description>IIS 5.0 and 5.1 allows remote attackers to cause a denial of service (crash) via malformed WebDAV requests that cause a large amount of memory to be assigned.</description>
      <reference source="CVE">CVE-2002-1182</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-223" comment="IIS major version equals 5" negate="false"/>
          <criterion test_ref="wrt-390" comment="IIS 5.1 Minor Version" negate="false"/>
          <criterion test_ref="wft-336" comment="File %windir%\System32\w3svc.dll is less than 5.1.2600.1125" negate="false"/>
          <criterion test_ref="wrt-218" comment="Patch Q327696 Installed" negate="true"/>
          <criterion test_ref="wrt-219" comment="Patch Q811114 Installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1010" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 98</windows:platform>
        <windows:platform>Microsoft Windows ME</windows:platform>
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Microsoft Outlook Express</product>
      </affected>
      <dates>
        <submitted date="2004-04-13-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <status_change date="2004-05-05-12:00">INTERIM</status_change>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>The MHTML protocol handler in Microsoft Outlook Express 5.5 SP2 through Outlook Express 6 SP1 allows remote attackers to bypass domain restrictions and execute arbitrary code, as demonstrated on Internet Explorer using script in a compiled help (CHM) file that references the InfoTech Storage (ITS) protocol handlers such as (1) ms-its, (2) ms-itss, (3) its, or (4) mk:@MSITStore, aka the "MHTML URL Processing Vulnerability."</description>
      <reference source="CVE">CVE-2004-0380</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-173" comment="Outlook Express 6 SP1 is installed" negate="false"/>
          <criterion test_ref="wft-185" comment="the version of inetcomm.dll is less than 6.00.2800.1409" negate="false"/>
          <criterion test_ref="wrt-188" comment="the patch kb837009 is installed (installed components key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1011" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>IIS 5.0</product>
      </affected>
      <dates>
        <submitted date="2004-05-12-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2004-06-16-12:00">INTERIM</status_change>
        <status_change date="2004-06-30-12:00">ACCEPTED</status_change>
        <modified date="2005-01-11-12:00" comment="modified wft-330 - changed the version of msw3prt.dll to test against from 5.5.2195.58075 to 5.0.2195.5807">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-01-20-01:18">INTERIM</status_change>
        <status_change date="2005-02-16-12:00">ACCEPTED</status_change>
      </dates>
      <description>IIS 5.0 and 5.1 allows remote attackers to cause a denial of service (crash) via malformed WebDAV requests that cause a large amount of memory to be assigned.</description>
      <reference source="CVE">CVE-2002-1182</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-223" comment="IIS major version equals 5" negate="false"/>
          <criterion test_ref="wrt-215" comment="IIS minor version equals 0" negate="false"/>
          <criterion test_ref="wft-330" comment="File %windir%\System32\msw3prt.dll is less than 5.0.2195.5807" negate="false"/>
          <criterion test_ref="wrt-218" comment="Patch Q327696 Installed" negate="true"/>
          <criterion test_ref="wrt-219" comment="Patch Q811114 Installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1012" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>SquirrelMail</product>
      </affected>
      <dates>
        <submitted date="2004-06-29-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-07-21-12:00">INTERIM</status_change>
        <status_change date="2004-08-11-12:00">ACCEPTED</status_change>
      </dates>
      <description>Cross-site scripting (XSS) vulnerability in mime.php for SquirrelMail before 1.4.3 allows remote attackers to insert arbitrary HTML and script via the content-type mail header, as demonstrated using read_body.php.</description>
      <reference source="CVE">CVE-2004-0520</reference>
      <status>ACCEPTED</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="rvt-363" comment="squirrelmail rpm version prior to 1.4.3-0.e3.1 is installed" negate="false"/>
          <criterion test_ref="rrt-217" comment="php rpm is installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="rlt-218" comment="httpd is listening on the network" negate="false"/>
          <criterion test_ref="uft-1" comment="/etc/httpd/modules/libphp4.so exists" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1013" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>Red Hat Enteprise Linux 3</product>
      </affected>
      <dates>
        <submitted date="2004-05-12-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-06-16-12:00">INTERIM</status_change>
        <status_change date="2004-06-30-12:00">ACCEPTED</status_change>
      </dates>
      <description>Real time clock (RTC) routines in Linux kernel 2.4.23 and earlier do not properly initialize their structures, which could leak kernel data to user space.</description>
      <reference source="CVE">CVE-2003-0984</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-346" comment="kernel version is less than 2.4.21-15.EL" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1014" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 98</windows:platform>
        <windows:platform>Microsoft Windows ME</windows:platform>
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Internet Explorer 6</product>
      </affected>
      <dates>
        <submitted date="2004-04-29-04:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <status_change date="2004-05-25-04:00">INTERIM</status_change>
        <status_change date="2004-06-16-04:00">ACCEPTED</status_change>
        <status_change date="2004-09-22-04:00">INTERIM</status_change>
        <modified date="2004-09-22-04:01" comment="Replaced IE cumulative patch IDs to correspond to the original IDs">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </modified>
        <status_change date="2004-10-06-04:00">ACCEPTED</status_change>
        <modified date="2005-09-20-04:00" comment="Changed IE registry test to wrt-18">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-21-01:27">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 5.5 and 6.0 allows remote attackers to cause the File Download dialogue box to misrepresent the name of the file in the dialogue in a way that could fool users into thinking that the file type is safe to download.</description>
      <reference source="CVE">CVE-2001-0875</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wft-308" comment="the version of mshtml.dll is less than 6.0.2712.0300" negate="false"/>
          <criterion test_ref="wrt-354" comment="Patch Q313675 Installed" negate="true"/>
          <criterion test_ref="wrt-355" comment="Patch Q316059.exe Installed" negate="true"/>
          <criterion test_ref="wrt-356" comment="Patch Q319282 Installed" negate="true"/>
          <criterion test_ref="wrt-204" comment="the patch q321232 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-205" comment="the patch q323759 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-206" comment="the patch q328970 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-207" comment="the patch q324929 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-208" comment="the patch q810847 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-209" comment="the patch q813489 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-210" comment="the patch q818529 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-211" comment="the patch q822925 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-212" comment="the patch q828750 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-19" comment="the patch q824145 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-141" comment="the patch q832894 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-18" comment="Internet Explorer 6 is installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-902" comment="File Downloads Not Disabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1015" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Internet Explorer 5.01, Internet Explorer 5.01 Service Pack 1, or Internet Explorer 5.01 Service Pack 2</product>
        <product>Internet Explorer 5.5 Service Pack 2</product>
        <product>Internet Explorer 6.0</product>
        <product>Internet Explorer 5.5 or Internet Explorer 5.5 Service Pack 1</product>
        <product>Internet Explorer 6 SP1</product>
      </affected>
      <dates>
        <submitted date="2005-09-19-04:00">
          <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
        </submitted>
        <status_change date="2005-09-21-01:33">DRAFT</status_change>
        <status_change date="2005-10-12-05:49">INTERIM</status_change>
        <status_change date="2005-11-16-08:02">ACCEPTED</status_change>
        <modified date="2005-12-26-09:40" comment="Removed test to check kb890047, added check for shell32 version &lt; 6.0.2900.2578">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </modified>
        <status_change date="2006-01-12-08:59">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via drag and drop events, aka the "Drag-and-Drop Vulnerability."</description>
      <reference source="CVE">CVE-2005-0053</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-2" comment="Windows XP is installed" negate="false"/>
          <criterion test_ref="cmp-178" comment="Windows XP service pack 2 (or earlier) is installed" negate="false"/>
          <criterion test_ref="wft-716" comment="the version of shell32.dll is less than 6.0.2900.2578" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
          <criterion test_ref="wrt-157" comment="Drag-and-Drop disabled when set to 3" negate="true"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1016" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Lightweight Directory Access Protocol (LDAP)</product>
      </affected>
      <dates>
        <submitted date="2004-04-13-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <status_change date="2004-05-05-12:00">INTERIM</status_change>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Unknown vulnerability in the Local Security Authority Subsystem Service (LSASS) in Windows 2000 domain controllers allows remote attackers to cause a denial of service via a crafted LDAP message.</description>
      <reference source="CVE">CVE-2003-0663</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-220" comment="Windows 2000 (domain controller) is installed" negate="false"/>
          <criterion test_ref="wft-192" comment="the version of lsasrv.dll is less than 5.0.2195.6902" negate="false"/>
          <criterion test_ref="wrt-187" comment="the patch kb835732 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1017" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>Red Hat Enteprise Linux 3</product>
      </affected>
      <dates>
        <submitted date="2004-05-12-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-06-16-12:00">INTERIM</status_change>
        <status_change date="2004-06-30-12:00">ACCEPTED</status_change>
      </dates>
      <description>Unknown vulnerability in Linux kernel before 2.4.22 allows local users to gain privileges, related to "R128 DRI limits checking."</description>
      <reference source="CVE">CVE-2004-0003</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-347" comment="kernel version is less than 2.4.21-15.EL" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1018" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>IIS 4.0</product>
      </affected>
      <dates>
        <submitted date="2004-05-12-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2004-06-16-12:00">INTERIM</status_change>
        <status_change date="2004-06-30-12:00">ACCEPTED</status_change>
      </dates>
      <description>Directory traversal vulnerability in IIS 5.0 and earlier allows remote attackers to execute arbitrary commands by encoding .. (dot dot) and "\" characters twice.</description>
      <reference source="CVE">CVE-2001-0333</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-214" comment="IIS 4.0 Major Version" negate="false"/>
          <criterion test_ref="wrt-215" comment="IIS minor version equals 0" negate="false"/>
          <criterion test_ref="wft-338" comment="File %windir%\System32\w3svc.dll is less than 4.2.764.1" negate="false"/>
          <criterion test_ref="wrt-241" comment="Patch Q295534 Installed" negate="true"/>
          <criterion test_ref="wrt-242" comment="Patch Q301625 Installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1020" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Internet Explorer</product>
      </affected>
      <dates>
        <submitted date="2006-04-12-12:55">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-04-12-05:16">DRAFT</status_change>
        <status_change date="2006-05-03-10:06">INTERIM</status_change>
      </dates>
      <description>Unspecified vulnerability in Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via a crafted URL with double-byte characters, aka the "Double Byte Character Parsing Memory Corruption Vulnerability."</description>
      <reference source="CVE">CVE-2006-1189</reference>
      <status>INTERIM</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-692" comment="Windows XP (64-bit,SP1 or 32-bit,SP2) is installed" negate="false"/>
          <criterion test_ref="wft-777" comment="the version of mshtml.dll is less than 6.0.2900.2873" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1021" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>Microsoft Windows NT</product>
      </affected>
      <dates>
        <submitted date="2004-06-03-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <status_change date="2004-06-30-12:00">INTERIM</status_change>
        <status_change date="2004-07-12-12:00">ACCEPTED</status_change>
      </dates>
      <description>The Remote Registry server in Windows NT 4.0 allows local authenticated users to cause a denial of service via a malformed request, which causes the winlogon process to fail, aka the "Remote Registry Access Authentication" vulnerability.</description>
      <reference source="CVE">CVE-2000-0377</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" negate="false"/>
          <criterion test_ref="cmp-1043" comment="For Windows NT 4.0 Workstation, Server and Enterprise Edition" negate="false"/>
          <criterion test_ref="cmp-1044" comment="For Terminal Server" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1022" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Exchange 2000</product>
      </affected>
      <dates>
        <submitted date="2004-06-03-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <status_change date="2004-06-30-12:00">INTERIM</status_change>
        <status_change date="2004-07-12-12:00">ACCEPTED</status_change>
        <modified date="2005-09-26-12:35" comment="modified wft-417 - Changed test to match comment">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-28-01:04">INTERIM</status_change>
        <status_change date="2005-10-19-05:47">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Exchange Server 2000 System Attendant gives "Everyone" group privileges to the WinReg key, which could allow remote attackers to read or modify registry keys.</description>
      <reference source="CVE">CVE-2002-0049</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-457" comment="Microsoft Exchange 2000 Installed" negate="false"/>
          <criterion test_ref="wft-417" comment="File %ExchangeInstallDir%\bin\mad.exe is less than 6.0.5770.21" negate="false"/>
          <criterion test_ref="wrt-458" comment="Patch Q316056 installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-459" comment="Everyone group given remote access permissions" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1023" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>Microsoft Windows NT</product>
      </affected>
      <dates>
        <submitted date="2004-06-03-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <status_change date="2004-06-30-12:00">INTERIM</status_change>
        <status_change date="2004-07-12-12:00">ACCEPTED</status_change>
      </dates>
      <description>The registry in Windows NT can be accessed remotely by users who are not administrators.</description>
      <reference source="CVE">CVE-1999-0562</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" negate="false"/>
          <criterion test_ref="wrt-224" comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-399" comment="Remote access to registry not controlled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1024" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>NetBIOS</product>
      </affected>
      <dates>
        <submitted date="2004-05-18-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <status_change date="2004-06-16-12:00">INTERIM</status_change>
        <status_change date="2004-06-30-12:00">ACCEPTED</status_change>
      </dates>
      <description>A component service related to NETBIOS is running.</description>
      <reference source="CVE">CVE-1999-0621</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-933" comment="Windows NT or 2000 Installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-934" comment="NetBIOS enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1025" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>SQL Server 2000</product>
      </affected>
      <dates>
        <submitted date="2004-06-15-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <status_change date="2004-06-30-12:00">INTERIM</status_change>
        <status_change date="2004-07-12-12:00">ACCEPTED</status_change>
        <modified date="2005-01-13-12:00" comment="modified wft-418 - Added space to registry key. used to say &quot;AppPath&quot; I changed it to &quot;App Path&quot;">
          <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
        </modified>
        <status_change date="2005-01-20-12:00">INTERIM</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-02-16-10:31">ACCEPTED</status_change>
        <modified date="2005-04-08-12:00" comment="modified wft-418 - wft-418 corrected literal string">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <modified date="2005-04-08-10:31" comment="modified wft-419 - wft-419 corrected literal string">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <modified date="2005-04-08-10:31" comment="modified wft-420 - wft-420 corrected literal string">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <modified date="2005-04-08-10:31" comment="modified wft-428 - wft-428 corrected literal string">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <modified date="2005-04-08-10:31" comment="modified wft-429 - wft-429 corrected literal string">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <modified date="2005-04-08-10:31" comment="modified wft-430 - wft-430 corrected literal string">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <modified date="2005-04-08-10:34" comment="modified wft-431 - wft-431 corrected literal string">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <status_change date="2005-04-11-08:48">INTERIM</status_change>
        <status_change date="2005-04-27-12:07">ACCEPTED</status_change>
      </dates>
      <description>The registry key containing the SQL Server service account information in Microsoft SQL Server 2000, including Microsoft SQL Server Desktop Engine (MSDE) 2000, has insecure permissions, which allows local users to gain privileges, aka "Incorrect Permission on SQL Server Service Account Registry Key."</description>
      <reference source="CVE">CVE-2002-0642</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-460" comment="SQL Server 2000 installed" negate="false"/>
          <criterion test_ref="wft-418" comment="the version of sqlservr.exe is less than 2000.80.650.0" negate="false"/>
          <criterion test_ref="wft-419" comment="the version of odsole70.dll is less than 2000.80.606.0" negate="false"/>
          <criterion test_ref="wft-428" comment="the version of xpqueue.dll is less than 2000.80.606.0" negate="false"/>
          <criterion test_ref="wft-429" comment="the version of xprepl.dll is less than 2000.80.606.0" negate="false"/>
          <criterion test_ref="wft-430" comment="the version of xplog70.dll is less than 2000.80.606.0" negate="false"/>
          <criterion test_ref="wft-431" comment="the version of xpweb70.dll is less than 2000.80.606.0" negate="false"/>
          <criterion test_ref="wft-420" comment="the version of xpstar.dll is less than 2000.80.628.0" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1026" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Internet Explorer 5.01 Service Pack 3</product>
      </affected>
      <dates>
        <submitted date="2005-06-22-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2005-06-22-12:38">DRAFT</status_change>
        <status_change date="2005-07-27-10:37">INTERIM</status_change>
        <status_change date="2005-08-18-07:37">ACCEPTED</status_change>
      </dates>
      <description>The legacy &lt;script> data-island capability for XML in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to read arbitrary XML files, and portions of other files, via a URL whose "src" attribute redirects to a local file.</description>
      <reference source="CVE">CVE-2002-0648</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-55" comment="Internet Explorer 5.01 Service Pack 3 is installed" negate="false"/>
          <criterion test_ref="wft-115" comment="the version of mshtml.dll is less than 5.0.3541.2700" negate="false"/>
          <criterion test_ref="wrt-62" comment="the patch kb883939 is installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1027" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft DirectPlay</product>
      </affected>
      <dates>
        <submitted date="2004-06-11-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <status_change date="2004-06-30-12:00">INTERIM</status_change>
        <status_change date="2004-07-12-12:00">ACCEPTED</status_change>
      </dates>
      <description>IDirectPlay4 Application Programming Interface (API) of Microsoft DirectPlay 7.0a thru 9.0b, as used in Windows Server 2003 and earlier allows remote attackers to cause a denial of service (application crash) via a malformed packet.</description>
      <reference source="CVE">CVE-2004-0202</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
          <criterion test_ref="cmp-1045" comment="Vulnerable versions of DirectX" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1028" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Outlook Express</product>
      </affected>
      <dates>
        <submitted date="2004-04-13-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <status_change date="2004-05-05-12:00">INTERIM</status_change>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
        <modified date="2005-09-26-12:57" comment="modified wft-184 - Deleted extra character in Build section">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-28-01:04">INTERIM</status_change>
        <status_change date="2005-10-19-05:47">ACCEPTED</status_change>
      </dates>
      <description>The MHTML protocol handler in Microsoft Outlook Express 5.5 SP2 through Outlook Express 6 SP1 allows remote attackers to bypass domain restrictions and execute arbitrary code, as demonstrated on Internet Explorer using script in a compiled help (CHM) file that references the InfoTech Storage (ITS) protocol handlers such as (1) ms-its, (2) ms-itss, (3) its, or (4) mk:@MSITStore, aka the "MHTML URL Processing Vulnerability."</description>
      <reference source="CVE">CVE-2004-0380</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wrt-172" comment="Outlook Express 6 for Windows 2003 is installed" negate="false"/>
          <criterion test_ref="wft-184" comment="the version of inetcomm.dll is less than 6.00.3790.137" negate="false"/>
          <criterion test_ref="wrt-186" comment="the patch kb837009 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1029" class="vulnerability">
      <affected family="hp-ux">
        <hpux:platform>HP-UX 11</hpux:platform>
        <product>ftpd</product>
      </affected>
      <dates>
        <submitted date="2005-11-30-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-12-20-11:03">DRAFT</status_change>
        <status_change date="2006-01-04-08:04">INTERIM</status_change>
        <status_change date="2006-01-25-07:30">ACCEPTED</status_change>
      </dates>
      <description>The FTP server in HP-UX 10.20, B.11.00, and B.11.11, allows remote attackers to list arbitrary directories as root by running the LIST command before logging in.</description>
      <reference source="CVE">CVE-2005-3296</reference>
      <status>ACCEPTED</status>
      <version>5</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-671" comment="InternetSrvcs.INETSVCS-RUN, InternetSrvcs.INET-ENG-A-MAN, or VirtualVaultOS.VVOS-AUX-IA (B.11.04) is installed" negate="false"/>
          <criterion test_ref="cmp-674" comment="700 Series or 800 Series OS Release 11.04" negate="false"/>
          <criterion test_ref="hpt-5" comment="Patch PHNE_24395 or later is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1030" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>COM Internet Services</product>
      </affected>
      <dates>
        <submitted date="2004-05-25-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2004-06-18-12:00">INTERIM</status_change>
        <status_change date="2004-07-02-12:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the COM Internet Services and in the RPC over HTTP Proxy components for Microsoft Windows NT Server 4.0, NT 4.0 Terminal Server Edition, 2000, XP, and Server 2003 allows remote attackers to cause a denial of service via a crafted request.</description>
      <reference source="CVE">CVE-2003-0807</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-193" comment="Windows Server 2003 (excluding WinXP 64-bit, Version 2003) is installed" negate="false"/>
          <criterion test_ref="cmp-190" comment="a vulnerable version of rpcproxy.dll exists on Server 2003" negate="false"/>
          <criterion test_ref="wrt-189" comment="the patch kb828741 is installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-385" comment="COM Internet Services are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1032" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Help and Support Center (HSC)</product>
      </affected>
      <dates>
        <submitted date="2004-05-12-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2004-06-16-12:00">INTERIM</status_change>
        <status_change date="2004-06-30-12:00">ACCEPTED</status_change>
      </dates>
      <description>Help and Support Center in Microsoft Windows XP and Windows Server 2003 SP1 does not properly validate HCP URLs, which allows remote attackers to execute arbitrary code, as demonstrated using certain hcp:// URLs that access the DVD Upgrade capability (dvdupgrd.htm).</description>
      <reference source="CVE">CVE-2004-0199</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wft-294" comment="the version of helpctr.exe is less than 5.2.3790.161" negate="false"/>
          <criterion test_ref="wrt-10" comment="the patch kb840374 is installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-12" comment="the HCP Protocol is registered" negate="true"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1033" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>SquirrelMail</product>
      </affected>
      <dates>
        <submitted date="2004-06-29-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-07-21-12:00">INTERIM</status_change>
        <status_change date="2004-08-11-12:00">ACCEPTED</status_change>
      </dates>
      <description>SQL injection vulnerability in SquirrelMail before 1.4.3 RC1 allows remote attackers to execute unauthorized SQL statements, with unknown impact, probably via abook_database.php.</description>
      <reference source="CVE">CVE-2004-0521</reference>
      <status>ACCEPTED</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="rvt-363" comment="squirrelmail rpm version prior to 1.4.3-0.e3.1 is installed" negate="false"/>
          <criterion test_ref="rrt-217" comment="php rpm is installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="rlt-218" comment="httpd is listening on the network" negate="false"/>
          <criterion test_ref="uft-1" comment="/etc/httpd/modules/libphp4.so exists" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1035" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>Red Hat Enteprise Linux 3</product>
      </affected>
      <dates>
        <submitted date="2004-05-12-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-06-16-12:00">INTERIM</status_change>
        <status_change date="2004-06-30-12:00">ACCEPTED</status_change>
      </dates>
      <description>Stack-based buffer overflow in the ncp_lookup function for ncpfs in Linux kernel 2.4.x allows local users to gain privileges.</description>
      <reference source="CVE">CVE-2004-0010</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-347" comment="kernel version is less than 2.4.21-15.EL" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1036" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Veritas Backup Exec 8.5</product>
      </affected>
      <dates>
        <submitted date="2004-06-15-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <status_change date="2004-06-30-12:00">INTERIM</status_change>
        <modified date="2005-04-08-12:00" comment="modified wrt-472 - wrt-472 corrected literal string">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
      </dates>
      <description>Veritas Backup Exec 8.5 and earlier requires that the "RestrictAnonymous" registry key for Microsoft Exchange 2000 must be set to 0, which enables anonymous listing of the SAM database and shares.</description>
      <reference source="CVE">CVE-2002-1117</reference>
      <status>INTERIM</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="ukn-25" comment="Affected bkupexec.exe versions 3.60.1.298" negate="false"/>
          <criterion test_ref="wrt-472" comment="Veritas Backup Exec 8.5 Installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-471" comment="RestrictAnonymous registry value allows anonymous connections" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1038" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>fetchmail</product>
      </affected>
      <dates>
        <submitted date="2005-08-15-04:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2005-08-19-10:05">DRAFT</status_change>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the POP3 client in Fetchmail before 6.2.5.2 allows remote POP3 servers to cause a denial of service and possibly execute arbitrary code via long UIDL responses.  NOTE: a typo in an advisory accidentally used the wrong CVE identifier for the Fetchmail issue. This is the correct identifier.</description>
      <reference source="CVE">CVE-2005-2335</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-216" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="rvt-29" comment="fetchmail RPM older than 0:6.2.0-3.el3.1" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="upt-858" comment="/usr/bin/fetchmail is executable by any user" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1039" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Microsoft Data Access Components 2.7</product>
      </affected>
      <dates>
        <submitted date="2004-05-04-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <modified date="2004-07-20-12:00" comment="Changed patch registry key value to IsInstalled">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2004-07-21-12:00">INTERIM</status_change>
        <status_change date="2004-08-04-12:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in a component of SQL-DMO for Microsoft Data Access Components (MDAC) 2.5 through 2.7 allows remote attackers to execute arbitrary code via a long response to a broadcast request to UDP port 1434.</description>
      <reference source="CVE">CVE-2003-0353</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-912" comment="Affected MDAC versions" negate="false"/>
          <criterion test_ref="wrt-376" comment="Patch Q823718 Installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1041" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>Remote Procedure Call (RPC)</product>
      </affected>
      <dates>
        <submitted date="2004-04-19-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2004-04-20-12:00">INTERIM</status_change>
        <status_change date="2004-06-16-12:00">ACCEPTED</status_change>
      </dates>
      <description>The DCOM RPC interface for Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to cause network communications via an "alter context" call that contains additional data, aka the "Object Identity Vulnerability."</description>
      <reference source="CVE">CVE-2004-0124</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" negate="false"/>
          <criterion test_ref="cmp-195" comment="a vulnerable version of ole32.dll exists on NT" negate="false"/>
          <criterion test_ref="wrt-189" comment="the patch kb828741 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1042" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>Red Hat Enteprise Linux 3</product>
      </affected>
      <dates>
        <submitted date="2004-05-10-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-05-25-12:00">INTERIM</status_change>
        <status_change date="2004-06-16-12:00">ACCEPTED</status_change>
      </dates>
      <description>The client for CVS before 1.11 allows a remote malicious CVS server to create arbitrary files using certain RCS diff files that use absolute pathnames during checkouts or updates, a different vulnerability than CVE-2004-0405.</description>
      <reference source="CVE">CVE-2004-0180</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-348" comment="cvs version is less than 1.11.2-18" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-931" comment="/usr/bin/cvs is executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1044" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <solaris:platform>Sun Solaris 10</solaris:platform>
        <product>X</product>
      </affected>
      <dates>
        <submitted date="2006-02-12-01:16">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-03-09-12:19">DRAFT</status_change>
        <status_change date="2006-04-06-06:30">INTERIM</status_change>
        <status_change date="2006-05-03-10:06">ACCEPTED</status_change>
      </dates>
      <description>Multiple integer overflows in XFree86 before 4.3.0 allow user-complicit attackers to execute arbitrary code via a crafted pixmap image.</description>
      <reference source="CVE">CVE-2005-2495</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-750" comment="Solaris 8 (SPARC,Xsun) meets Sun Alert ID 101926 criteria." negate="false"/>
          <criterion test_ref="cmp-751" comment="Solaris 9 (SPARC,Xsun) meets Sun Alert ID 101926 criteria." negate="false"/>
          <criterion test_ref="cmp-752" comment="Solaris 10 (SPARC,Xsun) meets Sun Alert ID 101926 criteria." negate="false"/>
          <criterion test_ref="cmp-753" comment="Solaris 8 (x86,Xsun) meets Sun Alert ID 101926 criteria." negate="false"/>
          <criterion test_ref="cmp-754" comment="Solaris 9 (x86,Xsun) meets Sun Alert ID 101926 criteria." negate="false"/>
          <criterion test_ref="cmp-756" comment="Solaris 10 (x86,Xsun) meets Sun Alert ID 101926 criteria." negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-22" comment="The Xsun X server is running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1045" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Print Spooler Service</product>
      </affected>
      <dates>
        <submitted date="2005-09-19-04:00">
          <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
        </submitted>
        <status_change date="2005-09-21-01:33">DRAFT</status_change>
        <status_change date="2005-10-12-05:49">INTERIM</status_change>
        <status_change date="2005-11-16-08:02">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the Print Spooler service (Spoolsv.exe) for Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code via a malicious message.</description>
      <reference source="CVE">CVE-2005-1984</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
          <criterion test_ref="wrt-538" comment="Win2K/XP/2003 service pack 4 (or earlier) is installed" negate="false"/>
          <criterion test_ref="wft-630" comment="the version of Spoolsv.exe is less than 5.0.2195.7059" negate="false"/>
          <criterion test_ref="wrt-370" comment="the patch KB896423 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1046" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Utility Manager</product>
      </affected>
      <dates>
        <submitted date="2004-04-14-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2004-05-25-12:00">INTERIM</status_change>
        <status_change date="2004-06-16-12:00">ACCEPTED</status_change>
      </dates>
      <description>The Utility Manager in Microsoft Windows 2000 executes winhlp32.exe with system privileges, which allows local users to execute arbitrary code via a "Shatter" style attack using a Windows message that accesses the context sensitive help button in the GUI, as demonstrated using the File Open dialog in the Help window, a different vulnerability than CVE-2004-0213.</description>
      <reference source="CVE">CVE-2003-0908</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
          <criterion test_ref="wft-322" comment="the version of umandlg.dll is less than 1.0.0.4" negate="false"/>
          <criterion test_ref="wrt-187" comment="the patch kb835732 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1048" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>snmpdx</product>
      </affected>
      <dates>
        <submitted date="2005-02-01-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-02-01-08:41">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Vulnerabilities in a large number of SNMP implementations allow remote attackers to cause a denial of service or gain privileges via SNMPv1 trap handling, as demonstrated by the PROTOS c06-SNMPv1 test suite.  NOTE: It is highly likely that this candidate will be SPLIT into multiple candidates, one or more for each vendor.  This and other SNMP-related candidates will be updated when more accurate information is available.</description>
      <reference source="CVE">CVE-2002-0012</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-43" comment="Solaris 7 or 8 installed" negate="false"/>
          <criterion test_ref="sat-48" comment="Solstice Enterprise Agents SNMP (SUNWsasnm) installed" negate="false"/>
          <criterion test_ref="spt-104" comment="Patch 107709-18 or later installed" negate="true"/>
          <criterion test_ref="spt-105" comment="Patch 108869-15 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-6" comment="snmpdx running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1049" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <product>OpenSSL</product>
      </affected>
      <dates>
        <submitted date="2004-03-20-12:00">
          <contributor organization="The MITRE Corporation">Matt Busby</contributor>
        </submitted>
        <modified date="2004-05-05-12:00" comment="Corrected syntax errors in sql verion of the definition.">
          <contributor organization="The MITRE Corporation">Matt Busby</contributor>
        </modified>
        <status_change date="2004-05-25-12:00">INTERIM</status_change>
        <status_change date="2004-06-16-12:00">ACCEPTED</status_change>
      </dates>
      <description>The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, which allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that causes an out-of-bounds read.</description>
      <reference source="CVE">CVE-2004-0112</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-201" comment="Red Hat 9 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-318" comment="openssl version is less than 0.9.7a-20" negate="false"/>
          <criterion test_ref="rvt-319" comment="openssl-devel version is less than 0.9.7a-20" negate="false"/>
          <criterion test_ref="rvt-320" comment="openssl-perl version is less than 0.9.7a-20" negate="false"/>
          <criterion test_ref="rvt-321" comment="openssl096 version is less than 0.9.6-25.9" negate="false"/>
          <criterion test_ref="rvt-322" comment="openssl096b version is less than 0.9.6b-15" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1051" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>IIS 5.0</product>
      </affected>
      <dates>
        <submitted date="2004-05-12-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2004-06-16-12:00">INTERIM</status_change>
        <status_change date="2004-06-30-12:00">ACCEPTED</status_change>
      </dates>
      <description>Directory traversal vulnerability in IIS 5.0 and earlier allows remote attackers to execute arbitrary commands by encoding .. (dot dot) and "\" characters twice.</description>
      <reference source="CVE">CVE-2001-0333</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-223" comment="IIS major version equals 5" negate="false"/>
          <criterion test_ref="wrt-215" comment="IIS minor version equals 0" negate="false"/>
          <criterion test_ref="wft-339" comment="File %windir%\System32\msw3prt.dll is less than 5.0.2195.3649" negate="false"/>
          <criterion test_ref="wrt-249" comment="Patch Q293826 Installed" negate="true"/>
          <criterion test_ref="wrt-242" comment="Patch Q301625 Installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1052" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Rockliffe MailSite Express</product>
      </affected>
      <dates>
        <submitted date="2006-01-25-07:14">
          <contributor organization="OS2A">Rahul Mohandas</contributor>
        </submitted>
        <status_change date="2006-01-25-07:30">DRAFT</status_change>
        <status_change date="2006-02-22-08:27">INTERIM</status_change>
        <status_change date="2006-03-09-12:19">ACCEPTED</status_change>
      </dates>
      <description>Cross-site scripting (XSS) vulnerability in Rockliffe MailSite Express before 6.1.22 allows remote attackers to inject arbitrary web script or HTML via a message body.</description>
      <reference source="CVE">CVE-2005-3428</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-633" comment="the software MailSite Express version 6.1.20 or earlier is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1053" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Compressed Folders</product>
      </affected>
      <dates>
        <submitted date="2004-10-14-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
        <status_change date="2004-10-20-12:00">DRAFT</status_change>
        <status_change date="2004-11-03-12:00">INTERIM</status_change>
        <status_change date="2004-12-09-12:00">ACCEPTED</status_change>
        <modified date="2005-01-13-12:00" comment="modified wrt-554 - corrected regular exprsssion on value. Needed to escape the period in the file name and change the *'s to .*">
          <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
        </modified>
        <status_change date="2005-01-20-12:00">INTERIM</status_change>
        <status_change date="2005-02-16-12:00">ACCEPTED</status_change>
        <modified date="2005-05-05-12:00" comment="Removed the negate=&quot;true&quot; from the config test; should be vulnerable *if* enabled, rather than vulnerable if *not*  enabled.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2005-05-11-05:33">INTERIM</status_change>
        <status_change date="2005-06-01-03:30">ACCEPTED</status_change>
      </dates>
      <description>Integer overflow in DUNZIP32.DLL for Microsoft Windows XP, Windows XP 64-bit Edition, Windows Server 2003, and Windows Server 2003 64-bit Edition allows remote attackers to execute arbitrary code via compressed (zipped) folders that involve an "unchecked buffer" and improper length validation.</description>
      <reference source="CVE">CVE-2004-0575</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-2" comment="Windows XP is installed" negate="false"/>
          <criterion test_ref="wrt-72" comment="32-Bit version of Windows is installed" negate="false"/>
          <criterion test_ref="wrt-29" comment="Win2K/XP/2003 service pack 2 (or later) is installed" negate="true"/>
          <criterion test_ref="cmp-1141" comment="vulnerable 32-bit version of zipfldr.dll" negate="false"/>
          <criterion test_ref="wrt-553" comment="the patch q873376 is installed (Hotfix key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-554" comment="Compressed Folders with zipfldr.dll are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1054" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Windows logon process (winlogon)</product>
      </affected>
      <dates>
        <submitted date="2004-04-13-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <status_change date="2004-05-05-12:00">INTERIM</status_change>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
        <modified date="2004-09-13-11:26" comment="cmp-66 added">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2004-09-15-12:00">INTERIM</status_change>
        <status_change date="2004-09-29-12:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the Windows logon process (winlogon) in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, and XP SP1, when a member of a domain, allows remote attackers to execute arbitrary code.</description>
      <reference source="CVE">CVE-2003-0806</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-120" comment="a vulnerable version of msgina.dll exists" negate="false"/>
          <criterion test_ref="wrt-187" comment="the patch kb835732 is installed" negate="true"/>
          <criterion test_ref="cmp-66" comment="Windows XP (sp1 or earlier) is installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-196" comment="machine is a member of a domain" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1056" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>CertGetCertificateChain, CertVerifyCertificateChainPolicy, and WinVerifyTrust APIs</product>
      </affected>
      <dates>
        <submitted date="2004-07-12-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <modified date="2004-07-13-12:00" comment="Added superceding patch info.">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2004-08-04-12:00">INTERIM</status_change>
        <status_change date="2004-08-25-12:00">ACCEPTED</status_change>
        <modified date="2004-09-13-12:00" comment="cmp-66 added">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2004-09-15-12:00">INTERIM</status_change>
        <status_change date="2004-09-29-12:00">ACCEPTED</status_change>
        <modified date="2005-06-02-12:00" comment="Added product">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-06-08-03:17">INTERIM</status_change>
        <status_change date="2005-06-29-06:49">ACCEPTED</status_change>
      </dates>
      <description>The (1) CertGetCertificateChain, (2) CertVerifyCertificateChainPolicy, and (3) WinVerifyTrust APIs within the CryptoAPI for Microsoft products including Microsoft Windows 98 through XP, Office for Mac, Internet Explorer for Mac, and Outlook Express for Mac, do not properly verify the Basic Constraints of intermediate CA-signed X.509 certificates, which allows remote attackers to spoof the certificates of trusted sites via a man-in-the-middle attack for SSL sessions, as originally reported for Internet Explorer and IIS.</description>
      <reference source="CVE">CVE-2002-0862</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wft-432" comment="the version of crypt32.dll is less than 5.131.2600.1123" negate="false"/>
          <criterion test_ref="wrt-477" comment="the patch Q329115 is installed" negate="true"/>
          <criterion test_ref="wrt-187" comment="the patch kb835732 is installed" negate="true"/>
          <criterion test_ref="cmp-66" comment="Windows XP (sp1 or earlier) is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1057" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>HTML Help Facility</product>
      </affected>
      <dates>
        <submitted date="2005-06-20-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <status_change date="2005-06-22-12:38">DRAFT</status_change>
        <status_change date="2005-07-27-10:37">INTERIM</status_change>
        <status_change date="2005-08-18-07:37">ACCEPTED</status_change>
      </dates>
      <description>Integer overflow in Microsoft Windows 98, 2000, XP SP2 and earlier, and Server 2003 SP1 and earlier allows remote attackers to execute arbitrary code via a crafted compiled Help (.CHM) file with a large size field that triggers a heap-based buffer overflow, as demonstrated using a "ms-its:" URL in Internet Explorer.</description>
      <reference source="CVE">CVE-2005-1208</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-2" comment="Windows XP is installed" negate="false"/>
          <criterion test_ref="cmp-49" comment="a vulnerable version of hh.exe exists" negate="false"/>
          <criterion test_ref="wrt-57" comment="the patch kb896358 is installed (Hotfix key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1059" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>Certificate Validation</product>
      </affected>
      <dates>
        <submitted date="2004-07-12-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <modified date="2004-07-13-12:00" comment="Added superceding patch info.">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <modified date="2004-07-14-12:00" comment="Changed to DRAFT">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2004-08-04-12:00">INTERIM</status_change>
        <status_change date="2004-08-25-12:00">ACCEPTED</status_change>
        <status_change date="2004-08-26-12:00">INTERIM</status_change>
        <status_change date="2004-09-09-12:00">ACCEPTED</status_change>
        <modified date="2005-06-02-12:00" comment="Added product">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-06-08-03:17">INTERIM</status_change>
        <status_change date="2005-06-29-06:49">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Windows 98 and Windows NT 4.0 do not properly verify the Basic Constraints of digital certificates, allowing remote attackers to execute code, aka "New Variant of Certificate Validation Flaw Could Enable Identity Spoofing" (CAN-2002-0862).</description>
      <reference source="CVE">CVE-2002-1183</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-45" comment="Windows NT Server 4.0, Terminal Server Edition is installed" negate="false"/>
          <criterion test_ref="wft-434" comment="the version of cryptdlg.dll is less then 5.0.1558.6072" negate="false"/>
          <criterion test_ref="wrt-477" comment="the patch Q329115 is installed" negate="true"/>
          <criterion test_ref="wrt-187" comment="the patch kb835732 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1060" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>Red Hat Enteprise Linux 3</product>
      </affected>
      <dates>
        <submitted date="2004-05-10-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-05-25-12:00">INTERIM</status_change>
        <status_change date="2004-06-16-12:00">ACCEPTED</status_change>
      </dates>
      <description>CVS before 1.11 allows CVS clients to read arbitrary files via .. (dot dot) sequences in filenames via CVS client requests, a different vulnerability than CVE-2004-0180.</description>
      <reference source="CVE">CVE-2004-0405</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-348" comment="cvs version is less than 1.11.2-18" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-931" comment="/usr/bin/cvs is executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1061" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Microsoft Internet Explorer 6</product>
      </affected>
      <dates>
        <submitted date="2005-08-23-04:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2005-08-25-10:05">DRAFT</status_change>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
        <modified date="2005-12-26-09:40" comment="Removed reference to patch kb896727 from criteria.">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </modified>
        <status_change date="2006-01-12-08:59">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 5.0, 5.5, and 6.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not ActiveX controls, including (1) devenum.dll, (2) diactfrm.dll, (3) wmm2filt.dll, (4) fsusd.dll, (5) dmdskmgr.dll, (6) browsewm.dll, (7) browseui.dll, (8) shell32.dll, (9) mshtml.dll, (10) inetcfg.dll, (11) infosoft.dll, (12) query.dll, (13) syncui.dll, (14) clbcatex.dll, (15) clbcatq.dll, (16) comsvcs.dll, and (17) msconf.dll, which causes memory corruption, aka "COM Object Instantiation Memory Corruption Vulnerability," a different vulnerability than CVE-2005-2087.</description>
      <reference source="CVE">CVE-2005-1990</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-200" comment="Internet Explorer 6.0 Installed XP SP2" negate="false"/>
          <criterion test_ref="wft-626" comment="the version of mshtml.dll is less than 6.0.2900.2722" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1062" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Remote Procedure Call (RPC)</product>
      </affected>
      <dates>
        <submitted date="2004-04-20-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2004-05-25-12:00">INTERIM</status_change>
        <status_change date="2004-06-16-12:00">ACCEPTED</status_change>
      </dates>
      <description>The DCOM RPC interface for Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to cause network communications via an "alter context" call that contains additional data, aka the "Object Identity Vulnerability."</description>
      <reference source="CVE">CVE-2004-0124</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
          <criterion test_ref="wft-177" comment="the version of comsvcs.dll is less than 2000.2.3511.0" negate="false"/>
          <criterion test_ref="wrt-189" comment="the patch kb828741 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1063" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2005-11-09-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-11-10-07:06">DRAFT</status_change>
        <status_change date="2005-12-01-06:00">INTERIM</status_change>
        <status_change date="2005-12-16-01:04">ACCEPTED</status_change>
      </dates>
      <description>Multiple integer overflows in the Graphics Rendering Engine (GDI32.DLL) in Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allow remote attackers to execute arbitrary code via crafted Windows Metafile (WMF) and Enhanced Metafile (EMF) format images that lead to heap-based buffer overflows, as demonstrated using MRBP16::bCheckRecord.</description>
      <reference source="CVE">CVE-2005-2123</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-212" comment="Windows 2000 Service Pack 4 (or later) is installed" negate="false"/>
          <criterion test_ref="cmp-644" comment="version of Gdi32.dll is less than 5.0.2195.7069 OR the version of Mf3216.dll is less than 5.0.2195.6898" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1064" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Enhanced Metafile (EMF)</product>
        <product>Windows Metafile (WMF)</product>
      </affected>
      <dates>
        <submitted date="2004-04-13-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <status_change date="2004-05-05-12:00">INTERIM</status_change>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
        <modified date="2004-09-13-11:27" comment="cmp-66 added">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2004-09-15-12:00">INTERIM</status_change>
        <status_change date="2004-09-29-12:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the rendering for (1) Windows Metafile (WMF) or (2) Enhanced Metafile (EMF) image formats in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, and XP SP1 allows remote attackers to execute arbitrary code via a malformed WMF or EMF image.</description>
      <reference source="CVE">CVE-2003-0906</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-170" comment="a vulnerable version of mf3216.dll exists on XP" negate="false"/>
          <criterion test_ref="wrt-187" comment="the patch kb835732 is installed" negate="true"/>
          <criterion test_ref="cmp-66" comment="Windows XP (sp1 or earlier) is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1065" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>Red Hat Enteprise Linux 3</product>
      </affected>
      <dates>
        <submitted date="2004-05-10-04:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-05-25-04:00">INTERIM</status_change>
        <status_change date="2004-06-16-04:00">ACCEPTED</status_change>
        <modified date="2005-09-20-04:00" comment="modified upt-36 - Fixed typo: oofice should have been ooffice">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <modified date="2005-09-20-04:01" comment="modified upt-37 - Fixed typo--oofice should have been ooffice">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <modified date="2005-09-20-04:02" comment="modified upt-38 - Fixed typo--oofice should have been ooffice">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <modified date="2005-09-20-04:03" comment="modified cmp-940 - Fixed comment typo--oofice should have been ooffice">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2005-09-21-01:27">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Multiple format string vulnerabilities in (1) neon 0.24.4 and earlier, and other products that use neon including (2) Cadaver, (3) Subversion, and (4) OpenOffice, allow remote malicious WebDAV servers to execute arbitrary code.</description>
      <reference source="CVE">CVE-2004-0179</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="uut-1" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="rvt-349" comment="openoffice version is less than 1.1.0-15.EL" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-937" comment="OpenOffice Permissions" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1066" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Remote Procedure Call (RPC)</product>
      </affected>
      <dates>
        <submitted date="2004-04-13-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2004-05-25-12:00">INTERIM</status_change>
        <status_change date="2004-06-16-12:00">ACCEPTED</status_change>
      </dates>
      <description>The DCOM RPC interface for Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to cause network communications via an "alter context" call that contains additional data, aka the "Object Identity Vulnerability."</description>
      <reference source="CVE">CVE-2004-0124</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wft-179" comment="the version of comsvcs.dll is less than 2001.12.4720.130" negate="false"/>
          <criterion test_ref="wrt-189" comment="the patch kb828741 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1068" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>IIS 5.0</product>
      </affected>
      <dates>
        <submitted date="2004-05-12-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2004-06-16-12:00">INTERIM</status_change>
        <status_change date="2004-06-30-12:00">ACCEPTED</status_change>
        <modified date="2005-01-14-12:00" comment="modified wft-340 - added .dll to end of literal string as needed">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <status_change date="2005-01-20-01:23">INTERIM</status_change>
        <status_change date="2005-02-16-12:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in Internet Printing ISAPI extension in Windows 2000 allows remote attackers to gain root privileges via a long print request that is passed to the extension through IIS 5.0.</description>
      <reference source="CVE">CVE-2001-0241</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-223" comment="IIS major version equals 5" negate="false"/>
          <criterion test_ref="wrt-215" comment="IIS minor version equals 0" negate="false"/>
          <criterion test_ref="wft-340" comment="File %windir%\System32\Msw3prt.dll is less than 5.0.2195.2956" negate="false"/>
          <criterion test_ref="wrt-29" comment="Win2K/XP/2003 service pack 2 (or later) is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1071" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>MSDTC</product>
      </affected>
      <dates>
        <submitted date="2005-10-12-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-10-19-05:46">DRAFT</status_change>
        <status_change date="2005-11-16-08:02">INTERIM</status_change>
        <status_change date="2005-12-01-06:00">ACCEPTED</status_change>
      </dates>
      <description>The MIDL_user_allocate function in the Microsoft Distributed Transaction Coordinator (MSDTC) proxy (MSDTCPRX.DLL) allocates a 4K page of memory regardless of the required size, which allows attackers to overwrite arbitrary memory locations using an incorrect size value that is provided to the NdrAllocate function, which writes management data to memory outside of the allocated buffer.</description>
      <reference source="CVE">CVE-2005-2119</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1058" comment="Windows XP 32-bit edition is installed" negate="false"/>
          <criterion test_ref="wrt-4" comment="Win2K/XP/2003 service pack 1 is installed" negate="false"/>
          <criterion test_ref="cmp-606" comment="Either ole32.dll or rpcss.dll has a version less than 5.1.2600.1720" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1072" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Remote Procedure Call (RPC)</product>
      </affected>
      <dates>
        <submitted date="2004-04-20-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2004-05-25-12:00">INTERIM</status_change>
        <status_change date="2004-06-16-12:00">ACCEPTED</status_change>
        <modified date="2004-09-13-11:34" comment="cmp-66 added">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2004-09-15-12:00">INTERIM</status_change>
        <status_change date="2004-09-29-12:00">ACCEPTED</status_change>
      </dates>
      <description>The DCOM RPC interface for Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to cause network communications via an "alter context" call that contains additional data, aka the "Object Identity Vulnerability."</description>
      <reference source="CVE">CVE-2004-0124</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wft-178" comment="the version of comsvcs.dll is less than 2001.12.4414.53" negate="false"/>
          <criterion test_ref="wrt-189" comment="the patch kb828741 is installed" negate="true"/>
          <criterion test_ref="cmp-66" comment="Windows XP (sp1 or earlier) is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1073" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 4</redhat:platform>
        <product>mozilla</product>
      </affected>
      <dates>
        <submitted date="2005-08-15-04:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2005-08-19-10:05">DRAFT</status_change>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Firefox before 1.0.5 allows remote attackers to steal information and possibly execute arbitrary code by using standalone applications such as Flash and QuickTime to open a javascript: URL, which is run in the context of the previous page, and may lead to code execution if the standalone application loads a privileged chrome: URL.</description>
      <reference source="CVE">CVE-2005-2267</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rvt-32" comment="mozilla RPM is earlier than 37:1.7.10-1.4.1" negate="false"/>
          <criterion test_ref="rrt-1" comment="Red Hat Enterprise 4 is installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="upt-859" comment="/usr/bin/mozilla is executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1074" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 10</solaris:platform>
        <product>Perl</product>
      </affected>
      <dates>
        <submitted date="2006-03-02-02:05">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-03-09-12:19">DRAFT</status_change>
        <status_change date="2006-04-06-06:30">INTERIM</status_change>
        <status_change date="2006-05-03-10:06">ACCEPTED</status_change>
      </dates>
      <description>Integer overflow in the format string functionality (Perl_sv_vcatpvfn) in Perl 5.9.2 and 5.8.6 Perl allows attackers to overwrite arbitrary memory and possibly execute arbitrary code via format string specifiers with large values, which causes an integer wrap and leads to a buffer overflow, as demonstrated using format string vulnerabilities in Perl applications.</description>
      <reference source="CVE">CVE-2005-3962</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-769" comment="Solaris 10 (SPARC) meets Sun Alert ID 102192 criteria." negate="false"/>
          <criterion test_ref="cmp-770" comment="Solaris 10 (x86) meets Sun Alert ID 102192 criteria." negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1075" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Telephony Service</product>
      </affected>
      <dates>
        <submitted date="2005-08-11-04:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <status_change date="2005-08-19-10:05">DRAFT</status_change>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the Telephony Application Programming Interface (TAPI) for Microsoft Windows 98, Windows 98 SE, Windows ME, Windows 2000, Windows XP, and Windows Server 2003 allows attackers elevate privileges or execute arbitrary code via a crafted message.</description>
      <reference source="CVE">CVE-2005-0058</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-2" comment="Windows XP is installed" negate="false"/>
          <criterion test_ref="cmp-290" comment=" a vulnerable version of tapisrv.dll exists" negate="false"/>
          <criterion test_ref="wrt-139" comment="the patch kb893756 is installed (Hotfix key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-201" comment="the Telephony service is enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1076" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft ASN.1 Library</product>
      </affected>
      <dates>
        <submitted date="2004-04-13-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
        <status_change date="2004-05-05-12:00">INTERIM</status_change>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Double-free vulnerability in the ASN.1 library as used in Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service and possibly execute arbitrary code.</description>
      <reference source="CVE">CVE-2004-0123</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-139" comment="Windows NT or 2000 is installed" negate="false"/>
          <criterion test_ref="wft-193" comment="the version of msasn1.dll is less than 5.0.2195.6905" negate="false"/>
          <criterion test_ref="wrt-187" comment="the patch kb835732 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1077" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>SQL Server 2000</product>
      </affected>
      <dates>
        <submitted date="2004-06-15-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <status_change date="2004-06-30-12:00">INTERIM</status_change>
        <status_change date="2004-07-12-12:00">ACCEPTED</status_change>
        <modified date="2005-01-13-12:00" comment="modified wft-426 - Added space to registry key. used to say &quot;AppPaths&quot; I changed it to &quot;App Paths&quot;">
          <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
        </modified>
        <status_change date="2005-01-20-12:00">INTERIM</status_change>
        <status_change date="2005-02-16-12:00">ACCEPTED</status_change>
        <modified date="2005-04-08-12:00" comment="modified wft-426 - wft-426 corrected literal string">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <modified date="2005-04-08-10:31" comment="modified wft-427 - wft-427 correct literal string">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <status_change date="2005-04-11-08:48">INTERIM</status_change>
        <status_change date="2005-04-27-12:07">ACCEPTED</status_change>
      </dates>
      <description>Multiple buffer overflows in SQL Server 2000 Resolution Service allow remote attackers to cause a denial of service or execute arbitrary code via UDP packets to port 1434 in which (1) a 0x04 byte causes the SQL Monitor thread to generate a long registry key name, or (2) a 0x08 byte with a long string causes heap corruption.</description>
      <reference source="CVE">CVE-2002-0649</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-460" comment="SQL Server 2000 installed" negate="false"/>
          <criterion test_ref="wft-426" comment="the version of sqlservr.exe is less than 2000.80.636.0" negate="false"/>
          <criterion test_ref="wft-427" comment="the version of ssnetlib.dll is less than 2000.80.636.0" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1079" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>NetBIOS</product>
      </affected>
      <dates>
        <submitted date="2004-05-18-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <status_change date="2004-06-16-12:00">INTERIM</status_change>
        <status_change date="2004-06-30-12:00">ACCEPTED</status_change>
        <modified date="2005-01-13-12:00" comment="modified wrt-398 - corrected regular expression on key. needed to escape all back slashes">
          <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
        </modified>
        <status_change date="2005-01-20-01:23">INTERIM</status_change>
        <status_change date="2005-02-16-12:00">ACCEPTED</status_change>
      </dates>
      <description>Interactions between the CIFS Browser Protocol and NetBIOS as implemented in Microsoft Windows 95, 98, NT, and 2000 allow remote attackers to modify dynamic NetBIOS name cache entries via a spoofed Browse Frame Request in a unicast or UDP broadcast datagram.</description>
      <reference source="CVE">CVE-2000-1079</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-943" comment="Windows 95, 98, NT or 2000 is installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-397" comment="TCP/IP NetBIOS not disabled" negate="false"/>
          <criterion test_ref="wrt-398" comment="WINS Client binding not disabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1081" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>zgrep</product>
      </affected>
      <dates>
        <submitted date="2005-07-11-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2005-07-27-10:36">DRAFT</status_change>
        <status_change date="2005-08-18-07:37">INTERIM</status_change>
        <status_change date="2005-09-21-01:33">ACCEPTED</status_change>
      </dates>
      <description>zgrep in gzip before 1.3.5 does not properly sanitize arguments, which allows local users to execute arbitrary commands via filenames that are injected into a sed script.</description>
      <reference source="CVE">CVE-2005-0758</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="rvt-20" comment="bzip2 RPM earlier than 0:1.0.2-11.EL3.4" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="upt-2" comment="/usr/bin/bzgrep is executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1082" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Outlook</product>
      </affected>
      <dates>
        <submitted date="2006-01-11-12:56">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-01-12-09:21">DRAFT</status_change>
        <status_change date="2006-02-01-09:08">INTERIM</status_change>
        <status_change date="2006-02-22-08:27">ACCEPTED</status_change>
      </dates>
      <description>Unspecified vulnerability in Microsoft Outlook 2000 through 2003, Exchange 5.0 Server SP2 and 5.5 SP4, Exchange 2000 SP3, and Office allows remote attackers to execute arbitrary code via an e-mail message with a crafted Transport Neutral Encapsulation Format (TNEF) MIME attachment, related to message length validation.</description>
      <reference source="CVE">CVE-2006-0002</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wft-739" comment="the version of Mapi32.dll is greater than or equal 6.0.6603.0 (Exchange 2000 Server,SP3 is installed)" negate="false"/>
          <criterion test_ref="wft-737" comment="the version of Mapi32.dll is less than 6.0.6617.47" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1086" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>postgresql</product>
      </affected>
      <dates>
        <submitted date="2005-06-27-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2005-06-29-06:49">DRAFT</status_change>
        <status_change date="2005-07-27-10:37">INTERIM</status_change>
        <status_change date="2005-08-18-07:37">ACCEPTED</status_change>
      </dates>
      <description>The tsearch2 module in PostgreSQL 7.4 through 8.0.x declares the (1) dex_init, (2) snb_en_init, (3) snb_ru_init, (4) spell_init, and (5) syn_init functions as "internal" even when they do not take an internal argument, which allows attackers to cause a denial of service (application crash) and possibly have other impacts via SQL commands that call other functions that accept internal arguments.</description>
      <reference source="CVE">CVE-2005-1410</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="rvt-10" comment="rh-postgresql-contrib rpm is earlier than 0:7.3.10-1" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-1" comment="postmaster (the PostgreSQL master daemon) is running" negate="false"/>
          <criterion test_ref="uft-2" comment="/usr/lib/pgsql/tsearch.so (PostgreSQL's tsearch module) exists as a regular file" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1088" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows ME</windows:platform>
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Outlook Express</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-04:00">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </submitted>
        <status_change date="2005-08-19-10:05">DRAFT</status_change>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Stack-based buffer overflow in the news reader for Microsoft Outlook Express (MSOE.DLL) 5.5 SP2, 6, and 6 SP1 allows remote malicious NNTP servers to execute arbitrary code via a LIST response with a long second field.</description>
      <reference source="CVE">CVE-2005-1213</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-170" comment="Outlook Express 5.5 SP2 is installed" negate="false"/>
          <criterion test_ref="wft-82" comment="the version of inetcomm.dll is less than 5.50.4952.2800" negate="false"/>
          <criterion test_ref="wrt-58" comment="Patch KB897715 Installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1089" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>mozilla</product>
      </affected>
      <dates>
        <submitted date="2005-11-11-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-12-12-10:00">DRAFT</status_change>
        <status_change date="2005-12-28-04:28">INTERIM</status_change>
        <status_change date="2006-01-12-08:59">ACCEPTED</status_change>
      </dates>
      <description>Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to modify HTTP headers of XML HTTP requests via XMLHttpRequest, and possibly use the client to exploit vulnerabilities in servers or proxies.</description>
      <reference source="CVE">CVE-2005-2703</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-621" comment="Mozilla Suite version 1.7.10 or earlier is installed" negate="false"/>
          <criterion test_ref="cmp-631" comment="Mozilla Firefox version 1.0.6 or earlier is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1091" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Internet Explorer</product>
      </affected>
      <dates>
        <submitted date="2005-11-11-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-12-12-10:00">DRAFT</status_change>
        <modified date="2005-12-14-12:00" comment="Updated with newly available information.">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </modified>
        <status_change date="2006-01-04-08:04">INTERIM</status_change>
        <status_change date="2006-01-25-07:30">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Internet Explorer 6 SP2 6.0.2900.2180 and 6.0.2800.1106, and earlier versions, allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a Javascript BODY onload event that calls the window function, aka "Mismatched Document Object Model Objects Memory Corruption Vulnerability."</description>
      <reference source="CVE">CVE-2005-1790</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wrt-10027" comment="Internet Explorer 6 is installed" negate="false"/>
          <criterion test_ref="wft-708" comment="the version of mshtml.dll is less than 6.0.3790.449" negate="false"/>
          <criterion test_ref="wrt-3" comment="a Win2K/XP/2003 service pack is installed" negate="true"/>
          <criterion test_ref="cmp-686" comment="Server 2003 IE Enhanced Security is installed and set." negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1093" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Private Communications Transport (PCT)</product>
      </affected>
      <dates>
        <submitted date="2004-04-13-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <status_change date="2004-05-05-12:00">INTERIM</status_change>
        <status_change date="2004-05-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the Private Communications Transport (PCT) protocol implementation in the Microsoft SSL library, as used in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows 98, and Windows ME, allows remote attackers to execute arbitrary code via PCT 1.0 handshake packets.</description>
      <reference source="CVE">CVE-2003-0719</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wft-172" comment="the version of schannel.dll is less than 5.2.3790.132" negate="false"/>
          <criterion test_ref="wrt-187" comment="the patch kb835732 is installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wmt-5" comment="SSL is enabled" negate="false"/>
          <criterion test_ref="wrt-165" comment="PCT support is disabled" negate="true"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1094" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 98</windows:platform>
        <windows:platform>Microsoft Windows ME</windows:platform>
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Internet Explorer 5.5 Service Pack 2</product>
      </affected>
      <dates>
        <submitted date="2004-04-30-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <status_change date="2004-05-25-12:00">INTERIM</status_change>
        <status_change date="2004-06-16-12:00">ACCEPTED</status_change>
        <status_change date="2004-09-22-12:00">INTERIM</status_change>
        <modified date="2004-09-22-11:10" comment="Replaced IE cumulative patch IDs to correspond to the original IDs">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </modified>
        <status_change date="2004-10-06-12:00">ACCEPTED</status_change>
      </dates>
      <description>Heap-based buffer overflow in plugin.ocx for Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to execute arbitrary code via the Load() method, a different vulnerability than CVE-2003-0115.</description>
      <reference source="CVE">CVE-2003-0233</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-53" comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false"/>
          <criterion test_ref="wft-309" comment="the version of mshtml.dll is less than 5.50.4926.2500" negate="false"/>
          <criterion test_ref="wrt-209" comment="the patch q813489 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-210" comment="the patch q818529 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-211" comment="the patch q822925 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-212" comment="the patch q828750 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-19" comment="the patch q824145 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-141" comment="the patch q832894 is installed (Installed Components key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1095" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 98</windows:platform>
        <windows:platform>Microsoft Windows ME</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>DirectX</product>
      </affected>
      <dates>
        <submitted date="2005-10-12-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-10-19-05:46">DRAFT</status_change>
        <status_change date="2005-11-16-08:02">INTERIM</status_change>
        <status_change date="2005-12-01-06:00">ACCEPTED</status_change>
        <modified date="2006-01-31-05:11" comment="Updated reference to CVE-2003-0346.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2006-02-01-09:07">INTERIM</status_change>
        <status_change date="2006-02-22-08:27">ACCEPTED</status_change>
      </dates>
      <description>Multiple integer overflows in a Microsoft Windows DirectX MIDI library (QUARTZ.DLL) allow remote attackers to execute arbitrary code via a MIDI (.mid) file with (1) large length for a Text or Copyright string, or (2) a large number of tracks, which leads to a heap-based buffer overflow.</description>
      <reference source="CVE">CVE-2003-0346</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-421" comment="DirectX 8.x Installed" negate="false"/>
          <criterion test_ref="wrt-422" comment="Patch Windows2000-KB819696-x86-ENU.EXE Installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1096" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 98</windows:platform>
        <windows:platform>Microsoft Windows ME</windows:platform>
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Internet Explorer 5.5, Internet Explorer 5.5 Service Pack 1</product>
      </affected>
      <dates>
        <submitted date="2004-04-29-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <status_change date="2004-05-25-12:00">INTERIM</status_change>
        <status_change date="2004-06-16-12:00">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 5.5 and earlier allows remote attackers to display a URL in the address bar that is different than the URL that is actually being displayed, which could be used in web site spoofing attacks, aka the "Web page spoofing vulnerability."</description>
      <reference source="CVE">CVE-2001-0339</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-901" comment="Internet Explorer 5.5 Installed" negate="false"/>
          <criterion test_ref="wft-323" comment="File %windir%\system32\mshtml.dll version is less than 5.50.4616.200" negate="false"/>
          <criterion test_ref="wft-324" comment="File %windir%\system32\urlmon.dll version is less than 5.50.4701.2400" negate="false"/>
          <criterion test_ref="wrt-352" comment="Patch Q295106 Installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1097" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Internet Explorer</product>
      </affected>
      <dates>
        <submitted date="2005-12-13-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-12-16-01:03">DRAFT</status_change>
        <status_change date="2006-01-04-08:04">INTERIM</status_change>
        <status_change date="2006-01-25-07:30">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Internet Explorer 5.01, 5.5, and 6, when using an HTTPS proxy server that requires Basic Authentication, sends URLs in cleartext, which allows remote attackers to obtain sensitive information, aka "HTTPS Proxy Vulnerability."</description>
      <reference source="CVE">CVE-2005-2830</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-613" comment="Win2K or XP,SP1 is installed" negate="false"/>
          <criterion test_ref="wrt-50" comment="Internet Explorer 6 Service Pack 1 is installed" negate="false"/>
          <criterion test_ref="wft-705" comment="the version of mshtml.dll is less than 6.0.2800.1528" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1098" class="vulnerability">
      <affected family="hp-ux">
        <hpux:platform>HP-UX 11</hpux:platform>
        <product>Apache</product>
      </affected>
      <dates>
        <submitted date="2006-03-18-07:24">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-03-22-11:10">DRAFT</status_change>
        <status_change date="2006-04-06-06:31">INTERIM</status_change>
        <status_change date="2006-05-03-10:06">ACCEPTED</status_change>
      </dates>
      <description>A security flaw in some versions of the HP-UX usermod command can result in recursively changing the ownership of all directories and files under a user's home directory.  Specifically, executing	# usermod -d &lt;old home dir> -u &lt;new gid> -m &lt;username> or	# usermod -d &lt;old home dir> -u &lt;new or old gid> -m &lt;username> incorrectly changes ownership recursively to &lt;username>.  If the home directory is '/', this action will render the system inoperable.</description>
      <reference source="MISC">http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00614838</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-682" comment="700 Series or 800 Series OS Release 11.23" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1099" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>CDE</product>
      </affected>
      <dates>
        <submitted date="2004-10-15-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2004-10-20-12:00">DRAFT</status_change>
        <status_change date="2004-11-03-12:00">INTERIM</status_change>
        <status_change date="2004-12-09-12:00">ACCEPTED</status_change>
        <modified date="2005-01-11-12:00" comment="modified sat-6 - Changed test to pattern match and added check for 64bit version">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </modified>
        <modified date="2005-01-14-12:00" comment="modified sat-6 - Changed regular expression test to properly check for 64bit package">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </modified>
        <status_change date="2005-01-24-02:33">INTERIM</status_change>
        <status_change date="2005-02-16-12:00">ACCEPTED</status_change>
      </dates>
      <description>CDE ToolTalk database server (ttdbserver) allows remote attackers to overwrite arbitrary memory locations with a zero, and possibly gain privileges, via a file descriptor argument in an AUTH_UNIX procedure call, which is used as a table index by the _TT_ISCLOSE procedure.</description>
      <reference source="CVE">CVE-2002-0677</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-6" comment="Solaris 9 Installed" negate="false"/>
          <criterion test_ref="sat-6" comment="Toolktalk (SUNWtltk/SUNWtltkx) installed" negate="false"/>
          <criterion test_ref="spt-255" comment="Patch 112808-02 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-202" comment="inetd.conf contains rpc.ttdbserverd" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1101" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Internet Explorer</product>
      </affected>
      <dates>
        <submitted date="2005-12-13-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-12-16-01:03">DRAFT</status_change>
        <status_change date="2006-01-04-08:04">INTERIM</status_change>
        <status_change date="2006-01-25-07:30">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Internet Explorer 5.01, 5.5, and 6, when using an HTTPS proxy server that requires Basic Authentication, sends URLs in cleartext, which allows remote attackers to obtain sensitive information, aka "HTTPS Proxy Vulnerability."</description>
      <reference source="CVE">CVE-2005-2830</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1066" comment="Windows XP 64-bit with Service Pack 1" negate="false"/>
          <criterion test_ref="wrt-10027" comment="Internet Explorer 6 is installed" negate="false"/>
          <criterion test_ref="wrt-4" comment="Win2K/XP/2003 service pack 1 is installed" negate="false"/>
          <criterion test_ref="wft-707" comment="the version of mshtml.dll is less than 6.0.3790.2577" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1104" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 98</windows:platform>
        <windows:platform>Microsoft Windows ME</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>DirectX</product>
      </affected>
      <dates>
        <submitted date="2005-10-12-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-10-19-05:46">DRAFT</status_change>
        <status_change date="2005-11-16-08:02">INTERIM</status_change>
        <status_change date="2005-12-01-06:00">ACCEPTED</status_change>
        <modified date="2006-01-31-06:03" comment="Updated reference to CVE-2003-0346.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2006-02-01-09:07">INTERIM</status_change>
        <status_change date="2006-02-22-08:27">ACCEPTED</status_change>
      </dates>
      <description>Multiple integer overflows in a Microsoft Windows DirectX MIDI library (QUARTZ.DLL) allow remote attackers to execute arbitrary code via a MIDI (.mid) file with (1) large length for a Text or Copyright string, or (2) a large number of tracks, which leads to a heap-based buffer overflow.</description>
      <reference source="CVE">CVE-2003-0346</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-334" comment="DirectX 9.0 or 9.0a installed." negate="false"/>
          <criterion test_ref="wrt-422" comment="Patch Windows2000-KB819696-x86-ENU.EXE Installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1105" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>GDI+</product>
      </affected>
      <dates>
        <submitted date="2004-09-20-03:22">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </submitted>
        <status_change date="2004-09-22-02:10">DRAFT</status_change>
        <status_change date="2004-10-06-12:00">INTERIM</status_change>
        <status_change date="2004-10-20-12:00">ACCEPTED</status_change>
        <modified date="2005-12-20-07:05" comment="Changed criteria to filter out 32-bit XP consideration.  wft-493 will always be positive on 32-bit machines.">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </modified>
        <status_change date="2006-01-04-08:04">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length before a memory copy operation.</description>
      <reference source="CVE">CVE-2004-0200</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-647" comment="64-bit XP or Server 2003 is installed" negate="false"/>
          <criterion test_ref="wft-493" comment="the version of sxs.dll is less than 5.2.3790.121" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1106" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>NetWare</product>
      </affected>
      <dates>
        <submitted date="2005-10-12-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-10-19-05:46">DRAFT</status_change>
        <status_change date="2005-11-16-08:02">INTERIM</status_change>
        <status_change date="2005-12-01-06:00">ACCEPTED</status_change>
      </dates>
      <description>The Client Service for NetWare (CSNW) on Microsoft Windows 2000 SP4, XP SP1 and Sp2, and Server 2003 SP1 and earlier, allows remote attackers to execute arbitrary code due to an "unchecked buffer" when processing certain crafted network messages.</description>
      <reference source="CVE">CVE-2005-1985</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-2" comment="Windows XP is installed" negate="false"/>
          <criterion test_ref="wrt-4" comment="Win2K/XP/2003 service pack 1 is installed" negate="false"/>
          <criterion test_ref="wft-670" comment="nwwks.dll is less than 5.1.2600.1727" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1107" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>gzip</product>
      </affected>
      <dates>
        <submitted date="2005-06-20-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2005-06-22-12:38">DRAFT</status_change>
        <status_change date="2005-07-27-10:37">INTERIM</status_change>
        <status_change date="2005-08-18-07:37">ACCEPTED</status_change>
      </dates>
      <description>zgrep in gzip before 1.3.5 does not properly sanitize arguments, which allows local users to execute arbitrary commands via filenames that are injected into a sed script.</description>
      <reference source="CVE">CVE-2005-0758</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="rvt-7" comment="gzip RPM earlier than 0:1.3.3-12rhel3" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="upt-227" comment="/usr/bin/zgrep is executable by any user" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1110" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Solaris Enterprise Authentication Mechanism (SEAM)</product>
      </affected>
      <dates>
        <submitted date="2005-02-01-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-02-01-08:41">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>MIT Kerberos V5 Key Distribution Center (KDC) before 1.2.5 allows remote authenticated attackers to cause a denial of service (crash) on KDCs within the same realm via a certain protocol request that causes a null dereference.</description>
      <reference source="CVE">CVE-2003-0058</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-157" comment="Solaris 7 and Solaris Enterprise Authentication Mechanism OR Solaris 8 or 9 installed" negate="false"/>
          <criterion test_ref="spt-96" comment="Patch 112536-02 or later installed" negate="true"/>
          <criterion test_ref="spt-99" comment="Patch 112908-04 or later installed" negate="true"/>
          <criterion test_ref="spt-97" comment="Patch 112237-07 or later installed" negate="true"/>
          <criterion test_ref="spt-98" comment="Patch 112390-07 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="tft-5" comment="/etc/krb5/krb5.conf is configured with a kerberos domain" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1114" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Internet Explorer 6.0</product>
      </affected>
      <dates>
        <submitted date="2005-02-10-12:00">
          <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
        </submitted>
        <status_change date="2005-02-11-12:00">DRAFT</status_change>
        <status_change date="2005-03-02-12:00">INTERIM</status_change>
        <status_change date="2005-03-23-12:00">ACCEPTED</status_change>
        <modified date="2005-06-02-12:00" comment="Added product">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-06-08-03:17">INTERIM</status_change>
        <status_change date="2005-06-29-06:49">ACCEPTED</status_change>
      </dates>
      <description>The DHTML Edit Control (dhtmled.ocx) allows remote attackers to inject arbitrary web script into other domains by setting a name for a window, opening a child page whose target is the window with the given name, then injecting the script from the parent into the child using execScript, as demonstrated by "AbusiveParent" in Internet Explorer 6.0.2900.2180.</description>
      <reference source="CVE">CVE-2004-1319</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-182" comment="Microsoft Windows Server 2003 32-Bit Edition" negate="false"/>
          <criterion test_ref="wft-376" comment="the version of dhtmled.ocx is less than 6.1.0.9231" negate="false"/>
          <criterion test_ref="wrt-87" comment="the patch kb891781 is installed (Hotfix key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1115" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Microsoft Internet Explorer 6</product>
      </affected>
      <dates>
        <submitted date="2005-06-22-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2005-06-22-02:13">DRAFT</status_change>
        <modified date="2005-06-24-12:00" comment="added description ">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </modified>
        <status_change date="2005-07-27-10:37">INTERIM</status_change>
        <status_change date="2005-08-18-07:37">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the PNG image rendering component of Microsoft Internet Explorer allows remote attackers to execute arbitrary code via a crafted PNG file.</description>
      <reference source="CVE">CVE-2005-1211</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-200" comment="Internet Explorer 6.0 Installed XP SP2" negate="false"/>
          <criterion test_ref="wft-99" comment="the version of mshtml.dll is less than 6.0.2900.2668" negate="false"/>
          <criterion test_ref="wrt-62" comment="the patch kb883939 is installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-59" comment="PNG image rendering enabled in Internet Explorer" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1116" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2005-10-12-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-10-19-05:46">DRAFT</status_change>
        <status_change date="2005-11-16-08:02">INTERIM</status_change>
        <status_change date="2005-12-01-06:00">ACCEPTED</status_change>
      </dates>
      <description>Windows Shell for Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 allows remote user-complicit attackers to execute arbitrary commands via a crafted shortcut (.lnk) file with long font properties that lead to a buffer overflow when the user views the file's properties using Windows Explorer, a different vulnerability than CVE-2005-2122.</description>
      <reference source="CVE">CVE-2005-2118</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1058" comment="Windows XP 32-bit edition is installed" negate="false"/>
          <criterion test_ref="wrt-4" comment="Win2K/XP/2003 service pack 1 is installed" negate="false"/>
          <criterion test_ref="wft-684" comment="shell32.dll is less than 6.0.2800.1751" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1117" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>Linux kernel</product>
      </affected>
      <dates>
        <submitted date="2005-06-29-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2005-06-29-06:49">DRAFT</status_change>
        <status_change date="2005-07-27-10:37">INTERIM</status_change>
        <status_change date="2005-08-18-07:37">ACCEPTED</status_change>
      </dates>
      <description>The linux-2.4.21-mlock.patch in Red Hat Enterprise Linux 3 does not properly maintain the mlock page count when one process unlocks pages that belong to another process, which allows local users to mlock more memory than specified by the rlimit.</description>
      <reference source="CVE">CVE-2004-0491</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="cmp-268" comment="kernel, kernel-smp or kernel-hugemem RPM earlier than 0:2.4.21-32.0.1.EL" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1118" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Remote Procedure Call (RPC)</product>
      </affected>
      <dates>
        <submitted date="2005-01-18-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2005-01-20-12:00">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-12:00">ACCEPTED</status_change>
        <modified date="2005-06-17-12:00" comment="modified cmp-1106 - Replaced the test that checks for the service pack level, instead of checking for sp4 or ealier (did not check for GOLD edition) it is now negating the test that checks for sp5 for later.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <status_change date="2005-06-22-12:35">INTERIM</status_change>
        <status_change date="2005-07-27-10:37">ACCEPTED</status_change>
      </dates>
      <description>The RPC DCOM interface in Windows 2000 SP3 and SP4 allows remote attackers to cause a denial of service (crash), and local attackers to use the DoS to hijack the epmapper pipe to gain privileges, via certain messages to the __RemoteGetClassObject interface that cause a NULL pointer to be passed to the PerformScmStage function.</description>
      <reference source="CVE">CVE-2003-0605</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1106" comment="Windows 2000 (sp4 or earlier) is installed" negate="false"/>
          <criterion test_ref="wft-239" comment="the version of rpcrt4.dll is less than 5.0.2195.6802" negate="false"/>
          <criterion test_ref="wrt-281" comment="the patch kb824146 is installed (Hotfix key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1121" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2005-11-09-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-11-10-07:06">DRAFT</status_change>
        <status_change date="2005-12-01-06:00">INTERIM</status_change>
        <status_change date="2005-12-16-01:04">ACCEPTED</status_change>
      </dates>
      <description>The GetEnhMetaFilePaletteEntries API in GDI32.DLL in Windows 2000 allows remote attackers to cause a denial of service (application crash) via a crafted Enhanced Metafile (EMF) file that causes invalid (1) end, (2) emreof, or (3) palent offsets to be used, aka "Enhanced Metafile Vulnerability."</description>
      <reference source="CVE">CVE-2005-0803</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-2" comment="Windows XP is installed" negate="false"/>
          <criterion test_ref="wrt-250" comment="Win2K/XP/2003 service pack 2 is installed" negate="false"/>
          <criterion test_ref="wft-701" comment="the version of Gdi32.dll is less than 5.1.2600.2770" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1122" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>Linux kernel</product>
      </affected>
      <dates>
        <submitted date="2005-06-29-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2005-06-29-06:49">DRAFT</status_change>
        <status_change date="2005-07-27-10:37">INTERIM</status_change>
        <status_change date="2005-08-18-07:37">ACCEPTED</status_change>
      </dates>
      <description>The elf_core_dump function in binfmt_elf.c for Linux kernel 2.x.x to 2.2.27-rc2, 2.4.x to 2.4.31-pre1, and 2.6.x to 2.6.12-rc4 allows local users to execute arbitrary code via an ELF binary that, in certain conditions involving the create_elf_tables function, causes a negative length argument to pass a signed integer comparison, leading to a buffer overflow.</description>
      <reference source="CVE">CVE-2005-1263</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="cmp-268" comment="kernel, kernel-smp or kernel-hugemem RPM earlier than 0:2.4.21-32.0.1.EL" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1124" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 4</redhat:platform>
        <product>fetchmail</product>
      </affected>
      <dates>
        <submitted date="2005-08-15-04:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2005-08-19-10:05">DRAFT</status_change>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the POP3 client in Fetchmail before 6.2.5.2 allows remote POP3 servers to cause a denial of service and possibly execute arbitrary code via long UIDL responses.  NOTE: a typo in an advisory accidentally used the wrong CVE identifier for the Fetchmail issue. This is the correct identifier.</description>
      <reference source="CVE">CVE-2005-2335</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-1" comment="Red Hat Enterprise 4 is installed" negate="false"/>
          <criterion test_ref="rvt-30" comment="fetchmail RPM earlier than 0:6.2.5-6.el4.2" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="upt-858" comment="/usr/bin/fetchmail is executable by any user" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1125" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Color Management Module</product>
      </affected>
      <dates>
        <submitted date="2005-08-02-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2005-08-03-11:30">DRAFT</status_change>
        <status_change date="2005-08-18-07:37">INTERIM</status_change>
        <status_change date="2005-09-21-01:33">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the Microsoft Color Management Module for Windows allows remote attackers to execute arbitrary code via an image with crafted ICC profile format tags.</description>
      <reference source="CVE">CVE-2005-1219</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wft-572" comment="the version of mscms.dll is less than 5.2.3790.359" negate="false"/>
          <criterion test_ref="wrt-128" comment="the patch KB901214 is installed " negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1126" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2006-01-11-12:56">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-01-12-09:18">DRAFT</status_change>
        <status_change date="2006-02-01-09:08">INTERIM</status_change>
        <status_change date="2006-02-22-08:27">ACCEPTED</status_change>
      </dates>
      <description>Heap-based buffer overflow in T2EMBED.DLL in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 up to SP1, Windows 98, and Windows ME allows remote attackers to execute arbitrary code via an e-mail message or web page with a crafted Embedded Open Type (EOT) web font that triggers the overflow during decompression.</description>
      <reference source="CVE">CVE-2006-0010</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wrt-10026" comment="Win2K/XP/2003 is patched" negate="true"/>
          <criterion test_ref="cmp-711" comment="Fontsub.dll &lt; 5.2.3790.426 or T2embed.dll &lt;5.2.3790.426 (S03-Gold)" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1127" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>uucp</product>
      </affected>
      <dates>
        <submitted date="2005-04-13-04:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-04-20-04:00">DRAFT</status_change>
        <status_change date="2005-05-11-04:00">INTERIM</status_change>
        <status_change date="2005-06-01-04:00">ACCEPTED</status_change>
        <modified date="2005-08-22-04:00" comment="Product set to uucp; was mistakenly .NET framework">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2005-08-25-10:03">INTERIM</status_change>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Multiple buffer overflows in uucp for Sun Solaris 2.6, 7, 8, and 9 allow local users to execute arbitrary code as the uucp user.</description>
      <reference source="CVE">CVE-2004-1359</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" negate="false"/>
          <criterion test_ref="sat-42" comment="Networking UUCP Utilities - Usr (SUNWbnuu) installed" negate="false"/>
          <criterion test_ref="spt-86" comment="Patch 106952-04 or later installed" negate="true"/>
          <criterion test_ref="spt-87" comment="Patch 111570-03 or later installed" negate="true"/>
          <criterion test_ref="spt-88" comment="Patch 113322-02 or later installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1130" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2005-10-12-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-10-19-05:46">DRAFT</status_change>
        <status_change date="2005-11-16-08:02">INTERIM</status_change>
        <status_change date="2005-12-01-06:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in Collaboration Data Objects (CDO), as used in Microsoft Windows and Microsoft Exchange Server, allows remote attackers to execute arbitrary code when CDOSYS or CDOEX processes an e-mail message with a large header name, as demonstrated using the "Content-Type" string.</description>
      <reference source="CVE">CVE-2005-1987</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wrt-10026" comment="Win2K/XP/2003 is patched" negate="true"/>
          <criterion test_ref="wft-681" comment="cdosys.dll is less than 6.5.6749.0" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1132" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Services for UNIX</product>
      </affected>
      <dates>
        <submitted date="2005-06-22-12:00">
          <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
        </submitted>
        <status_change date="2005-06-22-12:38">DRAFT</status_change>
        <status_change date="2005-07-27-10:37">INTERIM</status_change>
        <status_change date="2005-08-18-07:37">ACCEPTED</status_change>
      </dates>
      <description>The Telnet client for Microsoft Windows XP, Windows Server 2003, and Windows Services for UNIX allows remote attackers to read sensitive environment variables via the NEW-ENVIRON option with a SEND ENV_USERVAR command.</description>
      <reference source="CVE">CVE-2005-1205</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-2" comment="Windows XP is installed" negate="false"/>
          <criterion test_ref="cmp-181" comment="a vulnerable version of telnet.exe exists" negate="false"/>
          <criterion test_ref="wrt-27" comment="the patch KB896428 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1133" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows ME</windows:platform>
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Microsoft Internet Explorer 6 Service Pack 1</product>
      </affected>
      <dates>
        <submitted date="2004-07-30-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <status_change date="2004-08-02-12:00">DRAFT</status_change>
        <status_change date="2004-08-25-12:00">INTERIM</status_change>
        <status_change date="2004-09-09-12:00">ACCEPTED</status_change>
        <modified date="2005-09-26-11:01" comment="modified wft-267 - Changed comment to match test">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-28-01:04">INTERIM</status_change>
        <status_change date="2005-10-19-05:47">ACCEPTED</status_change>
      </dates>
      <description>The WebBrowser ActiveX control, or the Internet Explorer HTML rendering engine (MSHTML), as used in Internet Explorer 6, allows remote attackers to execute arbitrary code in the Local Security context by using the showModalDialog method and modifying the location to execute code such as Javascript, as demonstrated using (1) delayed HTTP redirect operations, and an HTTP response with a Location: header containing a "URL:" prepended to a "ms-its" protocol URI, or (2) modifying the location attribute of the window, as exploited by the Download.ject (aka Scob aka Toofer) using the ADODB.Stream object.</description>
      <reference source="CVE">CVE-2004-0549</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-50" comment="Internet Explorer 6 Service Pack 1 is installed" negate="false"/>
          <criterion test_ref="wft-267" comment="the version of mshtml.dll is less than 6.0.2800.1458" negate="false"/>
          <criterion test_ref="wrt-245" comment="the patch kb832894 is installed (Installed Components key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1134" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>TIP</product>
      </affected>
      <dates>
        <submitted date="2005-10-12-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-10-19-05:46">DRAFT</status_change>
        <status_change date="2005-11-16-08:02">INTERIM</status_change>
        <status_change date="2005-12-01-06:00">ACCEPTED</status_change>
      </dates>
      <description>Distributed Transaction Controller in Microsoft Windows allows remote servers to cause a denial of service (MSDTC service exception and exit) via an "unexpected protocol command during the reconnection request," which is not properly handled by the Transaction Internet Protocol (TIP) functionality.</description>
      <reference source="CVE">CVE-2005-1979</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1058" comment="Windows XP 32-bit edition is installed" negate="false"/>
          <criterion test_ref="cmp-35" comment="Windows XP 32 bit Service Pack 2" negate="false"/>
          <criterion test_ref="cmp-607" comment="Either ole32.dll or rpcss.dll has a version less than 5.1.2600.2726" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1136" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>TIP</product>
      </affected>
      <dates>
        <submitted date="2005-10-12-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-10-19-05:46">DRAFT</status_change>
        <status_change date="2005-11-16-08:02">INTERIM</status_change>
        <status_change date="2005-12-01-06:00">ACCEPTED</status_change>
      </dates>
      <description>Distributed Transaction Controller in Microsoft Windows allows remote servers to cause a denial of service (MSDTC service hang) via a crafted Transaction Internet Protocol (TIP) message that causes DTC to repeatedly connect to a target IP and port number after an error occurs, aka the "Distributed TIP Vulnerability."</description>
      <reference source="CVE">CVE-2005-1980</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wrt-4" comment="Win2K/XP/2003 service pack 1 is installed" negate="false"/>
          <criterion test_ref="cmp-608" comment="Either ole32.dll or rpcss.dll has a version less than 5.2.3790.2492" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1139" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>telnet</product>
      </affected>
      <dates>
        <submitted date="2005-07-11-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2005-07-27-10:36">DRAFT</status_change>
        <status_change date="2005-08-18-07:37">INTERIM</status_change>
        <status_change date="2005-09-21-01:33">ACCEPTED</status_change>
      </dates>
      <description>Certain BSD-based Telnet clients, including those used on Solaris and SuSE Linux, allow remote malicious Telnet servers to read sensitive environment variables via the NEW-ENVIRON option with a SEND ENV_USERVAR command.</description>
      <reference source="CVE">CVE-2005-0488</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="rvt-22" comment="telnet RPM earlier than 1:0.17-20.EL3.3" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="upt-57" comment="/usr/bin/telnet is executable by any user" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1140" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Microsoft Internet Explorer 6 Service Pack 1</product>
      </affected>
      <dates>
        <submitted date="2005-08-23-04:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2005-08-25-10:05">DRAFT</status_change>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Unknown vulnerability in Internet Explorer 5.0, 5.5, and 6.0 allows remote attackers to execute arbitrary code via a web site or an HTML e-mail containing a crafted JPEG image that causes memory corruption, aka "JPEG Image Rendering Memory Corruption Vulnerability".</description>
      <reference source="CVE">CVE-2005-1988</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-50" comment="Internet Explorer 6 Service Pack 1 is installed" negate="false"/>
          <criterion test_ref="cmp-317" comment="the version of mshtml.dll is less than 6.0.2800.1515 or 6.0.2800.1516 " negate="false"/>
          <criterion test_ref="wrt-346" comment="the patch kb896727 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1142" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>SMB (Server Message Block)</product>
      </affected>
      <dates>
        <submitted date="2005-06-22-12:00">
          <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
        </submitted>
        <status_change date="2005-06-22-12:38">DRAFT</status_change>
        <status_change date="2005-07-27-10:37">INTERIM</status_change>
        <status_change date="2005-08-18-07:37">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the Server Message Block (SMB) functionality for Microsoft Windows 2000, XP SP1 and SP2, and Server 2003 and SP1 allows remote attackers to execute arbitrary code via unknown vectors, aka the "Server Message Block Vulnerability."</description>
      <reference source="CVE">CVE-2005-1206</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-2" comment="Windows XP is installed" negate="false"/>
          <criterion test_ref="cmp-254" comment=" a vulnerable version of srv.sys exists" negate="false"/>
          <criterion test_ref="wrt-63" comment="the patch KB896422 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1143" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Internet Explorer</product>
      </affected>
      <dates>
        <submitted date="2005-12-13-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-12-16-01:03">DRAFT</status_change>
        <status_change date="2006-01-04-08:04">INTERIM</status_change>
        <status_change date="2006-01-25-07:30">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Internet Explorer 5.01, 5.5, and 6, when using an HTTPS proxy server that requires Basic Authentication, sends URLs in cleartext, which allows remote attackers to obtain sensitive information, aka "HTTPS Proxy Vulnerability."</description>
      <reference source="CVE">CVE-2005-2830</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wrt-10027" comment="Internet Explorer 6 is installed" negate="false"/>
          <criterion test_ref="wft-707" comment="the version of mshtml.dll is less than 6.0.3790.2577" negate="false"/>
          <criterion test_ref="wrt-4" comment="Win2K/XP/2003 service pack 1 is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1144" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Internet Explorer</product>
      </affected>
      <dates>
        <submitted date="2006-04-12-12:55">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-04-12-05:16">DRAFT</status_change>
        <status_change date="2006-05-03-10:06">INTERIM</status_change>
      </dates>
      <description>Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via HTML elements with a certain crafted tag, which leads to memory corruption.</description>
      <reference source="CVE">CVE-2006-1188</reference>
      <status>INTERIM</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wrt-4" comment="Win2K/XP/2003 service pack 1 is installed" negate="false"/>
          <criterion test_ref="wft-779" comment="the version of mshtml.dll is less than 6.0.3790.2666" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1145" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>ISA Server 2000</product>
      </affected>
      <dates>
        <submitted date="2005-06-23-04:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2005-06-29-04:00">DRAFT</status_change>
        <status_change date="2005-07-27-04:00">INTERIM</status_change>
        <status_change date="2005-08-18-04:00">ACCEPTED</status_change>
        <modified date="2005-09-19-04:00" comment="modified wft-81 - Removed extra trailing \\ on registry component.">
          <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
        </modified>
        <status_change date="2005-09-21-01:27">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Microsoft ISA Server 2000 allows remote attackers to poison the ISA cache or bypass content restriction policies via a malformed HTTP request packet containing multiple Content-Length headers.</description>
      <reference source="CVE">CVE-2005-1215</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-11" comment="ISA Server 2000 SP2 (or earlier) is installed" negate="false"/>
          <criterion test_ref="wft-81" comment="the version of w3proxy.exe is less than 3.0.1200.430" negate="false"/>
          <criterion test_ref="wrt-52" comment="the patch KB899753 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1146" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2005-10-12-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-10-19-05:46">DRAFT</status_change>
        <status_change date="2005-11-16-08:02">INTERIM</status_change>
        <status_change date="2005-12-01-06:00">ACCEPTED</status_change>
      </dates>
      <description>The FTP client in Windows XP SP1 and Server 2003, and Internet Explorer 6 SP1 on Windows 2000 SP4, when "Enable Folder View for FTP Sites" is enabled and the user manually initiates a file transfer, allows user-complicit, remote FTP servers to overwrite files in arbitrary locations via crafted filenames.</description>
      <reference source="CVE">CVE-2005-2126</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
          <criterion test_ref="wrt-432" comment="Win2K/XP/2003 service pack 4 is installed" negate="false"/>
          <criterion test_ref="wrt-50" comment="Internet Explorer 6 Service Pack 1 is installed" negate="false"/>
          <criterion test_ref="wft-689" comment="msieftp.dll is less than 5.50.4956.500" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1147" class="vulnerability">
      <affected family="hp-ux">
        <hpux:platform>HP-UX 11</hpux:platform>
        <product>ftpd</product>
      </affected>
      <dates>
        <submitted date="2006-01-30-07:20">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-02-01-09:08">DRAFT</status_change>
        <status_change date="2006-02-22-08:27">INTERIM</status_change>
        <status_change date="2006-03-09-12:19">ACCEPTED</status_change>
      </dates>
      <description>wu-ftpd 2.6.2 and earlier, with the restricted-gid option enabled, allows local users to bypass access restrictions by changing the permissions to prevent access to their home directory, which causes wu-ftpd to use the root directory instead.</description>
      <reference source="CVE">CVE-2004-0148</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-618" comment="700 Series or 800 Series OS Release 11.11" negate="false"/>
          <criterion test_ref="hst-52" comment="WUFTP-26.INETSVCS-FTP with version less than B.11.00.01.004 is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1148" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Microsoft Internet Explorer 6</product>
      </affected>
      <dates>
        <submitted date="2005-06-22-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2005-06-22-12:38">DRAFT</status_change>
        <status_change date="2005-07-27-10:37">INTERIM</status_change>
        <status_change date="2005-08-18-07:37">ACCEPTED</status_change>
      </dates>
      <description>The legacy &lt;script> data-island capability for XML in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to read arbitrary XML files, and portions of other files, via a URL whose "src" attribute redirects to a local file.</description>
      <reference source="CVE">CVE-2002-0648</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-200" comment="Internet Explorer 6.0 Installed XP SP2" negate="false"/>
          <criterion test_ref="wft-99" comment="the version of mshtml.dll is less than 6.0.2900.2668" negate="false"/>
          <criterion test_ref="wrt-62" comment="the patch kb883939 is installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1149" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>DirectX</product>
      </affected>
      <dates>
        <submitted date="2005-10-12-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-10-19-05:46">DRAFT</status_change>
        <status_change date="2005-11-16-08:02">INTERIM</status_change>
        <status_change date="2005-12-01-06:00">ACCEPTED</status_change>
      </dates>
      <description>QUARTZ.DLL in Microsoft Windows Media Player 9 allows remote attackers to write a null byte to arbitrary memory via an AVI file with a crafted strn element with a modified length value.</description>
      <reference source="CVE">CVE-2005-2128</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-604" comment="DirectX packaged with Windows Server 2003,SP1 has DirectShow Vulnerability" negate="false"/>
          <criterion test_ref="cmp-598" comment="Standalone DirectX 8 has DirectShow Vulnerability" negate="false"/>
          <criterion test_ref="cmp-599" comment="Standalone DirectX 9 has DirectShow Vulnerability" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1150" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>mozilla</product>
      </affected>
      <dates>
        <submitted date="2005-11-11-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-12-12-10:00">DRAFT</status_change>
        <status_change date="2005-12-28-04:28">INTERIM</status_change>
        <status_change date="2006-01-12-08:59">ACCEPTED</status_change>
      </dates>
      <description>Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via Unicode sequences with "zero-width non-joiner" characters.</description>
      <reference source="CVE">CVE-2005-2702</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-621" comment="Mozilla Suite version 1.7.10 or earlier is installed" negate="false"/>
          <criterion test_ref="cmp-631" comment="Mozilla Firefox version 1.0.6 or earlier is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1151" class="vulnerability">
      <affected family="hp-ux">
        <hpux:platform>HP-UX 11</hpux:platform>
        <product>remshd</product>
      </affected>
      <dates>
        <submitted date="2005-11-30-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-12-20-11:03">DRAFT</status_change>
        <status_change date="2006-01-04-08:04">INTERIM</status_change>
        <status_change date="2006-01-25-07:30">ACCEPTED</status_change>
      </dates>
      <description>Unknown vulnerability in remshd daemon in HP-UX B.11.00, B.11.11, and B.11.23 while running in "Trusted Mode" allows remote attackers to gain unauthorized system access via unknown attack vectors.</description>
      <reference source="CVE">CVE-2005-3565</reference>
      <status>ACCEPTED</status>
      <version>5</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-618" comment="700 Series or 800 Series OS Release 11.11" negate="false"/>
          <criterion test_ref="cmp-667" comment="InternetSrvcs.INETSVCS-RUN or InternetSrvcs.INET-ENG-A-MAN (B.11.11) is installed" negate="false"/>
          <criterion test_ref="hpt-13" comment="Patch PHNE_33791 or later is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1152" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2005-11-09-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-11-10-07:06">DRAFT</status_change>
        <status_change date="2005-12-01-06:00">INTERIM</status_change>
        <status_change date="2005-12-16-01:04">ACCEPTED</status_change>
      </dates>
      <description>The GetEnhMetaFilePaletteEntries API in GDI32.DLL in Windows 2000 allows remote attackers to cause a denial of service (application crash) via a crafted Enhanced Metafile (EMF) file that causes invalid (1) end, (2) emreof, or (3) palent offsets to be used, aka "Enhanced Metafile Vulnerability."</description>
      <reference source="CVE">CVE-2005-0803</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-2" comment="Windows XP is installed" negate="false"/>
          <criterion test_ref="wrt-4" comment="Win2K/XP/2003 service pack 1 is installed" negate="false"/>
          <criterion test_ref="wrt-70" comment="64-Bit version of Windows is installed" negate="true"/>
          <criterion test_ref="cmp-645" comment="version of Gdi32.dll is less than 5.1.2600.1755 OR the version of Mf3216.dll is less than 5.1.2600.1331" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1154" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>bzip2</product>
      </affected>
      <dates>
        <submitted date="2005-07-11-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2005-07-27-10:36">DRAFT</status_change>
        <status_change date="2005-08-18-07:37">INTERIM</status_change>
        <status_change date="2005-09-21-01:33">ACCEPTED</status_change>
      </dates>
      <description>Race condition in bzip2 1.0.2 and earlier allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by bzip2 after the decompression is complete.</description>
      <reference source="CVE">CVE-2005-0953</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="rvt-20" comment="bzip2 RPM earlier than 0:1.0.2-11.EL3.4" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="upt-55" comment="/usr/bin/bzip2 is executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1155" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Internet Explorer</product>
      </affected>
      <dates>
        <submitted date="2005-10-12-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-10-19-05:46">DRAFT</status_change>
        <status_change date="2005-11-16-08:02">INTERIM</status_change>
        <status_change date="2005-12-01-06:00">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not intended for use within Internet Explorer, as originally demonstrated using the (1) DDS Library Shape Control (Msdds.dll) COM object, and other objects including (2) Blnmgrps.dll, (3) Ciodm.dll, (4) Comsvcs.dll, (5) Danim.dll, (6) Htmlmarq.ocx, (7) Mdt2dd.dll (as demonstrated using a heap corruption attack with uninitialized memory), (8) Mdt2qd.dll, (9) Mpg4ds32.ax, (10) Msadds32.ax, (11) Msb1esen.dll, (12) Msb1fren.dll, (13) Msb1geen.dll, (14) Msdtctm.dll, (15) Mshtml.dll, (16) Msoeacct.dll, (17) Msosvfbr.dll, (18) Mswcrun.dll, (19) Netshell.dll, (20) Ole2disp.dll, (21) Outllib.dll, (22) Psisdecd.dll, (23) Qdvd.dll, (24) Repodbc.dll, (25) Shdocvw.dll, (26) Shell32.dll, (27) Soa.dll, (28) Srchui.dll, (29) Stobject.dll, (30) Vdt70.dll, (31) Vmhelper.dll, and (32) Wbemads.dll, aka a variant of the "COM Object Instantiation Memory Corruption vulnerability."</description>
      <reference source="CVE">CVE-2005-2127</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1112" comment="Windows XP 64-bit" negate="false"/>
          <criterion test_ref="wrt-4" comment="Win2K/XP/2003 service pack 1 is installed" negate="false"/>
          <criterion test_ref="wft-668" comment="mshtml.dll is less than 6.0.3790.2541" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1157" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Crystal Enterprise</product>
        <product>Crystal Reports</product>
      </affected>
      <dates>
        <submitted date="2004-06-09-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <modified date="2005-01-18-12:00" comment="modified wrt-400 - Changed datatype to int was incorrectly set to binary">
          <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
        </modified>
      </dates>
      <description>Directory traversal vulnerability in the web viewers for Business Objects Crystal Reports 9 and 10, and Crystal Enterprise 9 or 10, as used in Visual Studio .NET 2003 and Outlook 2003 with Business Contact Manager, Microsoft Business Solutions CRM 1.2, and other products, allows remote attackers to read and delete arbitrary files via ".." sequences in the dynamicimag argument to crystalimagehandler.aspx.</description>
      <reference source="CVE">CVE-2004-0204</reference>
      <status>DRAFT</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wft-341" comment="the version of CrystalDecisions.Web.dll is less than 9.1.9800.9" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-400" comment="the w3svc service is enabled" negate="false"/>
          <criterion test_ref="ukn-24" comment="a website linked to the Crystal Reports Viewer is active" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1158" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Office</product>
      </affected>
      <dates>
        <submitted date="2006-03-15-10:53">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-03-15-07:17">DRAFT</status_change>
        <status_change date="2006-04-06-06:30">INTERIM</status_change>
        <status_change date="2006-05-03-10:06">ACCEPTED</status_change>
      </dates>
      <description>Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-complicit attackers to execute arbitrary code via a BIFF parsing format file containing malformed BOOLERR records that lead to memory corruption, probably involving invalid pointers.</description>
      <reference source="CVE">CVE-2006-0028</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-137" comment="Excel 2000 is installed" negate="false"/>
          <criterion test_ref="wft-769" comment="the version of excel.exe is less than 9.0.0.8938" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1159" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>COM Internet Services</product>
      </affected>
      <dates>
        <submitted date="2005-02-15-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2005-02-18-12:00">DRAFT</status_change>
        <status_change date="2005-03-09-12:00">INTERIM</status_change>
        <status_change date="2005-03-29-12:00">ACCEPTED</status_change>
        <modified date="2005-06-17-12:00" comment="modified cmp-1106 - Replaced the test that checks for the service pack level, instead of checking for sp4 or ealier (did not check for GOLD edition) it is now negating the test that checks for sp5 for later.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <status_change date="2005-06-22-12:35">INTERIM</status_change>
        <status_change date="2005-07-27-10:37">ACCEPTED</status_change>
      </dates>
      <description>Windows 2000, XP, and Server 2003 does not properly "validate the use of memory regions" for COM structured storage files, which allows attackers to execute arbitrary code, aka the "COM Structured Storage Vulnerability."</description>
      <reference source="CVE">CVE-2005-0047</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1106" comment="Windows 2000 (sp4 or earlier) is installed" negate="false"/>
          <criterion test_ref="wft-386" comment="the version of ole32.dll is less than 5.0.2195.7021" negate="false"/>
          <criterion test_ref="wrt-91" comment="the patch KB873333 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1165" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Outlook</product>
      </affected>
      <dates>
        <submitted date="2006-01-11-12:56">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-01-12-09:25">DRAFT</status_change>
        <status_change date="2006-02-01-09:08">INTERIM</status_change>
        <status_change date="2006-02-22-08:27">ACCEPTED</status_change>
      </dates>
      <description>Unspecified vulnerability in Microsoft Outlook 2000 through 2003, Exchange 5.0 Server SP2 and 5.5 SP4, Exchange 2000 SP3, and Office allows remote attackers to execute arbitrary code via an e-mail message with a crafted Transport Neutral Encapsulation Format (TNEF) MIME attachment, related to message length validation.</description>
      <reference source="CVE">CVE-2006-0002</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-631" comment="Outlook 2002 is installed" negate="false"/>
          <criterion test_ref="wft-735" comment="the version of msmapi32.dll is less than 10.0.6772.0" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1168" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Word for Windows 6.0 Converter</product>
      </affected>
      <dates>
        <submitted date="2005-01-05-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2005-01-12-12:00">DRAFT</status_change>
        <status_change date="2005-02-02-12:00">INTERIM</status_change>
        <status_change date="2005-02-23-12:00">ACCEPTED</status_change>
        <modified date="2005-04-08-12:00" comment="modified wrt-35 - wrt-35 corrected literal string">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <status_change date="2005-04-11-08:48">INTERIM</status_change>
        <status_change date="2005-04-27-12:07">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Word for Windows 6.0 Converter does not properly validate certain data lengths, which allows remote attackers to execute arbitrary code via a .wri, .rtf, and .doc file sent by email or malicious web site, aka "Table Conversion Vulnerability," a different vulnerability than CVE-2004-0901.</description>
      <reference source="CVE">CVE-2004-0571</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-25" comment="the patch kb885836 is installed (Hotfix key)" negate="true"/>
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wft-281" comment="the version of mswrd632.wpc is less than 2004.10.25.0" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-35" comment="Word for Windows 6.0 Converter is enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1169" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>gzip</product>
      </affected>
      <dates>
        <submitted date="2005-06-20-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2005-06-22-12:38">DRAFT</status_change>
        <status_change date="2005-07-27-10:37">INTERIM</status_change>
        <status_change date="2005-08-18-07:37">ACCEPTED</status_change>
      </dates>
      <description>Race condition in gzip 1.2.4, 1.3.3, and earlier, when decompressing a gzipped file, allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by gzip after the decompression is complete.</description>
      <reference source="CVE">CVE-2005-0988</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="rvt-7" comment="gzip RPM earlier than 0:1.3.3-12rhel3" negate="false"/>
        </software>
        <configuration operation="OR">
          <criterion test_ref="upt-428" comment="/usr/bin/gunzip is executable" negate="false"/>
          <criterion test_ref="upt-529" comment="/usr/bin/gzip is executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1172" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>mozilla</product>
      </affected>
      <dates>
        <submitted date="2005-08-15-04:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2005-08-19-10:05">DRAFT</status_change>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Firefox before 1.0.5 allows remote attackers to steal information and possibly execute arbitrary code by using standalone applications such as Flash and QuickTime to open a javascript: URL, which is run in the context of the previous page, and may lead to code execution if the standalone application loads a privileged chrome: URL.</description>
      <reference source="CVE">CVE-2005-2267</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-216" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="rvt-32" comment="mozilla RPM is earlier than 37:1.7.10-1.4.1" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="upt-859" comment="/usr/bin/mozilla is executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1173" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>libxml2</product>
      </affected>
      <dates>
        <submitted date="2005-06-27-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2005-06-29-06:49">DRAFT</status_change>
        <status_change date="2005-07-27-10:37">INTERIM</status_change>
        <status_change date="2005-08-18-07:37">ACCEPTED</status_change>
      </dates>
      <description>Multiple buffer overflows in libXML 2.6.12 and 2.6.13 (libxml2), and possibly other versions, may allow remote attackers to execute arbitrary code via (1) a long FTP URL that is not properly handled by the xmlNanoFTPScanURL function, (2) a long proxy URL containing FTP data that is not properly handled by the xmlNanoFTPScanProxy function, and other overflows related to manipulation of DNS length values, including (3) xmlNanoFTPConnect, (4) xmlNanoHTTPConnectHost, and (5) xmlNanoHTTPConnectHost.</description>
      <reference source="CVE">CVE-2004-0989</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="cmp-261" comment="libxml or libxml-devel RPM is earlier than 1:1.8.17-9.2" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1175" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2005-11-09-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-11-10-07:06">DRAFT</status_change>
        <status_change date="2005-12-01-06:00">INTERIM</status_change>
        <status_change date="2005-12-16-01:04">ACCEPTED</status_change>
      </dates>
      <description>Multiple integer overflows in the Graphics Rendering Engine (GDI32.DLL) in Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allow remote attackers to execute arbitrary code via crafted Windows Metafile (WMF) and Enhanced Metafile (EMF) format images that lead to heap-based buffer overflows, as demonstrated using MRBP16::bCheckRecord.</description>
      <reference source="CVE">CVE-2005-2123</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-2" comment="Windows XP is installed" negate="false"/>
          <criterion test_ref="wrt-250" comment="Win2K/XP/2003 service pack 2 is installed" negate="false"/>
          <criterion test_ref="wft-701" comment="the version of Gdi32.dll is less than 5.1.2600.2770" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1178" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Internet Explorer</product>
      </affected>
      <dates>
        <submitted date="2006-04-12-12:55">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-04-12-05:16">DRAFT</status_change>
        <status_change date="2006-05-03-10:06">INTERIM</status_change>
      </dates>
      <description>Microsoft Internet Explorer 6 and 7 Beta 2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a certain createTextRange call on a checkbox object, which results in a dereference of an invalid table pointer.</description>
      <reference source="CVE">CVE-2006-1359</reference>
      <status>INTERIM</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wrt-10026" comment="Win2K/XP/2003 is patched" negate="true"/>
          <criterion test_ref="wft-778" comment="the version of mshtml.dll is less than 6.0.3790.507" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1180" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Windows Media Player 9</product>
      </affected>
      <dates>
        <submitted date="2005-02-15-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2005-02-18-10:39">DRAFT</status_change>
        <status_change date="2005-03-09-07:56">INTERIM</status_change>
        <status_change date="2005-03-29-07:59">ACCEPTED</status_change>
      </dates>
      <description>The OLE component in Windows 98, 2000, XP, and Server 2003, and Exchange Server 5.0 through 2003, does not properly validate the lengths of messages for certain OLE data, which allows remote attackers to execute arbitrary code, aka the "Input Validation Vulnerability."</description>
      <reference source="CVE">CVE-2005-0044</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-35" comment="Windows XP 32 bit Service Pack 2" negate="false"/>
          <criterion test_ref="wft-388" comment="the version of ole32.dll is less than 5.1.2600.2595" negate="false"/>
          <criterion test_ref="wrt-91" comment="the patch KB873333 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1182" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>TIP</product>
      </affected>
      <dates>
        <submitted date="2005-10-12-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-10-19-05:46">DRAFT</status_change>
        <status_change date="2005-11-16-08:02">INTERIM</status_change>
        <status_change date="2005-12-01-06:00">ACCEPTED</status_change>
      </dates>
      <description>Distributed Transaction Controller in Microsoft Windows allows remote servers to cause a denial of service (MSDTC service hang) via a crafted Transaction Internet Protocol (TIP) message that causes DTC to repeatedly connect to a target IP and port number after an error occurs, aka the "Distributed TIP Vulnerability."</description>
      <reference source="CVE">CVE-2005-1980</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1058" comment="Windows XP 32-bit edition is installed" negate="false"/>
          <criterion test_ref="cmp-35" comment="Windows XP 32 bit Service Pack 2" negate="false"/>
          <criterion test_ref="cmp-607" comment="Either ole32.dll or rpcss.dll has a version less than 5.1.2600.2726" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1185" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2006-01-11-12:56">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-01-12-09:18">DRAFT</status_change>
        <status_change date="2006-02-01-09:08">INTERIM</status_change>
        <status_change date="2006-02-22-08:27">ACCEPTED</status_change>
      </dates>
      <description>Heap-based buffer overflow in T2EMBED.DLL in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 up to SP1, Windows 98, and Windows ME allows remote attackers to execute arbitrary code via an e-mail message or web page with a crafted Embedded Open Type (EOT) web font that triggers the overflow during decompression.</description>
      <reference source="CVE">CVE-2006-0010</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wrt-4" comment="Win2K/XP/2003 service pack 1 is installed" negate="false"/>
          <criterion test_ref="cmp-710" comment="Fontsub.dll &lt; 5.2.3790.2549 or T2embed.dll &lt;5.2.3790.2549 (WinXP,64-bit and S03,SP1)" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1186" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>HTML Help Facility</product>
      </affected>
      <dates>
        <submitted date="2004-07-13-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <modified date="2004-07-14-12:00" comment="added the unregistered HTML Help criterion to the configuration section of the criteria">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <status_change date="2004-08-04-12:00">INTERIM</status_change>
        <status_change date="2004-08-25-12:00">ACCEPTED</status_change>
        <modified date="2004-09-13-11:36" comment="cmp-66 added">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2004-09-15-12:00">INTERIM</status_change>
        <status_change date="2004-09-29-12:00">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 5.x and 6.0 allows remote attackers to execute arbitrary programs via a modified directory traversal attack using a URL containing ".." (dot dot) sequences and a filename that ends in "::" which is treated as a .chm file even if it does not have a .chm extension.  NOTE: this bug may overlap CVE-2004-0475.</description>
      <reference source="CVE">CVE-2003-1041</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wft-444" comment="the version of itss.dll is less than 5.2.3790.185" negate="false"/>
          <criterion test_ref="wrt-482" comment="the patch kb840315 is installed" negate="true"/>
          <criterion test_ref="cmp-66" comment="Windows XP (sp1 or earlier) is installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-491" comment="HTML Help is registered" negate="true"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1190" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Microsoft Office XP SP3</product>
      </affected>
      <dates>
        <submitted date="2005-07-21-04:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2005-07-27-04:00">DRAFT</status_change>
        <status_change date="2005-08-18-04:00">INTERIM</status_change>
        <modified date="2005-09-19-04:00" comment="modified wft-368 - corrected registry component to point to the key that stores the location of WinWord.exe">
          <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
        </modified>
        <status_change date="2005-10-05-11:37">ACCEPTED</status_change>
        <modified date="2005-12-20-07:05" comment="Edited criteria to check for Word 2002 instead of MS Office SP3.">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </modified>
        <status_change date="2006-01-04-08:04">ACCEPTED</status_change>
      </dates>
      <description>Stack-based buffer overflow in Microsoft Word 2000 and Word 2002, and Microsoft Works Suites 2000 through 2004, might allow remote attackers to execute arbitrary code via a .doc file with long font information.</description>
      <reference source="CVE">CVE-2005-0564</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-133" comment="Word 2002 is installed" negate="false"/>
          <criterion test_ref="wft-368" comment="the version of winword.exe is less than 10.00.6764.0" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1191" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2006-04-12-12:55">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-04-12-05:16">DRAFT</status_change>
        <status_change date="2006-05-03-10:06">INTERIM</status_change>
      </dates>
      <description>Unspecified vulnerability in Windows Explorer in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote attackers to execute arbitrary code via attack vectors involving COM objects and "crafted files and directories," aka the "Windows Shell Vulnerability."</description>
      <reference source="CVE">CVE-2006-0012</reference>
      <status>INTERIM</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-212" comment="Windows 2000 Service Pack 4 (or later) is installed" negate="false"/>
          <criterion test_ref="wft-788" comment="the version of shell32.dll is less than 5.0.3900.7078" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1192" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2005-10-12-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-10-19-05:46">DRAFT</status_change>
        <status_change date="2005-11-16-08:02">INTERIM</status_change>
        <status_change date="2005-12-01-06:00">ACCEPTED</status_change>
      </dates>
      <description>Windows Shell for Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 allows remote user-complicit attackers to execute arbitrary commands via a crafted shortcut (.lnk) file with long font properties that lead to a buffer overflow when the user views the file's properties using Windows Explorer, a different vulnerability than CVE-2005-2122.</description>
      <reference source="CVE">CVE-2005-2118</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
          <criterion test_ref="wrt-432" comment="Win2K/XP/2003 service pack 4 is installed" negate="false"/>
          <criterion test_ref="wft-683" comment="shell32.dll is less than 5.0.3900.7071" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1194" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Microsoft Agent</product>
      </affected>
      <dates>
        <submitted date="2005-06-22-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2005-06-22-03:21">DRAFT</status_change>
        <modified date="2005-06-24-12:00" comment="added description">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </modified>
        <status_change date="2005-07-27-10:37">INTERIM</status_change>
        <status_change date="2005-08-18-07:37">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Agent allows remote attackers to spoof trusted Internet content and execute arbitrary code by disguising security prompts on a malicious Web page.</description>
      <reference source="CVE">CVE-2005-1214</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-2" comment="Windows XP is installed" negate="false"/>
          <criterion test_ref="cmp-225" comment=" a vulnerable version of agentdpv exists" negate="false"/>
          <criterion test_ref="wrt-64" comment="the patch kb890046 is installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1195" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>libgd</product>
      </affected>
      <dates>
        <submitted date="2005-06-27-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2005-06-29-06:49">DRAFT</status_change>
        <status_change date="2005-07-27-10:37">INTERIM</status_change>
        <status_change date="2005-08-18-07:37">ACCEPTED</status_change>
      </dates>
      <description>Multiple buffer overflows in the gd graphics library (libgd) 2.0.21 and earlier may allow remote attackers to execute arbitrary code via malformed image files that trigger the overflows due to improper calls to the gdMalloc function, a different set of vulnerabilities than CVE-2004-0990.</description>
      <reference source="CVE">CVE-2004-0941</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="cmp-260" comment="libgd or libgd-devel RPM is earlier than 0:1.8.4-12.3.1" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1196" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Internet Explorer 5.01 Service Pack 3</product>
      </affected>
      <dates>
        <submitted date="2005-05-10-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2005-05-11-05:38">DRAFT</status_change>
        <status_change date="2005-06-01-03:30">INTERIM</status_change>
        <status_change date="2005-06-22-12:38">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the URL processor of Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a URL with a long hostname, aka "URL Parsing Memory Corruption Vulnerability."</description>
      <reference source="CVE">CVE-2005-0554</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-55" comment="Internet Explorer 5.01 Service Pack 3 is installed" negate="false"/>
          <criterion test_ref="wft-598" comment="the version of mshtml.dll is less than 5.0.3539.2400" negate="false"/>
          <criterion test_ref="wrt-441" comment="the patch kb890923  is installed (Win2K SP3  Hotfix key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1197" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>mozilla</product>
      </affected>
      <dates>
        <submitted date="2005-11-11-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-12-12-10:00">DRAFT</status_change>
        <status_change date="2005-12-28-04:28">INTERIM</status_change>
        <status_change date="2006-01-12-08:59">ACCEPTED</status_change>
      </dates>
      <description>Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to spawn windows without user interface components such as the address and status bar, which could be used to conduct spoofing or phishing attacks.</description>
      <reference source="CVE">CVE-2005-2707</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-621" comment="Mozilla Suite version 1.7.10 or earlier is installed" negate="false"/>
          <criterion test_ref="cmp-631" comment="Mozilla Firefox version 1.0.6 or earlier is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1201" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2005-10-12-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-10-19-05:46">DRAFT</status_change>
        <status_change date="2005-11-16-08:02">INTERIM</status_change>
        <status_change date="2005-12-01-06:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in Collaboration Data Objects (CDO), as used in Microsoft Windows and Microsoft Exchange Server, allows remote attackers to execute arbitrary code when CDOSYS or CDOEX processes an e-mail message with a large header name, as demonstrated using the "Content-Type" string.</description>
      <reference source="CVE">CVE-2005-1987</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-457" comment="Microsoft Exchange 2000 Installed" negate="false"/>
          <criterion test_ref="wft-682" comment="cdoex.dll is less than 6.0.6617.86" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1202" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Distributed Component Object Model (DCOM) interface</product>
      </affected>
      <dates>
        <submitted date="2005-01-18-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2005-01-20-02:31">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Heap-based buffer overflow in the Distributed Component Object Model (DCOM) interface in the RPCSS Service allows remote attackers to execute arbitrary code via a malformed DCERPC DCOM object activation request packet with modified length fields, a different vulnerability than CVE-2003-0352 (Blaster/Nachi) and CVE-2003-0528.</description>
      <reference source="CVE">CVE-2003-0715</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-38" comment="Windows Server 2003 or Windows XP 64-Bit Edition Version 2003" negate="false"/>
          <criterion test_ref="wft-358" comment="the version of rpcrt4.dll is less than 5.2.3790.76" negate="false"/>
          <criterion test_ref="wrt-281" comment="the patch kb824146 is installed (Hotfix key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-283" comment="DCOM is enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1203" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>TIP</product>
      </affected>
      <dates>
        <submitted date="2005-10-12-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-10-19-05:46">DRAFT</status_change>
        <status_change date="2005-11-16-08:02">INTERIM</status_change>
        <status_change date="2005-12-01-06:00">ACCEPTED</status_change>
      </dates>
      <description>Distributed Transaction Controller in Microsoft Windows allows remote servers to cause a denial of service (MSDTC service hang) via a crafted Transaction Internet Protocol (TIP) message that causes DTC to repeatedly connect to a target IP and port number after an error occurs, aka the "Distributed TIP Vulnerability."</description>
      <reference source="CVE">CVE-2005-1980</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1058" comment="Windows XP 32-bit edition is installed" negate="false"/>
          <criterion test_ref="wrt-4" comment="Win2K/XP/2003 service pack 1 is installed" negate="false"/>
          <criterion test_ref="cmp-606" comment="Either ole32.dll or rpcss.dll has a version less than 5.1.2600.1720" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1204" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>MDAC</product>
      </affected>
      <dates>
        <submitted date="2006-04-12-12:55">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-04-12-05:16">DRAFT</status_change>
        <status_change date="2006-05-03-10:06">INTERIM</status_change>
      </dates>
      <description>Unspecified vulnerability in the RDS.Dataspace ActiveX control, which is contained in ActiveX Data Objects (ADO) and distributed in Microsoft Data Access Components (MDAC) 2.7 and 2.8, allows remote attackers to execute arbitrary code via unknown attack vectors.</description>
      <reference source="CVE">CVE-2006-0003</reference>
      <status>INTERIM</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-2" comment="Windows XP is installed" negate="false"/>
          <criterion test_ref="wrt-250" comment="Win2K/XP/2003 service pack 2 is installed" negate="false"/>
          <criterion test_ref="wft-785" comment="the version of msadco.dll is less than 2.81.1124.0" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1207" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Microsoft Internet Explorer 6 Service Pack 1</product>
      </affected>
      <dates>
        <submitted date="2005-06-22-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2005-06-22-12:38">DRAFT</status_change>
        <status_change date="2005-07-27-10:37">INTERIM</status_change>
        <status_change date="2005-08-18-07:37">ACCEPTED</status_change>
      </dates>
      <description>The legacy &lt;script> data-island capability for XML in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to read arbitrary XML files, and portions of other files, via a URL whose "src" attribute redirects to a local file.</description>
      <reference source="CVE">CVE-2002-0648</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-50" comment="Internet Explorer 6 Service Pack 1 is installed" negate="false"/>
          <criterion test_ref="cmp-158" comment="the version of mshtml.dll is less than 6.0.2800.1505 or 6.0.2800.1506" negate="false"/>
          <criterion test_ref="wrt-62" comment="the patch kb883939 is installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1209" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Internet Explorer</product>
      </affected>
      <dates>
        <submitted date="2005-12-13-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-12-16-01:03">DRAFT</status_change>
        <status_change date="2006-01-04-08:04">INTERIM</status_change>
        <status_change date="2006-01-25-07:30">ACCEPTED</status_change>
      </dates>
      <description>Multiple design errors in Microsoft Internet Explorer 5.01, 5.5, and 6 allow user-complicit attackers to execute arbitrary code by (1) overlaying a malicious new window above a file download box, then (2) using a keyboard shortcut and delaying the display of the file download box until the user hits a shortcut that activates the "Run" button, aka "File Download Dialog Box Manipulation Vulnerability."</description>
      <reference source="CVE">CVE-2005-2829</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wrt-10027" comment="Internet Explorer 6 is installed" negate="false"/>
          <criterion test_ref="wft-707" comment="the version of mshtml.dll is less than 6.0.3790.2577" negate="false"/>
          <criterion test_ref="wrt-4" comment="Win2K/XP/2003 service pack 1 is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1210" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>NetWare</product>
      </affected>
      <dates>
        <submitted date="2005-10-12-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-10-19-05:46">DRAFT</status_change>
        <status_change date="2005-11-16-08:02">INTERIM</status_change>
        <status_change date="2005-12-01-06:00">ACCEPTED</status_change>
      </dates>
      <description>The Client Service for NetWare (CSNW) on Microsoft Windows 2000 SP4, XP SP1 and Sp2, and Server 2003 SP1 and earlier, allows remote attackers to execute arbitrary code due to an "unchecked buffer" when processing certain crafted network messages.</description>
      <reference source="CVE">CVE-2005-1985</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-2" comment="Windows XP is installed" negate="false"/>
          <criterion test_ref="wrt-250" comment="Win2K/XP/2003 service pack 2 is installed" negate="false"/>
          <criterion test_ref="wft-671" comment="nwwks.dll is less than 5.1.2600.2736" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1212" class="vulnerability">
      <affected family="hp-ux">
        <hpux:platform>HP-UX 11</hpux:platform>
        <product>ftpd</product>
      </affected>
      <dates>
        <submitted date="2005-11-30-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-12-20-11:03">DRAFT</status_change>
        <status_change date="2006-01-04-08:04">INTERIM</status_change>
        <status_change date="2006-01-25-07:30">ACCEPTED</status_change>
      </dates>
      <description>The FTP server in HP-UX 10.20, B.11.00, and B.11.11, allows remote attackers to list arbitrary directories as root by running the LIST command before logging in.</description>
      <reference source="CVE">CVE-2005-3296</reference>
      <status>ACCEPTED</status>
      <version>5</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-677" comment="700 Series or 800 Series OS Release 10.24" negate="false"/>
          <criterion test_ref="hpt-9" comment="Patch PHNE_24394 or later is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1213" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Telephony Service</product>
      </affected>
      <dates>
        <submitted date="2005-08-11-04:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <status_change date="2005-08-19-10:05">DRAFT</status_change>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the Telephony Application Programming Interface (TAPI) for Microsoft Windows 98, Windows 98 SE, Windows ME, Windows 2000, Windows XP, and Windows Server 2003 allows attackers elevate privileges or execute arbitrary code via a crafted message.</description>
      <reference source="CVE">CVE-2005-0058</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1106" comment="Windows 2000 (sp4 or earlier) is installed" negate="false"/>
          <criterion test_ref="wft-614" comment="the version of tapisrv.dll is less than 5.0.2195.7057" negate="false"/>
          <criterion test_ref="wrt-139" comment="the patch kb893756 is installed (Hotfix key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-201" comment="the Telephony service is enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1215" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2005-11-09-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-11-10-07:06">DRAFT</status_change>
        <status_change date="2005-12-01-06:00">INTERIM</status_change>
        <status_change date="2005-12-16-01:04">ACCEPTED</status_change>
      </dates>
      <description>The GetEnhMetaFilePaletteEntries API in GDI32.DLL in Windows 2000 allows remote attackers to cause a denial of service (application crash) via a crafted Enhanced Metafile (EMF) file that causes invalid (1) end, (2) emreof, or (3) palent offsets to be used, aka "Enhanced Metafile Vulnerability."</description>
      <reference source="CVE">CVE-2005-0803</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-647" comment="64-bit XP or Server 2003 is installed" negate="false"/>
          <criterion test_ref="wrt-4" comment="Win2K/XP/2003 service pack 1 is installed" negate="false"/>
          <criterion test_ref="wft-703" comment="the version of Gdi32.dll is less than 5.2.3790.2542" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1216" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Internet Explorer 6.0 for Windows Server 2003</product>
      </affected>
      <dates>
        <submitted date="2005-08-23-04:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2005-08-25-10:05">DRAFT</status_change>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
        <modified date="2005-12-26-09:40" comment="Removed reference to patch kb896727 from criteria.">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </modified>
        <status_change date="2006-01-12-08:59">ACCEPTED</status_change>
      </dates>
      <description>Unknown vulnerability in Internet Explorer 5.0, 5.5, and 6.0 allows remote attackers to execute arbitrary code via a web site or an HTML e-mail containing a crafted JPEG image that causes memory corruption, aka "JPEG Image Rendering Memory Corruption Vulnerability".</description>
      <reference source="CVE">CVE-2005-1988</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-51" comment="Internet Explorer 6  for Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="cmp-315" comment="a vulnerable version of mshtml.dll exisits" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1220" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2006-02-17-07:36">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-02-22-08:27">DRAFT</status_change>
        <status_change date="2006-03-09-12:19">INTERIM</status_change>
        <status_change date="2006-04-06-06:30">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the Web Client service (WebClnt.dll) for Microsoft Windows XP SP1 and SP2, and Server 2003 up to SP1, allows remote authenticated users or Guests to execute arbitrary code via crafted RPC requests, a different vulnerability than CVE-2005-1207.</description>
      <reference source="CVE">CVE-2006-0013</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wrt-4" comment="Win2K/XP/2003 service pack 1 is installed" negate="false"/>
          <criterion test_ref="wft-762" comment="the version of webclnt.dll is less than 5.2.3790.2591 (64-bit,SP1)" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1221" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Internet Explorer 6.0 for Windows Server 2003</product>
      </affected>
      <dates>
        <submitted date="2005-08-23-04:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2005-08-25-10:05">DRAFT</status_change>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
        <modified date="2005-12-26-09:40" comment="Removed reference to patch kb896727 from criteria.">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </modified>
        <status_change date="2006-01-12-08:59">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 5.0, 5.5, and 6.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not ActiveX controls, including (1) devenum.dll, (2) diactfrm.dll, (3) wmm2filt.dll, (4) fsusd.dll, (5) dmdskmgr.dll, (6) browsewm.dll, (7) browseui.dll, (8) shell32.dll, (9) mshtml.dll, (10) inetcfg.dll, (11) infosoft.dll, (12) query.dll, (13) syncui.dll, (14) clbcatex.dll, (15) clbcatq.dll, (16) comsvcs.dll, and (17) msconf.dll, which causes memory corruption, aka "COM Object Instantiation Memory Corruption Vulnerability," a different vulnerability than CVE-2005-2087.</description>
      <reference source="CVE">CVE-2005-1990</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-51" comment="Internet Explorer 6  for Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="cmp-315" comment="a vulnerable version of mshtml.dll exisits" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1224" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 98</windows:platform>
        <windows:platform>Microsoft Windows ME</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Interactive Training</product>
      </affected>
      <dates>
        <submitted date="2005-08-08-12:00">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </submitted>
        <status_change date="2005-08-09-07:56">DRAFT</status_change>
        <status_change date="2005-08-24-09:56">INTERIM</status_change>
        <status_change date="2005-09-21-01:33">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in Microsoft Step-by-Step Interactive Training (orun32.exe) allows remote attackers to execute arbitrary code via a bookmark link file (.cbo, cbl, or .cbm extension) with a long User field.</description>
      <reference source="CVE">CVE-2005-1212</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-75" comment="Microsoft Interactive Training is installed" negate="false"/>
          <criterion test_ref="wft-155" comment="the version of Orun32.exe is less than 3.5.0.117" negate="false"/>
          <criterion test_ref="wrt-76" comment="the patch kb898458  is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1225" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>Linux kernel</product>
      </affected>
      <dates>
        <submitted date="2005-06-29-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2005-06-29-06:49">DRAFT</status_change>
        <status_change date="2005-07-27-10:37">INTERIM</status_change>
        <status_change date="2005-08-18-07:37">ACCEPTED</status_change>
      </dates>
      <description>The shmctl function in Linux 2.6.9 and earlier allows local users to unlock the memory of other processes, which could cause sensitive memory to be swapped to disk, which could allow it to be read by other users once it has been released.</description>
      <reference source="CVE">CVE-2005-0176</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="cmp-268" comment="kernel, kernel-smp or kernel-hugemem RPM earlier than 0:2.4.21-32.0.1.EL" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1226" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 4</redhat:platform>
        <product>mozilla</product>
      </affected>
      <dates>
        <submitted date="2005-08-15-04:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2005-08-19-10:05">DRAFT</status_change>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>The browser user interface in Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 and 7.2 does not properly distinguish between user-generated events and untrusted synthetic events, which makes it easier for remote attackers to perform dangerous actions that normally could only be performed manually by the user.</description>
      <reference source="CVE">CVE-2005-2260</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-1" comment="Red Hat Enterprise 4 is installed" negate="false"/>
          <criterion test_ref="rvt-32" comment="mozilla RPM is earlier than 37:1.7.10-1.4.1" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="upt-859" comment="/usr/bin/mozilla is executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1227" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>mozilla</product>
      </affected>
      <dates>
        <submitted date="2005-01-19-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-24-03:40">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Mozilla allows remote attackers to cause Mozilla to open a URI as a different MIME type than expected via a null character (%00) in an FTP URI.</description>
      <reference source="CVE">CVE-2004-0760</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" negate="false"/>
          <criterion test_ref="cmp-72" comment="Mozilla components (any SUNWmoznav/SUNWmozmail) installed" negate="false"/>
          <criterion test_ref="spt-46" comment="Patch 117765-02 or later installed" negate="true"/>
          <criterion test_ref="spt-47" comment="Patch 117767-02 or later installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1231" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>DirectX</product>
      </affected>
      <dates>
        <submitted date="2005-10-12-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-10-19-05:46">DRAFT</status_change>
        <status_change date="2005-11-16-08:02">INTERIM</status_change>
        <status_change date="2005-12-01-06:00">ACCEPTED</status_change>
      </dates>
      <description>QUARTZ.DLL in Microsoft Windows Media Player 9 allows remote attackers to write a null byte to arbitrary memory via an AVI file with a crafted strn element with a modified length value.</description>
      <reference source="CVE">CVE-2005-2128</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-602" comment="DirectX packaged with Windows XP,SP2 has DirectShow Vulnerability" negate="false"/>
          <criterion test_ref="cmp-598" comment="Standalone DirectX 8 has DirectShow Vulnerability" negate="false"/>
          <criterion test_ref="cmp-599" comment="Standalone DirectX 9 has DirectShow Vulnerability" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1235" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Microsoft Internet Explorer 6 Service Pack 1 for Windows Server 2003</product>
      </affected>
      <dates>
        <submitted date="2005-08-23-04:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2005-08-25-10:05">DRAFT</status_change>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 5.0, 5.5, and 6.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not ActiveX controls, including (1) devenum.dll, (2) diactfrm.dll, (3) wmm2filt.dll, (4) fsusd.dll, (5) dmdskmgr.dll, (6) browsewm.dll, (7) browseui.dll, (8) shell32.dll, (9) mshtml.dll, (10) inetcfg.dll, (11) infosoft.dll, (12) query.dll, (13) syncui.dll, (14) clbcatex.dll, (15) clbcatq.dll, (16) comsvcs.dll, and (17) msconf.dll, which causes memory corruption, aka "COM Object Instantiation Memory Corruption Vulnerability," a different vulnerability than CVE-2005-2087.</description>
      <reference source="CVE">CVE-2005-1990</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-50" comment="Internet Explorer 6 Service Pack 1 is installed" negate="false"/>
          <criterion test_ref="cmp-317" comment="the version of mshtml.dll is less than 6.0.2800.1515 or 6.0.2800.1516 " negate="false"/>
          <criterion test_ref="wrt-346" comment="the patch kb896727 is installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1236" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 95</windows:platform>
        <windows:platform>Microsoft Windows 98</windows:platform>
        <windows:platform>Microsoft Windows ME</windows:platform>
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Word 2003</product>
      </affected>
      <dates>
        <submitted date="2005-09-15-04:00">
          <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
        </submitted>
        <status_change date="2005-09-21-01:33">DRAFT</status_change>
        <status_change date="2005-10-12-05:49">INTERIM</status_change>
        <status_change date="2005-11-16-08:02">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in Microsoft Word 2000, Word 2002, and Word 2003 allows remote attackers to execute arbitrary code via a crafted document.</description>
      <reference source="CVE">CVE-2005-0558</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-607" comment="Word 2003 is installed" negate="false"/>
          <criterion test_ref="wft-639" comment="the version of wordview.exe is less than 11.0.6506.0" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1237" class="vulnerability">
      <affected family="hp-ux">
        <hpux:platform>HP-UX 11</hpux:platform>
        <product>Apache</product>
      </affected>
      <dates>
        <submitted date="2006-03-18-07:24">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-03-22-11:10">DRAFT</status_change>
        <status_change date="2006-04-06-06:31">INTERIM</status_change>
        <status_change date="2006-05-03-10:06">ACCEPTED</status_change>
      </dates>
      <description>'An undisclosed vulnerability has been identified in Apache HTTP server versions prior to Apache 1.3.34 that may allow HTTP Request Splitting/Spoofing attacks, resulting in remote unauthorized access.'</description>
      <reference source="MISC">http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00612828</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-783" comment="VirtualvaultTS A.04.70 is installed without patch PHSS_34169 or later" negate="false"/>
          <criterion test_ref="cmp-784" comment="VirtualvaultWS A.04.70 is installed without patch PHSS_34121 or later" negate="false"/>
          <criterion test_ref="cmp-785" comment="VirtualvaultTS A.04.60 is installed without patch PHSS_34170 or later" negate="false"/>
          <criterion test_ref="cmp-786" comment="VirtualvaultWS A.04.60 is installed without patch PHSS_34120 or later" negate="false"/>
          <criterion test_ref="cmp-787" comment="VirtualvaultTS A.04.50 is installed without patch PHSS_34171 or later" negate="false"/>
          <criterion test_ref="cmp-788" comment="VirtualvaultWS A.04.50 is installed without patch PHSS_34119 or later" negate="false"/>
          <criterion test_ref="cmp-789" comment="HP_Webproxy.HPWEB-PX-CORE A.02.10 is installed without patch PHSS_34203 or later" negate="false"/>
          <criterion test_ref="cmp-790" comment="HP_Webproxy.HPWEB-PX-CORE A.02.00 is installed without patch PHSS_34204 or later" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1239" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Internet Explorer 5.01 Service Pack 4</product>
      </affected>
      <dates>
        <submitted date="2005-06-22-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2005-06-22-12:38">DRAFT</status_change>
        <status_change date="2005-07-27-10:37">INTERIM</status_change>
        <status_change date="2005-08-18-07:37">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the PNG image rendering component of Microsoft Internet Explorer allows remote attackers to execute arbitrary code via a crafted PNG file.</description>
      <reference source="CVE">CVE-2005-1211</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-54" comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false"/>
          <criterion test_ref="wft-116" comment="the version of mshtml.dll is less than 5.0.3828.2700" negate="false"/>
          <criterion test_ref="wrt-62" comment="the patch kb883939 is installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-59" comment="PNG image rendering enabled in Internet Explorer" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1240" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2005-11-09-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-11-10-07:06">DRAFT</status_change>
        <status_change date="2005-12-01-06:00">INTERIM</status_change>
        <status_change date="2005-12-16-01:04">ACCEPTED</status_change>
      </dates>
      <description>The GetEnhMetaFilePaletteEntries API in GDI32.DLL in Windows 2000 allows remote attackers to cause a denial of service (application crash) via a crafted Enhanced Metafile (EMF) file that causes invalid (1) end, (2) emreof, or (3) palent offsets to be used, aka "Enhanced Metafile Vulnerability."</description>
      <reference source="CVE">CVE-2005-0803</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-212" comment="Windows 2000 Service Pack 4 (or later) is installed" negate="false"/>
          <criterion test_ref="cmp-644" comment="version of Gdi32.dll is less than 5.0.2195.7069 OR the version of Mf3216.dll is less than 5.0.2195.6898" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1241" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Word for Windows 6.0 Converter</product>
      </affected>
      <dates>
        <submitted date="2005-01-05-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2005-01-06-12:00">DRAFT</status_change>
        <status_change date="2005-02-02-12:00">INTERIM</status_change>
        <status_change date="2005-02-23-12:00">ACCEPTED</status_change>
        <modified date="2005-06-17-12:00" comment="modified cmp-1106 - Replaced the test that checks for the service pack level, instead of checking for sp4 or ealier (did not check for GOLD edition) it is now negating the test that checks for sp5 for later.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <status_change date="2005-06-22-12:35">INTERIM</status_change>
        <status_change date="2005-07-27-10:37">ACCEPTED</status_change>
        <modified date="2005-12-20-07:05" comment="Replaced all criteria. 1) Included all Win2k versions, 2) dropped explicit check for Hotfix kb885836, 3) check version of wordpad.exe rather than mswrd wpc files.">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </modified>
        <status_change date="2006-01-04-08:04">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Word for Windows 6.0 Converter (MSWRD632.WPC), as used in WordPad, does not properly validate certain data lengths, which allows remote attackers to execute arbitrary code via a .wri, .rtf, and .doc file sent by email or malicious web site, aka "Font Conversion Vulnerability," a different vulnerability than CVE-2004-0571.</description>
      <reference source="CVE">CVE-2004-0901</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
          <criterion test_ref="wft-712" comment="the version of wordpad.exe is less than 5.0.2195.6991" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1242" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>sudo</product>
      </affected>
      <dates>
        <submitted date="2005-07-18-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2005-07-27-10:36">DRAFT</status_change>
        <status_change date="2005-08-18-07:37">INTERIM</status_change>
        <status_change date="2005-09-21-01:33">ACCEPTED</status_change>
      </dates>
      <description>Race condition in sudo 1.3.1 up to 1.6.8p8, when the ALL pseudo-command is used after a user entry in the sudoers file, allows local users to gain privileges via a symlink attack.</description>
      <reference source="CVE">CVE-2005-1993</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <notes>
        <note>It appears that we can't parse the vulnerable configuration condition (an ALL in the second field of a line after a line that has no ALL in the second field) with our existing regexp.</note>
      </notes>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="rvt-26" comment="sudo RPM earlier than 0:1.6.7p5-1.1" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uft-3" comment="/etc/sudoers exists" negate="false"/>
          <criterion test_ref="upt-60" comment="/usr/bin/sudo is executable by everyone" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1244" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2005-10-12-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-10-19-05:46">DRAFT</status_change>
        <status_change date="2005-11-16-08:02">INTERIM</status_change>
        <status_change date="2005-12-01-06:00">ACCEPTED</status_change>
      </dates>
      <description>Stack-based buffer overflow in the Plug and Play (PnP) service (UMPNPMGR.DLL) in Microsoft Windows 2000 SP4, and XP SP1 and SP2, allows remote or local authenticated attackers to execute arbitrary code via a large number of "\" (backslash) characters in a registry key name, which triggers the overflow in a wsprintfW function call.</description>
      <reference source="CVE">CVE-2005-2120</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
          <criterion test_ref="wrt-432" comment="Win2K/XP/2003 service pack 4 is installed" negate="false"/>
          <criterion test_ref="wft-674" comment="umpnpmgr.dll is less than 5.0.2195.7069" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1245" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>gedit</product>
      </affected>
      <dates>
        <submitted date="2005-07-11-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2005-07-27-10:36">DRAFT</status_change>
        <status_change date="2005-08-18-07:37">INTERIM</status_change>
        <status_change date="2005-09-21-01:33">ACCEPTED</status_change>
      </dates>
      <description>Format string vulnerability in gedit 2.10.2 may allow attackers to cause a denial of service (application crash) via a bin file with format string specifiers in the filename.  NOTE: while this issue is triggered on the command line by the gedit user, it has been reported that web browsers and email clients could be configured to provide a file name as an argument to gedit, so there is a valid attack that crosses security boundaries.</description>
      <reference source="CVE">CVE-2005-1686</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="rvt-25" comment="gedit RPM earlier than 1:2.2.2-4rhel3" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="upt-59" comment="/usr/bin/gedit is executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1246" class="vulnerability">
      <affected family="hp-ux">
        <hpux:platform>HP-UX 11</hpux:platform>
        <product>Apache</product>
      </affected>
      <dates>
        <submitted date="2006-03-18-07:24">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-03-22-11:10">DRAFT</status_change>
        <status_change date="2006-04-06-06:31">INTERIM</status_change>
        <status_change date="2006-05-03-10:06">ACCEPTED</status_change>
      </dates>
      <description>The byte-range filter in Apache 2.0 before 2.0.54 allows remote attackers to cause a denial of service (memory consumption) via an HTTP header with a large Range field.</description>
      <reference source="CVE">CVE-2005-2728</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-672" comment="700 Series OS Release 11.04" negate="false"/>
          <criterion test_ref="hst-69" comment="VirusVault is installed" negate="false"/>
          <criterion test_ref="hpt-39" comment="Patch PHSS_34123 or later is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1250" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2005-10-12-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-10-19-05:46">DRAFT</status_change>
        <status_change date="2005-11-16-08:02">INTERIM</status_change>
        <status_change date="2005-12-01-06:00">ACCEPTED</status_change>
      </dates>
      <description>netman.dll in Microsoft Windows Connections Manager Library allows local users to cause a denial of service (Network Connections Service crash) via a large integer argument to a particular function.</description>
      <reference source="CVE">CVE-2005-2307</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wrt-10026" comment="Win2K/XP/2003 is patched" negate="true"/>
          <criterion test_ref="wft-695" comment="netman.dll is less than 5.2.3790.396" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1251" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Internet Explorer</product>
      </affected>
      <dates>
        <submitted date="2006-04-12-12:55">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-04-12-05:16">DRAFT</status_change>
        <status_change date="2006-05-03-10:06">INTERIM</status_change>
      </dates>
      <description>Microsoft Internet Explorer 5.01 through 6 does not always correctly identify the domain that is associated with a browser window, which allows remote attackers to obtain sensitive cross-domain information and spoof sites by running script after the user has navigated to another site.</description>
      <reference source="CVE">CVE-2006-1191</reference>
      <status>INTERIM</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-692" comment="Windows XP (64-bit,SP1 or 32-bit,SP2) is installed" negate="false"/>
          <criterion test_ref="wft-777" comment="the version of mshtml.dll is less than 6.0.2900.2873" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1253" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>TIP</product>
      </affected>
      <dates>
        <submitted date="2005-10-12-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-10-19-05:46">DRAFT</status_change>
        <status_change date="2005-11-16-08:02">INTERIM</status_change>
        <status_change date="2005-12-01-06:00">ACCEPTED</status_change>
      </dates>
      <description>Distributed Transaction Controller in Microsoft Windows allows remote servers to cause a denial of service (MSDTC service hang) via a crafted Transaction Internet Protocol (TIP) message that causes DTC to repeatedly connect to a target IP and port number after an error occurs, aka the "Distributed TIP Vulnerability."</description>
      <reference source="CVE">CVE-2005-1980</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
          <criterion test_ref="wrt-432" comment="Win2K/XP/2003 service pack 4 is installed" negate="false"/>
          <criterion test_ref="cmp-605" comment="Either ole32.dll or rpcss.dll has a version less than 5.0.2195.7059" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1254" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2005-10-12-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-10-19-05:46">DRAFT</status_change>
        <status_change date="2005-11-16-08:02">INTERIM</status_change>
        <status_change date="2005-12-01-06:00">ACCEPTED</status_change>
      </dates>
      <description>netman.dll in Microsoft Windows Connections Manager Library allows local users to cause a denial of service (Network Connections Service crash) via a large integer argument to a particular function.</description>
      <reference source="CVE">CVE-2005-2307</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-2" comment="Windows XP is installed" negate="false"/>
          <criterion test_ref="wrt-4" comment="Win2K/XP/2003 service pack 1 is installed" negate="false"/>
          <criterion test_ref="wft-693" comment="netman.dll is less than 5.1.2600.1733" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1255" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Web Client Service</product>
      </affected>
      <dates>
        <submitted date="2005-07-15-12:00">
          <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
        </submitted>
        <status_change date="2005-07-27-10:36">DRAFT</status_change>
        <status_change date="2005-08-18-07:37">INTERIM</status_change>
        <status_change date="2005-09-21-01:33">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the Web Client service in Microsoft Windows XP and Windows Server 2003 allows remote authenticated users to execute arbitrary code via a crafted WebDAV request containing special parameters.</description>
      <reference source="CVE">CVE-2005-1207</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-2" comment="Windows XP is installed" negate="false"/>
          <criterion test_ref="cmp-23" comment="32-bit version of Windows or 64-bit (itanium architecture) version of Windows is installed" negate="false"/>
          <criterion test_ref="wrt-29" comment="Win2K/XP/2003 service pack 2 (or later) is installed" negate="true"/>
          <criterion test_ref="wft-167" comment="the version of webclnt.dll is less than 5.2.3790.1673" negate="false"/>
          <criterion test_ref="wrt-124" comment="the patch kb896426 is installed (Hotfix key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1256" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Windows Media Player</product>
      </affected>
      <dates>
        <submitted date="2006-02-17-07:36">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-02-22-08:27">DRAFT</status_change>
        <status_change date="2006-03-09-12:19">INTERIM</status_change>
        <status_change date="2006-04-06-06:30">ACCEPTED</status_change>
      </dates>
      <description>Heap-based buffer overflow in the bitmap processing routine in Microsoft Windows Media Player 7.1 on Windows 2000 SP4, Media Player 9 on Windows 200 SP4 and XP SP1, and Media Player 10 on XP SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted bitmap (.BMP) file that specifies a size of 0 but contains additional data.</description>
      <reference source="CVE">CVE-2006-0006</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-645" comment="Windows Media Player 8 is installed" negate="false"/>
          <criterion test_ref="wft-744" comment="the version of Wmpui.dll is less than 8.0.0.4495" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1258" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>mozilla</product>
      </affected>
      <dates>
        <submitted date="2005-08-15-04:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2005-08-19-10:05">DRAFT</status_change>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 does not properly verify the associated types of DOM node names within the context of their namespaces, which allows remote attackers to modify certain tag properties, possibly leading to execution of arbitrary script or code, as demonstrated using an XHTML document with IMG tags with custom properties ("XHTML node spoofing").</description>
      <reference source="CVE">CVE-2005-2269</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-216" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="rvt-31" comment="mozilla RPM is earlier than 37:1.7.10-1.1.3.1" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="upt-859" comment="/usr/bin/mozilla is executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1260" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>libgd</product>
      </affected>
      <dates>
        <submitted date="2005-06-27-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2005-06-29-06:49">DRAFT</status_change>
        <status_change date="2005-07-27-10:37">INTERIM</status_change>
        <status_change date="2005-08-18-07:37">ACCEPTED</status_change>
      </dates>
      <description>Integer overflow in GD Graphics Library libgd 2.0.28 (libgd2), and possibly other versions, allows remote attackers to cause a denial of service and possibly execute arbitrary code via PNG image files with large image rows values that lead to a heap-based buffer overflow in the gdImageCreateFromPngCtx function, a different set of vulnerabilities than CVE-2004-0941.</description>
      <reference source="CVE">CVE-2004-0990</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="cmp-260" comment="libgd or libgd-devel RPM is earlier than 0:1.8.4-12.3.1" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1261" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2005-10-12-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-10-19-05:46">DRAFT</status_change>
        <status_change date="2005-11-16-08:02">INTERIM</status_change>
        <status_change date="2005-12-01-06:00">ACCEPTED</status_change>
      </dates>
      <description>COM+ in Microsoft Windows does not properly "create and use memory structures," which allows local users or remote attackers to execute arbitrary code.</description>
      <reference source="CVE">CVE-2005-1978</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1112" comment="Windows XP 64-bit" negate="false"/>
          <criterion test_ref="wrt-4" comment="Win2K/XP/2003 service pack 1 is installed" negate="false"/>
          <criterion test_ref="cmp-608" comment="Either ole32.dll or rpcss.dll has a version less than 5.2.3790.2492" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1262" class="vulnerability">
      <affected family="hp-ux">
        <hpux:platform>HP-UX 11</hpux:platform>
        <product>SecureShell</product>
      </affected>
      <dates>
        <submitted date="2006-01-11-12:55">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-01-12-09:18">DRAFT</status_change>
        <status_change date="2006-02-01-09:08">INTERIM</status_change>
        <status_change date="2006-02-22-08:27">ACCEPTED</status_change>
      </dates>
      <description>zlib 1.2 and later versions allows remote attackers to cause a denial of service (crash) via a crafted compressed stream with an incomplete code description of a length greater than 1, which leads to a buffer overflow, as demonstrated using a crafted PNG file.</description>
      <reference source="CVE">CVE-2005-2096</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-682" comment="700 Series or 800 Series OS Release 11.23" negate="false"/>
          <criterion test_ref="hst-36" comment="Secure_Shell.SECURE_SHELL is installed" negate="false"/>
          <criterion test_ref="hst-35" comment="Secure_Shell.SECURE_SHELL with version less than A.04.20.005 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1263" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2005-11-09-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-11-10-07:06">DRAFT</status_change>
        <status_change date="2005-12-01-06:00">INTERIM</status_change>
        <status_change date="2005-12-16-01:04">ACCEPTED</status_change>
      </dates>
      <description>Multiple integer overflows in the Graphics Rendering Engine (GDI32.DLL) in Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allow remote attackers to execute arbitrary code via crafted Windows Metafile (WMF) and Enhanced Metafile (EMF) format images that lead to heap-based buffer overflows, as demonstrated using MRBP16::bCheckRecord.</description>
      <reference source="CVE">CVE-2005-2123</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-647" comment="64-bit XP or Server 2003 is installed" negate="false"/>
          <criterion test_ref="wrt-10026" comment="Win2K/XP/2003 is patched" negate="true"/>
          <criterion test_ref="wft-702" comment="the version of Gdi32.dll is less than 5.2.3790.419" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1264" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Windows kernel</product>
      </affected>
      <dates>
        <submitted date="2005-01-31-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2005-02-11-12:00">DRAFT</status_change>
        <status_change date="2005-03-02-12:00">INTERIM</status_change>
        <status_change date="2005-03-23-12:00">ACCEPTED</status_change>
        <modified date="2005-06-02-12:00" comment="Added product">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-06-08-03:17">INTERIM</status_change>
        <status_change date="2005-06-29-06:49">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in Windows Kernel allows local users to gain privileges by causing certain error messages to be passed to a debugger.</description>
      <reference source="CVE">CVE-2003-0112</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-478" comment="the patch Q811493 is installed" negate="true"/>
          <criterion test_ref="cmp-1058" comment="Windows XP 32-bit edition is installed" negate="false"/>
          <criterion test_ref="wrt-4" comment="Win2K/XP/2003 service pack 1 is installed" negate="false"/>
          <criterion test_ref="wft-480" comment="The version of Ntoskrnl.exe is less than 5.1.2600.1151" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1265" class="vulnerability">
      <affected family="hp-ux">
        <hpux:platform>HP-UX 11</hpux:platform>
        <product>ftpd</product>
      </affected>
      <dates>
        <submitted date="2006-04-06-06:39">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-04-12-05:16">DRAFT</status_change>
        <status_change date="2006-05-03-10:06">INTERIM</status_change>
      </dates>
      <description>The wu_fnmatch function in wu_fnmatch.c for wu-fptd 2.6.1 and 2.6.2 allows remote attackers to cause a denial of service (CPU exhaustion by recursion) via a glob pattern with a large number of * (wildcard) characters, as demonstrated using the dir copmmand.</description>
      <reference source="CVE">CVE-2005-0256</reference>
      <status>INTERIM</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-682" comment="700 Series or 800 Series OS Release 11.23" negate="false"/>
          <criterion test_ref="hpt-63" comment="Patch PHNE_34306 or subsequent is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1267" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>DirectX</product>
      </affected>
      <dates>
        <submitted date="2005-10-12-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-10-19-05:46">DRAFT</status_change>
        <status_change date="2005-11-16-08:02">INTERIM</status_change>
        <status_change date="2005-12-01-06:00">ACCEPTED</status_change>
      </dates>
      <description>QUARTZ.DLL in Microsoft Windows Media Player 9 allows remote attackers to write a null byte to arbitrary memory via an AVI file with a crafted strn element with a modified length value.</description>
      <reference source="CVE">CVE-2005-2128</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-600" comment="DirectX packaged with Windows 2000,SP4 has DirectShow Vulnerability" negate="false"/>
          <criterion test_ref="cmp-598" comment="Standalone DirectX 8 has DirectShow Vulnerability" negate="false"/>
          <criterion test_ref="cmp-599" comment="Standalone DirectX 9 has DirectShow Vulnerability" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1268" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>mozilla</product>
      </affected>
      <dates>
        <submitted date="2005-08-15-04:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2005-08-19-10:05">DRAFT</status_change>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Firefox before 1.0.5 and Mozilla before 1.7.9 does not clearly associate a Javascript dialog box with the web page that generated it, which allows remote attackers to spoof a dialog box from a trusted site and facilitates phishing attacks, aka the "Dialog Origin Spoofing Vulnerability."</description>
      <reference source="CVE">CVE-2005-2268</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-216" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="rvt-31" comment="mozilla RPM is earlier than 37:1.7.10-1.1.3.1" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="upt-859" comment="/usr/bin/mozilla is executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1269" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2005-10-12-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-10-19-05:46">DRAFT</status_change>
        <status_change date="2005-11-16-08:02">INTERIM</status_change>
        <status_change date="2005-12-01-06:00">ACCEPTED</status_change>
      </dates>
      <description>COM+ in Microsoft Windows does not properly "create and use memory structures," which allows local users or remote attackers to execute arbitrary code.</description>
      <reference source="CVE">CVE-2005-1978</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1058" comment="Windows XP 32-bit edition is installed" negate="false"/>
          <criterion test_ref="wrt-4" comment="Win2K/XP/2003 service pack 1 is installed" negate="false"/>
          <criterion test_ref="cmp-606" comment="Either ole32.dll or rpcss.dll has a version less than 5.1.2600.1720" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1271" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Windows kernel</product>
      </affected>
      <dates>
        <submitted date="2005-05-02-12:00">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </submitted>
        <status_change date="2005-05-04-12:00">DRAFT</status_change>
        <status_change date="2005-06-01-12:00">INTERIM</status_change>
        <modified date="2005-06-02-12:00" comment="Added product">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-06-22-12:38">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to cause a denial of service (i.e., system crash) via a malformed request, aka "Object Management Vulnerability".</description>
      <reference source="CVE">CVE-2005-0550</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wft-583" comment="The version of Ntoskrnl.exe is less than 5.2.3790.280" negate="false"/>
          <criterion test_ref="wrt-427" comment="the patch KB890859 is installed (Hotfix key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1272" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>mozilla</product>
      </affected>
      <dates>
        <submitted date="2005-11-11-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-12-12-10:00">DRAFT</status_change>
        <status_change date="2005-12-28-04:28">INTERIM</status_change>
        <status_change date="2006-01-12-08:59">ACCEPTED</status_change>
      </dates>
      <description>Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to spoof DOM objects via an XBL control that implements an internal XPCOM interface.</description>
      <reference source="CVE">CVE-2005-2704</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-621" comment="Mozilla Suite version 1.7.10 or earlier is installed" negate="false"/>
          <criterion test_ref="cmp-631" comment="Mozilla Firefox version 1.0.6 or earlier is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1273" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Sadmin</product>
      </affected>
      <dates>
        <submitted date="2004-10-15-02:06">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <modified date="2004-10-15-02:21" comment="Added check for sadmind called with strong authentication">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </modified>
        <status_change date="2004-10-20-02:35">DRAFT</status_change>
        <status_change date="2004-11-03-12:00">INTERIM</status_change>
        <status_change date="2004-12-09-08:46">ACCEPTED</status_change>
      </dates>
      <description>The default installation of sadmind on Solaris uses weak authentication (AUTH_SYS), which allows local and remote attackers to spoof Solstice AdminSuite clients and gain root privileges via a certain sequence of RPC packets.</description>
      <reference source="CVE">CVE-2003-0722</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" negate="false"/>
          <criterion test_ref="sat-7" comment="System and Network Administration Framework Installed" negate="false"/>
          <criterion test_ref="spt-259" comment="Patch 116457-02 or later installed" negate="true"/>
          <criterion test_ref="spt-260" comment="Patch 116442-01 or later installed" negate="true"/>
          <criterion test_ref="spt-261" comment="Patch 116454-01 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
          <criterion test_ref="sit-209" comment="inetd.conf contains sadmind" negate="false"/>
          <criterion test_ref="sit-210" comment="Sadmin called using strong authentication" negate="true"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1276" class="vulnerability">
      <affected family="hp-ux">
        <hpux:platform>HP-UX 11</hpux:platform>
        <product>ftpd</product>
      </affected>
      <dates>
        <submitted date="2005-11-30-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-12-20-11:03">DRAFT</status_change>
        <status_change date="2006-01-04-08:04">INTERIM</status_change>
        <status_change date="2006-01-25-07:30">ACCEPTED</status_change>
      </dates>
      <description>The FTP server in HP-UX 10.20, B.11.00, and B.11.11, allows remote attackers to list arbitrary directories as root by running the LIST command before logging in.</description>
      <reference source="CVE">CVE-2005-3296</reference>
      <status>ACCEPTED</status>
      <version>5</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-619" comment="700 Series or 800 Series OS Release 11.00" negate="false"/>
          <criterion test_ref="cmp-666" comment="InternetSrvcs.INETSVCS-RUN or InternetSrvcs.INET-ENG-A-MAN (B.11.00) is installed" negate="false"/>
          <criterion test_ref="hpt-4" comment="Patch PHNE_23949 or later is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1279" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 98</windows:platform>
        <product>Program Group Converter</product>
      </affected>
      <dates>
        <submitted date="2004-10-14-03:38">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <status_change date="2004-10-20-02:35">DRAFT</status_change>
        <status_change date="2004-11-03-12:00">INTERIM</status_change>
        <status_change date="2004-12-09-08:46">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the Windows Program Group Converter (grpconv.exe) may allow remote attackers to execute arbitrary code via a shell: URL with a long filename and a .grp extension, which is not properly handled when the shell capability launches grpconv.exe.</description>
      <reference source="CVE">CVE-2004-0572</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-391" comment="Windows 98 Installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1280" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Color Management Module</product>
      </affected>
      <dates>
        <submitted date="2005-08-02-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2005-08-03-11:30">DRAFT</status_change>
        <status_change date="2005-08-18-07:37">INTERIM</status_change>
        <status_change date="2005-09-21-01:33">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the Microsoft Color Management Module for Windows allows remote attackers to execute arbitrary code via an image with crafted ICC profile format tags.</description>
      <reference source="CVE">CVE-2005-1219</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1106" comment="Windows 2000 (sp4 or earlier) is installed" negate="false"/>
          <criterion test_ref="wft-396" comment="the version of mscms.dll is less than 5.0.2195.7054" negate="false"/>
          <criterion test_ref="wrt-128" comment="the patch KB901214 is installed " negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1281" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>mozilla</product>
      </affected>
      <dates>
        <submitted date="2005-08-15-04:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2005-08-19-10:05">DRAFT</status_change>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>The InstallTrigger.install method in Firefox before 1.0.5 and Mozilla before 1.7.9 allows remote attackers to execute a callback function in the context of another domain by forcing a page navigation after the install method has been called, which causes the callback to be run in the context of the new page and results in a same origin violation.</description>
      <reference source="CVE">CVE-2005-2263</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-216" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="rvt-31" comment="mozilla RPM is earlier than 37:1.7.10-1.1.3.1" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="upt-859" comment="/usr/bin/mozilla is executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1283" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>TIP</product>
      </affected>
      <dates>
        <submitted date="2005-10-12-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-10-19-05:46">DRAFT</status_change>
        <status_change date="2005-11-16-08:02">INTERIM</status_change>
        <status_change date="2005-12-01-06:00">ACCEPTED</status_change>
      </dates>
      <description>Distributed Transaction Controller in Microsoft Windows allows remote servers to cause a denial of service (MSDTC service exception and exit) via an "unexpected protocol command during the reconnection request," which is not properly handled by the Transaction Internet Protocol (TIP) functionality.</description>
      <reference source="CVE">CVE-2005-1979</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1058" comment="Windows XP 32-bit edition is installed" negate="false"/>
          <criterion test_ref="wrt-4" comment="Win2K/XP/2003 service pack 1 is installed" negate="false"/>
          <criterion test_ref="cmp-606" comment="Either ole32.dll or rpcss.dll has a version less than 5.1.2600.1720" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1284" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2005-10-12-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-10-19-05:46">DRAFT</status_change>
        <status_change date="2005-11-16-08:02">INTERIM</status_change>
        <status_change date="2005-12-01-06:00">ACCEPTED</status_change>
      </dates>
      <description>The FTP client in Windows XP SP1 and Server 2003, and Internet Explorer 6 SP1 on Windows 2000 SP4, when "Enable Folder View for FTP Sites" is enabled and the user manually initiates a file transfer, allows user-complicit, remote FTP servers to overwrite files in arbitrary locations via crafted filenames.</description>
      <reference source="CVE">CVE-2005-2126</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wft-691" comment="msieftp.dll is less than 6.0.3790.383" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1287" class="vulnerability">
      <affected family="hp-ux">
        <hpux:platform>HP-UX 11</hpux:platform>
        <product>mozilla</product>
      </affected>
      <dates>
        <submitted date="2005-11-30-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-12-27-08:49">DRAFT</status_change>
        <status_change date="2006-01-12-08:59">INTERIM</status_change>
        <status_change date="2006-02-01-09:08">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the International Domain Name (IDN) support in Mozilla Firefox 1.0.6 and earlier, and Netscape 8.0.3.3 and 7.2, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a hostname with all "soft" hyphens (character 0xAD), which is not properly handled by the NormalizeIDN call in nsStandardURL::BuildNormalizedSpec.</description>
      <reference source="CVE">CVE-2005-2871</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-691" comment="700 Series or 800 Series OS Release 11.00, 11.11, 11.22, or 11.23" negate="false"/>
          <criterion test_ref="hst-31" comment="Mozilla is installed" negate="false"/>
          <criterion test_ref="hst-32" comment="Mozilla v1.7.12 (1.7.12.0.00) or later is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1288" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Windows 2000</product>
      </affected>
      <dates>
        <submitted date="2005-04-22-12:00">
          <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
        </submitted>
        <status_change date="2005-04-27-12:06">DRAFT</status_change>
        <status_change date="2005-06-01-03:30">INTERIM</status_change>
        <status_change date="2005-06-22-12:38">ACCEPTED</status_change>
      </dates>
      <description>Windows Server 2003 and XP SP2, with Windows Firewall turned off, allows remote attackers to cause a denial of service (CPU consumption) via a TCP packet with the SYN flag set and the same destination and source address and port, aka a reoccurrence of the "Land" vulnerability (CVE-1999-0016).</description>
      <reference source="CVE">CVE-2005-0688</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
          <criterion test_ref="wrt-538" comment="Win2K/XP/2003 service pack 4 (or earlier) is installed" negate="false"/>
          <criterion test_ref="wft-593" comment="the version of Tcpip.sys is less than 5.0.2195.7035" negate="false"/>
          <criterion test_ref="wrt-443" comment="the patch KB893066 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1289" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2005-10-12-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-10-19-05:46">DRAFT</status_change>
        <status_change date="2005-11-16-08:02">INTERIM</status_change>
        <status_change date="2005-12-01-06:00">ACCEPTED</status_change>
      </dates>
      <description>netman.dll in Microsoft Windows Connections Manager Library allows local users to cause a denial of service (Network Connections Service crash) via a large integer argument to a particular function.</description>
      <reference source="CVE">CVE-2005-2307</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
          <criterion test_ref="wrt-432" comment="Win2K/XP/2003 service pack 4 is installed" negate="false"/>
          <criterion test_ref="wft-692" comment="netman.dll is less than 5.0.2195.7061" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1290" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Internet Explorer</product>
      </affected>
      <dates>
        <submitted date="2006-04-12-12:55">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-04-12-05:16">DRAFT</status_change>
        <status_change date="2006-05-03-10:06">INTERIM</status_change>
      </dates>
      <description>Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via HTML elements with a certain crafted tag, which leads to memory corruption.</description>
      <reference source="CVE">CVE-2006-1188</reference>
      <status>INTERIM</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-613" comment="Win2K or XP,SP1 is installed" negate="false"/>
          <criterion test_ref="wrt-652" comment="Internet Explorer 6 (any patch level) is installed" negate="false"/>
          <criterion test_ref="wft-776" comment="the version of mshtml.dll is less than 6.0.2800.1543" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1291" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2005-10-12-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-10-19-05:46">DRAFT</status_change>
        <status_change date="2005-11-16-08:02">INTERIM</status_change>
        <status_change date="2005-12-01-06:00">ACCEPTED</status_change>
      </dates>
      <description>Web View in Windows Explorer on Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 does not properly handle certain HTML characters in preview fields, which allows remote user-complicit attackers to execute arbitrary code.</description>
      <reference source="CVE">CVE-2005-2117</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
          <criterion test_ref="wrt-432" comment="Win2K/XP/2003 service pack 4 is installed" negate="false"/>
          <criterion test_ref="wft-683" comment="shell32.dll is less than 5.0.3900.7071" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1294" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 98</windows:platform>
        <product>Internet Explorer 6</product>
        <product>Internet Explorer 6 SP1</product>
      </affected>
      <dates>
        <submitted date="2005-01-05-05:00">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </submitted>
        <status_change date="2005-01-12-05:00">DRAFT</status_change>
        <status_change date="2005-02-02-05:00">INTERIM</status_change>
        <status_change date="2005-02-23-05:00">ACCEPTED</status_change>
        <modified date="2005-06-02-04:00" comment="modified wrt-24 - corrected hotfix key">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <status_change date="2005-06-08-04:00">INTERIM</status_change>
        <status_change date="2005-06-29-04:00">ACCEPTED</status_change>
        <modified date="2005-09-20-04:00" comment="modified wrt-18 - Changed value element to include pattern match">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-21-01:27">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Heap-based buffer overflow in Internet Explorer 6 allows remote attackers to execute arbitrary code via long (1) SRC or (2) NAME attributes in IFRAME, FRAME, and EMBED elements, as originally discovered using the mangleme utility, aka "the IFRAME vulnerability" or the "HTML Elements Vulnerability."</description>
      <reference source="CVE">CVE-2004-1050</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-256" comment="Internet Explorer 6.0 or IE 6.0 SP1 is installed" negate="false"/>
          <criterion test_ref="cmp-25" comment="patch kb889293 is installed (hotfix or ID)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1296" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Internet Explorer</product>
      </affected>
      <dates>
        <submitted date="2006-04-12-12:55">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-04-12-05:16">DRAFT</status_change>
        <status_change date="2006-05-03-10:06">INTERIM</status_change>
      </dates>
      <description>Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via HTML elements with a certain crafted tag, which leads to memory corruption.</description>
      <reference source="CVE">CVE-2006-1188</reference>
      <status>INTERIM</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wrt-10026" comment="Win2K/XP/2003 is patched" negate="true"/>
          <criterion test_ref="wft-778" comment="the version of mshtml.dll is less than 6.0.3790.507" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1297" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Telephony Service</product>
      </affected>
      <dates>
        <submitted date="2005-08-11-04:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <status_change date="2005-08-19-10:05">DRAFT</status_change>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the Telephony Application Programming Interface (TAPI) for Microsoft Windows 98, Windows 98 SE, Windows ME, Windows 2000, Windows XP, and Windows Server 2003 allows attackers elevate privileges or execute arbitrary code via a crafted message.</description>
      <reference source="CVE">CVE-2005-0058</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="cmp-303" comment="a vulnerable version of tapisrv.dll exists" negate="false"/>
          <criterion test_ref="wrt-139" comment="the patch kb893756 is installed (Hotfix key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-201" comment="the Telephony service is enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1299" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Internet Explorer</product>
      </affected>
      <dates>
        <submitted date="2005-11-11-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-12-12-10:00">DRAFT</status_change>
        <modified date="2005-12-14-12:00" comment="Updated with newly available information.">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </modified>
        <status_change date="2006-01-04-08:04">INTERIM</status_change>
        <status_change date="2006-01-25-07:30">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Internet Explorer 6 SP2 6.0.2900.2180 and 6.0.2800.1106, and earlier versions, allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a Javascript BODY onload event that calls the window function, aka "Mismatched Document Object Model Objects Memory Corruption Vulnerability."</description>
      <reference source="CVE">CVE-2005-1790</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-35" comment="Windows XP 32 bit Service Pack 2" negate="false"/>
          <criterion test_ref="wrt-10027" comment="Internet Explorer 6 is installed" negate="false"/>
          <criterion test_ref="wft-706" comment="the version of mshtml.dll is less than 6.0.2900.2802" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1303" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Internet Explorer</product>
      </affected>
      <dates>
        <submitted date="2005-11-11-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-12-12-10:00">DRAFT</status_change>
        <modified date="2005-12-14-12:00" comment="Updated with newly available information.">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </modified>
        <status_change date="2006-01-04-08:04">INTERIM</status_change>
        <status_change date="2006-01-25-07:30">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Internet Explorer 6 SP2 6.0.2900.2180 and 6.0.2800.1106, and earlier versions, allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a Javascript BODY onload event that calls the window function, aka "Mismatched Document Object Model Objects Memory Corruption Vulnerability."</description>
      <reference source="CVE">CVE-2005-1790</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1066" comment="Windows XP 64-bit with Service Pack 1" negate="false"/>
          <criterion test_ref="wrt-10027" comment="Internet Explorer 6 is installed" negate="false"/>
          <criterion test_ref="wrt-4" comment="Win2K/XP/2003 service pack 1 is installed" negate="false"/>
          <criterion test_ref="wft-707" comment="the version of mshtml.dll is less than 6.0.3790.2577" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1304" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Windows Animated Cursor</product>
      </affected>
      <dates>
        <submitted date="2005-01-14-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2005-01-20-02:31">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>The Windows Animated Cursor (ANI) capability in Windows NT, Windows 2000 through SP4, Windows XP through SP1, and Windows 2003 allow remote attackers to cause a denial of service via (1) the frame number set to zero, which causes an invalid memory address to be used and leads to a kernel crash, or (2) the rate number set to zero, which leads to resource exhaustion and hang.</description>
      <reference source="CVE">CVE-2004-1305</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-61" comment="Windows XP SP1 OR Windows XP 64-bit SP1 is installed" negate="false"/>
          <criterion test_ref="wft-354" comment="the version of user32.dll is less than 5.1.2600.1617" negate="false"/>
          <criterion test_ref="wrt-68" comment="the patch kb891711 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1306" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Windows Media Player 9</product>
      </affected>
      <dates>
        <submitted date="2005-02-16-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2005-02-18-12:00">DRAFT</status_change>
        <modified date="2005-02-22-10:00" comment="Added vulnerable configuration">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <modified date="2005-02-22-10:01" comment="modified wrt-169 - fixed version">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <modified date="2005-02-22-10:02" comment="modified wrt-169 - fixed pattern match">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <modified date="2005-02-22-10:05" comment="modified wrt-174 - modified name">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <modified date="2005-02-22-10:05" comment="modified wrt-175 - modified name">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <modified date="2005-02-22-10:13" comment="modified wrt-176 - modified name">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <modified date="2005-02-22-10:14" comment="modified wrt-177 - modified name">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <modified date="2005-02-22-10:55" comment="modified wrt-178 - modified name ">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-03-09-07:56">INTERIM</status_change>
        <status_change date="2005-03-29-07:59">ACCEPTED</status_change>
      </dates>
      <description>Windows Media Player 9 allows remote attackers to execute arbitrary code via a PNG file containing large (1) width or (2) height values, aka the "PNG Processing Vulnerability."</description>
      <reference source="CVE">CVE-2004-1244</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-82" comment="Windows Media Player 9.0 installed" negate="false"/>
          <criterion test_ref="wft-374" comment="the version of wmp.dll is les than 9.0.0.3250" negate="false"/>
          <criterion test_ref="wrt-84" comment="The patch KB885492 is installed on Windows XP" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-188" comment="The files .asx, .wax, .wvx, .wpl, .wmx, .wms, .wmz EXIST" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1307" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>mozilla</product>
      </affected>
      <dates>
        <submitted date="2005-11-11-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-12-12-10:00">DRAFT</status_change>
        <status_change date="2005-12-28-04:28">INTERIM</status_change>
        <status_change date="2006-01-12-08:59">ACCEPTED</status_change>
      </dates>
      <description>Integer overflow in the JavaScript engine in Firefox before 1.0.7 and Mozilla Suite before 1.7.12 might allow remote attackers to execute arbitrary code.</description>
      <reference source="CVE">CVE-2005-2705</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-621" comment="Mozilla Suite version 1.7.10 or earlier is installed" negate="false"/>
          <criterion test_ref="cmp-631" comment="Mozilla Firefox version 1.0.6 or earlier is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1308" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Internet Explorer 5.01 Service Pack 4</product>
      </affected>
      <dates>
        <submitted date="2005-03-17-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2005-03-23-08:09">DRAFT</status_change>
        <status_change date="2005-04-13-12:15">INTERIM</status_change>
        <status_change date="2005-05-04-12:33">ACCEPTED</status_change>
        <modified date="2005-12-26-09:40" comment="Removed test to check kb867282.">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </modified>
        <status_change date="2006-01-12-08:59">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 5.01, 5.5, and 6 allows remote attackers to spoof a less restrictive security zone and execute arbitrary code via an HTML page containing URLs that contain hostnames that have been double hex encoded, which are decoded twice to generate a malicious hostname, aka the "URL Decoding Zone Spoofing Vulnerability."</description>
      <reference source="CVE">CVE-2005-0054</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-54" comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false"/>
          <criterion test_ref="wft-407" comment="the version of mshtml.dll is less than 5.0.3825.700" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1310" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2006-02-17-07:36">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-02-22-08:27">DRAFT</status_change>
        <status_change date="2006-03-09-12:19">INTERIM</status_change>
        <status_change date="2006-04-06-06:30">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Windows XP SP1 and SP2, and Server 2003 up to SP1, allows remote attackers to cause a denial of service (hang) via certain malformed IGMP packets, aka the "IGMP v3 DoS Vulnerability."</description>
      <reference source="CVE">CVE-2006-0021</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wrt-10026" comment="Win2K/XP/2003 is patched" negate="true"/>
          <criterion test_ref="wft-759" comment="the version of Tcpip.sys is less than 5.2.3790.468 (S03-Gold)" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1311" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 4</redhat:platform>
      </affected>
      <dates>
        <submitted date="2005-08-15-04:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2005-08-19-10:05">DRAFT</status_change>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>The InstallTrigger.install method in Firefox before 1.0.5 and Mozilla before 1.7.9 allows remote attackers to execute a callback function in the context of another domain by forcing a page navigation after the install method has been called, which causes the callback to be run in the context of the new page and results in a same origin violation.</description>
      <reference source="CVE">CVE-2005-2263</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-1" comment="Red Hat Enterprise 4 is installed" negate="false"/>
          <criterion test_ref="rvt-32" comment="mozilla RPM is earlier than 37:1.7.10-1.4.1" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="upt-859" comment="/usr/bin/mozilla is executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1313" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 4</redhat:platform>
        <product>mozilla</product>
      </affected>
      <dates>
        <submitted date="2005-08-15-04:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2005-08-19-10:05">DRAFT</status_change>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Firefox before 1.0.5 and Mozilla before 1.7.9 does not clearly associate a Javascript dialog box with the web page that generated it, which allows remote attackers to spoof a dialog box from a trusted site and facilitates phishing attacks, aka the "Dialog Origin Spoofing Vulnerability."</description>
      <reference source="CVE">CVE-2005-2268</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-1" comment="Red Hat Enterprise 4 is installed" negate="false"/>
          <criterion test_ref="rvt-32" comment="mozilla RPM is earlier than 37:1.7.10-1.4.1" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="upt-859" comment="/usr/bin/mozilla is executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1316" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Outlook</product>
      </affected>
      <dates>
        <submitted date="2006-01-11-12:56">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-01-12-09:25">DRAFT</status_change>
        <status_change date="2006-02-01-09:08">INTERIM</status_change>
        <status_change date="2006-02-22-08:27">ACCEPTED</status_change>
      </dates>
      <description>Unspecified vulnerability in Microsoft Outlook 2000 through 2003, Exchange 5.0 Server SP2 and 5.5 SP4, Exchange 2000 SP3, and Office allows remote attackers to execute arbitrary code via an e-mail message with a crafted Transport Neutral Encapsulation Format (TNEF) MIME attachment, related to message length validation.</description>
      <reference source="CVE">CVE-2006-0002</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wft-738" comment="the version of Mdbmsg.dll greater than or equal 5.0.1460.9 (Exchange Server 5.0,SP2 is installed)." negate="false"/>
          <criterion test_ref="wft-736" comment="the version of Mdbmsg.dll is less than 5.0.1462.22" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1317" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Internet Explorer</product>
      </affected>
      <dates>
        <submitted date="2005-12-13-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-12-16-01:03">DRAFT</status_change>
        <status_change date="2006-01-04-08:04">INTERIM</status_change>
        <status_change date="2006-01-25-07:30">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Internet Explorer 5.01, 5.5, and 6, when using an HTTPS proxy server that requires Basic Authentication, sends URLs in cleartext, which allows remote attackers to obtain sensitive information, aka "HTTPS Proxy Vulnerability."</description>
      <reference source="CVE">CVE-2005-2830</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wrt-10027" comment="Internet Explorer 6 is installed" negate="false"/>
          <criterion test_ref="wft-708" comment="the version of mshtml.dll is less than 6.0.3790.449" negate="false"/>
          <criterion test_ref="wrt-3" comment="a Win2K/XP/2003 service pack is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1319" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Microsoft Internet Explorer 6</product>
      </affected>
      <dates>
        <submitted date="2005-08-23-04:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2005-08-25-10:05">DRAFT</status_change>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
        <modified date="2005-12-26-09:40" comment="Removed reference to patch kb896727 from criteria.">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </modified>
        <status_change date="2006-01-12-08:59">ACCEPTED</status_change>
      </dates>
      <description>Unknown vulnerability in Internet Explorer 5.0, 5.5, and 6.0 allows remote attackers to obtain information and possibly execute code when browsing from a web site to a web folder view using WebDAV, aka "Web Folder Behaviors Cross-Domain Vulnerability".</description>
      <reference source="CVE">CVE-2005-1989</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-200" comment="Internet Explorer 6.0 Installed XP SP2" negate="false"/>
          <criterion test_ref="wft-626" comment="the version of mshtml.dll is less than 6.0.2900.2722" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1321" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>Windows kernel</product>
      </affected>
      <dates>
        <submitted date="2004-12-16-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2005-01-12-12:41">DRAFT</status_change>
        <status_change date="2005-02-02-12:00">INTERIM</status_change>
        <status_change date="2005-02-23-09:25">ACCEPTED</status_change>
      </dates>
      <description>The Local Procedure Call (LPC) interface of the Windows Kernel for Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 does not properly validate the lengths of messages sent to the LPC port, which allows local users to gain privileges, aka "Windows Kernel Vulnerability."</description>
      <reference source="CVE">CVE-2004-0893</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-44" comment="Windows NT Server 4.0 is installed" negate="false"/>
          <criterion test_ref="wft-146" comment="The version of Ntoskrnl.exe is less than 4.0.1381.7268" negate="false"/>
          <criterion test_ref="wrt-36" comment="the patch kb885835is installed (Hotfix key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1323" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>MDAC</product>
      </affected>
      <dates>
        <submitted date="2006-04-12-12:55">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-04-12-05:16">DRAFT</status_change>
        <status_change date="2006-05-03-10:06">INTERIM</status_change>
      </dates>
      <description>Unspecified vulnerability in the RDS.Dataspace ActiveX control, which is contained in ActiveX Data Objects (ADO) and distributed in Microsoft Data Access Components (MDAC) 2.7 and 2.8, allows remote attackers to execute arbitrary code via unknown attack vectors.</description>
      <reference source="CVE">CVE-2006-0003</reference>
      <status>INTERIM</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wrt-10026" comment="Win2K/XP/2003 is patched" negate="true"/>
          <criterion test_ref="wft-786" comment="the version of msadco.dll is less than 2.80.1062.0" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1325" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>TIP</product>
      </affected>
      <dates>
        <submitted date="2005-10-12-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-10-19-05:46">DRAFT</status_change>
        <status_change date="2005-11-16-08:02">INTERIM</status_change>
        <status_change date="2005-12-01-06:00">ACCEPTED</status_change>
      </dates>
      <description>Distributed Transaction Controller in Microsoft Windows allows remote servers to cause a denial of service (MSDTC service hang) via a crafted Transaction Internet Protocol (TIP) message that causes DTC to repeatedly connect to a target IP and port number after an error occurs, aka the "Distributed TIP Vulnerability."</description>
      <reference source="CVE">CVE-2005-1980</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1112" comment="Windows XP 64-bit" negate="false"/>
          <criterion test_ref="wrt-4" comment="Win2K/XP/2003 service pack 1 is installed" negate="false"/>
          <criterion test_ref="cmp-608" comment="Either ole32.dll or rpcss.dll has a version less than 5.2.3790.2492" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1326" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 98</windows:platform>
        <windows:platform>Microsoft Windows ME</windows:platform>
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Internet Explorer</product>
      </affected>
      <dates>
        <submitted date="2005-08-18-04:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2005-08-25-04:00">DRAFT</status_change>
        <modified date="2005-09-08-04:00" comment="modified wet-2 - Corrected structure of path components.">
          <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
        </modified>
        <status_change date="2005-09-28-01:05">INTERIM</status_change>
        <status_change date="2005-10-19-05:47">ACCEPTED</status_change>
        <modified date="2005-12-26-09:40" comment="This is fixed by MS05-038, which provides better test criteria. Changed test criteria accordingly.">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </modified>
        <status_change date="2006-01-12-08:59">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 5.01 SP4 up to 6 on various Windows operating systems, including IE 6.0.2900.2180 on Windows XP, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not ActiveX controls, as demonstrated using the JVIEW Profiler (Javaprxy.dll).  NOTE: the researcher says that the vendor could not reproduce this problem.</description>
      <reference source="CVE">CVE-2005-2087</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-54" comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false"/>
          <criterion test_ref="wft-629" comment="the version of mshtml.dll is less than 5.0.3831.1800" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1327" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Office</product>
      </affected>
      <dates>
        <submitted date="2006-03-15-10:53">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-03-15-07:17">DRAFT</status_change>
        <status_change date="2006-04-06-06:31">INTERIM</status_change>
        <status_change date="2006-05-03-10:06">ACCEPTED</status_change>
      </dates>
      <description>Stack-based buffer overflow in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-complicit attackers to execute arbitrary code via an Excel file with a malformed record with a modified length value, which leads to memory corruption.</description>
      <reference source="CVE">CVE-2006-0031</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-137" comment="Excel 2000 is installed" negate="false"/>
          <criterion test_ref="wft-769" comment="the version of excel.exe is less than 9.0.0.8938" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1328" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2005-10-12-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-10-19-05:46">DRAFT</status_change>
        <status_change date="2005-11-16-08:02">INTERIM</status_change>
        <status_change date="2005-12-01-06:00">ACCEPTED</status_change>
      </dates>
      <description>Stack-based buffer overflow in the Plug and Play (PnP) service (UMPNPMGR.DLL) in Microsoft Windows 2000 SP4, and XP SP1 and SP2, allows remote or local authenticated attackers to execute arbitrary code via a large number of "\" (backslash) characters in a registry key name, which triggers the overflow in a wsprintfW function call.</description>
      <reference source="CVE">CVE-2005-2120</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-2" comment="Windows XP is installed" negate="false"/>
          <criterion test_ref="wrt-4" comment="Win2K/XP/2003 service pack 1 is installed" negate="false"/>
          <criterion test_ref="wft-675" comment="umpnpmgr.dll is less than 5.1.2600.1734" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1329" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2005-10-12-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-10-19-05:46">DRAFT</status_change>
        <status_change date="2005-11-16-08:02">INTERIM</status_change>
        <status_change date="2005-12-01-06:00">ACCEPTED</status_change>
      </dates>
      <description>Windows Shell for Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 allows remote attackers to execute arbitrary commands via a shortcut (.lnk) file with long font properties that lead to a buffer overflow in the Client/Server Runtime Server Subsystem (CSRSS), a different vulnerability than CVE-2005-2118.</description>
      <reference source="CVE">CVE-2005-2122</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1058" comment="Windows XP 32-bit edition is installed" negate="false"/>
          <criterion test_ref="wrt-4" comment="Win2K/XP/2003 service pack 1 is installed" negate="false"/>
          <criterion test_ref="wft-684" comment="shell32.dll is less than 6.0.2800.1751" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1330" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>IIS 5.0</product>
      </affected>
      <dates>
        <submitted date="2004-10-13-09:30">
          <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
        </submitted>
        <status_change date="2004-10-13-01:15">DRAFT</status_change>
        <status_change date="2004-10-27-12:00">INTERIM</status_change>
        <status_change date="2004-11-17-10:00">ACCEPTED</status_change>
      </dates>
      <description>The WebDAV Message Handler for Internet Information Services (IIS) 5.0, 5.1, and 6.0 allows remote attackers to cause a denial of service (memory and CPU exhaustion, application crash) via a PROPFIND request with an XML message containing XML elements with a large number of attributes.</description>
      <reference source="CVE">CVE-2003-0718</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1107" comment="Windows 2000 (sp5 or earlier) is installed" negate="false"/>
          <criterion test_ref="wft-501" comment="the version of httpext.dll is less than 5.0.2195.6958" negate="false"/>
          <criterion test_ref="wrt-549" comment="the patch KB824151 is installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-541" comment="WebDav is disabled(for iis 5.0)" negate="true"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1331" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Office 2000 SP3</product>
      </affected>
      <dates>
        <submitted date="2005-07-21-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2005-07-27-10:36">DRAFT</status_change>
        <status_change date="2005-08-18-07:37">INTERIM</status_change>
        <status_change date="2005-09-21-01:33">ACCEPTED</status_change>
        <modified date="2005-12-20-07:05" comment="Edited criteria to check for Word 2000 instead of MS Office SP3.">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </modified>
        <status_change date="2006-01-04-08:04">ACCEPTED</status_change>
      </dates>
      <description>Stack-based buffer overflow in Microsoft Word 2000 and Word 2002, and Microsoft Works Suites 2000 through 2004, might allow remote attackers to execute arbitrary code via a .doc file with long font information.</description>
      <reference source="CVE">CVE-2005-0564</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-132" comment="Word 2000 is installed" negate="false"/>
          <criterion test_ref="wft-571" comment="the version of winword.exe is less than 9.0.0.8930" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1332" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Certificate Validation</product>
      </affected>
      <dates>
        <submitted date="2004-07-12-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <modified date="2004-07-13-12:00" comment="Added superceding patch info.">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <modified date="2004-07-14-12:00" comment="Changed to DRAFT">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2004-08-04-12:00">INTERIM</status_change>
        <status_change date="2004-08-25-12:00">ACCEPTED</status_change>
        <modified date="2005-03-07-12:00" comment="modified wrt-222 - changed pattern match">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-03-09-12:00">INTERIM</status_change>
        <status_change date="2005-03-29-12:00">ACCEPTED</status_change>
        <modified date="2005-06-02-12:00" comment="Added product">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-06-08-03:17">INTERIM</status_change>
        <status_change date="2005-06-29-06:49">ACCEPTED</status_change>
      </dates>
      <description>The (1) CertGetCertificateChain, (2) CertVerifyCertificateChainPolicy, and (3) WinVerifyTrust APIs within the CryptoAPI for Microsoft products including Microsoft Windows 98 through XP, Office for Mac, Internet Explorer for Mac, and Outlook Express for Mac, do not properly verify the Basic Constraints of intermediate CA-signed X.509 certificates, which allows remote attackers to spoof the certificates of trusted sites via a man-in-the-middle attack for SSL sessions, as originally reported for Internet Explorer and IIS.</description>
      <reference source="CVE">CVE-2002-0862</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-215" comment="Windows 2000 Service Pack 4 (or later) is installed" negate="false"/>
          <criterion test_ref="wft-433" comment="the version of cryptdlg.dll is less than 5.0.1558.6608" negate="false"/>
          <criterion test_ref="wrt-477" comment="the patch Q329115 is installed" negate="true"/>
          <criterion test_ref="wrt-187" comment="the patch kb835732 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1333" class="vulnerability">
      <affected family="hp-ux">
        <hpux:platform>HP-UX 11</hpux:platform>
        <product>ftpd</product>
      </affected>
      <dates>
        <submitted date="2006-04-06-06:39">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-04-12-05:16">DRAFT</status_change>
        <status_change date="2006-05-03-10:06">INTERIM</status_change>
      </dates>
      <description>The wu_fnmatch function in wu_fnmatch.c for wu-fptd 2.6.1 and 2.6.2 allows remote attackers to cause a denial of service (CPU exhaustion by recursion) via a glob pattern with a large number of * (wildcard) characters, as demonstrated using the dir copmmand.</description>
      <reference source="CVE">CVE-2005-0256</reference>
      <status>INTERIM</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-619" comment="700 Series or 800 Series OS Release 11.00" negate="false"/>
          <criterion test_ref="cmp-826" comment="INETSVCS-RUN without patch PHNE_34543 or later, OR WUFTP-26.INETSVCS-FTP with version less than B.11.11.01.006 is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1334" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Internet Explorer 6.0 for Windows Server 2003</product>
      </affected>
      <dates>
        <submitted date="2005-03-17-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2005-03-23-12:00">DRAFT</status_change>
        <status_change date="2005-04-13-12:00">INTERIM</status_change>
        <modified date="2005-04-21-10:35" comment="modified wrt-158 - removed note">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </modified>
        <modified date="2005-04-21-12:00" comment="modified wrt-158 - removed value to check against">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </modified>
        <modified date="2005-05-10-12:00" comment="modified wrt-51 - Comment updated to indicate IE 6.">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </modified>
        <status_change date="2005-06-01-03:30">ACCEPTED</status_change>
        <modified date="2005-12-26-09:40" comment="Removed test to check kb867282.">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </modified>
        <status_change date="2006-01-12-08:59">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via drag and drop events, aka the "Drag-and-Drop Vulnerability."</description>
      <reference source="CVE">CVE-2005-0053</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-51" comment="Internet Explorer 6  for Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wft-405" comment="the version of mshtml.dll is less than 6.0.3790.259" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-258" comment="Check for Drag&amp;Drop enabled and the patch kb834707(wildcard*)  missing" negate="false"/>
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1335" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Microsoft Internet Explorer 6</product>
      </affected>
      <dates>
        <submitted date="2005-08-23-04:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2005-08-25-10:05">DRAFT</status_change>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
        <modified date="2005-12-26-09:40" comment="Removed reference to patch kb896727 from criteria.">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </modified>
        <status_change date="2006-01-12-08:59">ACCEPTED</status_change>
      </dates>
      <description>Unknown vulnerability in Internet Explorer 5.0, 5.5, and 6.0 allows remote attackers to execute arbitrary code via a web site or an HTML e-mail containing a crafted JPEG image that causes memory corruption, aka "JPEG Image Rendering Memory Corruption Vulnerability".</description>
      <reference source="CVE">CVE-2005-1988</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-200" comment="Internet Explorer 6.0 Installed XP SP2" negate="false"/>
          <criterion test_ref="wft-626" comment="the version of mshtml.dll is less than 6.0.2900.2722" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1336" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Internet Explorer</product>
      </affected>
      <dates>
        <submitted date="2006-04-12-12:55">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-04-12-05:16">DRAFT</status_change>
        <status_change date="2006-05-03-10:06">INTERIM</status_change>
      </dates>
      <description>Microsoft Internet Explorer 5.01 through 6 allows remote attackers to conduct phishing attacks by spoofing the address bar and other parts of the trust UI via unknown methods that allow "window content to persist" after the user has navigated to another site, aka the "Address Bar Spoofing Vulnerability."  NOTE: this is a different vulnerability than CVE-2006-1626.</description>
      <reference source="CVE">CVE-2006-1192</reference>
      <status>INTERIM</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-613" comment="Win2K or XP,SP1 is installed" negate="false"/>
          <criterion test_ref="wrt-652" comment="Internet Explorer 6 (any patch level) is installed" negate="false"/>
          <criterion test_ref="wft-776" comment="the version of mshtml.dll is less than 6.0.2800.1543" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1337" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Internet Explorer 5.01 Service Pack 4</product>
      </affected>
      <dates>
        <submitted date="2005-08-23-04:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2005-08-25-10:05">DRAFT</status_change>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
        <modified date="2005-12-26-09:40" comment="Removed reference to patch kb896727 from criteria">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </modified>
        <status_change date="2006-01-12-08:59">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 5.0, 5.5, and 6.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not ActiveX controls, including (1) devenum.dll, (2) diactfrm.dll, (3) wmm2filt.dll, (4) fsusd.dll, (5) dmdskmgr.dll, (6) browsewm.dll, (7) browseui.dll, (8) shell32.dll, (9) mshtml.dll, (10) inetcfg.dll, (11) infosoft.dll, (12) query.dll, (13) syncui.dll, (14) clbcatex.dll, (15) clbcatq.dll, (16) comsvcs.dll, and (17) msconf.dll, which causes memory corruption, aka "COM Object Instantiation Memory Corruption Vulnerability," a different vulnerability than CVE-2005-2087.</description>
      <reference source="CVE">CVE-2005-1990</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-54" comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false"/>
          <criterion test_ref="wft-629" comment="the version of mshtml.dll is less than 5.0.3831.1800" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1338" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>TIP</product>
      </affected>
      <dates>
        <submitted date="2005-10-12-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-10-19-05:46">DRAFT</status_change>
        <status_change date="2005-11-16-08:02">INTERIM</status_change>
        <status_change date="2005-12-01-06:00">ACCEPTED</status_change>
      </dates>
      <description>Distributed Transaction Controller in Microsoft Windows allows remote servers to cause a denial of service (MSDTC service exception and exit) via an "unexpected protocol command during the reconnection request," which is not properly handled by the Transaction Internet Protocol (TIP) functionality.</description>
      <reference source="CVE">CVE-2005-1979</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
          <criterion test_ref="wrt-432" comment="Win2K/XP/2003 service pack 4 is installed" negate="false"/>
          <criterion test_ref="cmp-605" comment="Either ole32.dll or rpcss.dll has a version less than 5.0.2195.7059" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1339" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>mozilla</product>
      </affected>
      <dates>
        <submitted date="2006-02-07-06:13">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-02-22-08:27">DRAFT</status_change>
        <status_change date="2006-03-09-12:19">INTERIM</status_change>
        <status_change date="2006-04-06-06:30">ACCEPTED</status_change>
      </dates>
      <description>Multiple integer overflows in Mozilla Firefox 1.5, Thunderbird 1.5 if Javascript is enabled in mail, and SeaMonkey before 1.0 might allow remote attackers to execute arbitrary code via the (1) EscapeAttributeValue in jsxml.c for E4X, (2) nsSVGCairoSurface::Init in SVG, and (3) nsCanvasRenderingContext2D.cpp in Canvas.</description>
      <reference source="CVE">CVE-2006-0297</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-744" comment="Mozilla Firefox version 1.5 is installed and has NOT been patched with version 1.5.0.1" negate="false"/>
          <criterion test_ref="cmp-747" comment="A pre-release of SeaMonkey 1.0 is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1340" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Internet Explorer</product>
      </affected>
      <dates>
        <submitted date="2005-12-13-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-12-16-01:03">DRAFT</status_change>
        <status_change date="2006-01-04-08:04">INTERIM</status_change>
        <status_change date="2006-01-25-07:30">ACCEPTED</status_change>
      </dates>
      <description>Multiple design errors in Microsoft Internet Explorer 5.01, 5.5, and 6 allow user-complicit attackers to execute arbitrary code by (1) overlaying a malicious new window above a file download box, then (2) using a keyboard shortcut and delaying the display of the file download box until the user hits a shortcut that activates the "Run" button, aka "File Download Dialog Box Manipulation Vulnerability."</description>
      <reference source="CVE">CVE-2005-2829</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1066" comment="Windows XP 64-bit with Service Pack 1" negate="false"/>
          <criterion test_ref="wrt-10027" comment="Internet Explorer 6 is installed" negate="false"/>
          <criterion test_ref="wrt-4" comment="Win2K/XP/2003 service pack 1 is installed" negate="false"/>
          <criterion test_ref="wft-707" comment="the version of mshtml.dll is less than 6.0.3790.2577" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1344" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>Internet Explorer 6</product>
      </affected>
      <dates>
        <submitted date="2004-07-14-04:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <status_change date="2004-08-04-04:00">INTERIM</status_change>
        <status_change date="2004-08-25-04:00">ACCEPTED</status_change>
        <modified date="2005-03-14-05:00" comment="modified wrt-347 - Changed the service pack comparison from greater than or equal to a pattern match.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <modified date="2005-09-20-04:00" comment="modified wrt-18 - Changed value element to include pattern match">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-21-01:27">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Stack-based buffer overflow in the Task Scheduler for Windows 2000 and XP, and Internet Explorer 6 on Windows NT 4.0, allows local or remote attackers to execute arbitrary code via a .job file containing long parameters, as demonstrated using Internet Explorer and accessing a .job file on an anonymous share.</description>
      <reference source="CVE">CVE-2004-0212</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" negate="false"/>
          <criterion test_ref="wrt-347" comment="Win2K/XP/2003 service pack 6 (or later) is installed" negate="false"/>
          <criterion test_ref="wrt-18" comment="Internet Explorer 6 is installed" negate="false"/>
          <criterion test_ref="wft-457" comment="the version of mstask.dll is less than 4.71.1979.1" negate="false"/>
          <criterion test_ref="wrt-492" comment="Patch IE-KB841873-WindowsNT4sp6-x86-ENU.exe Installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1345" class="vulnerability">
      <affected family="hp-ux">
        <hpux:platform>HP-UX 11</hpux:platform>
        <product>SecureShell</product>
      </affected>
      <dates>
        <submitted date="2006-01-11-12:55">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-01-12-09:18">DRAFT</status_change>
        <status_change date="2006-02-01-09:08">INTERIM</status_change>
        <status_change date="2006-02-22-08:27">ACCEPTED</status_change>
      </dates>
      <description>sshd in OpenSSH before 4.2, when GSSAPIDelegateCredentials is enabled, allows GSSAPI credentials to be delegated to clients who log in using non-GSSAPI methods, which could cause those credentials to be exposed to untrusted users or hosts.</description>
      <reference source="CVE">CVE-2005-2798</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-682" comment="700 Series or 800 Series OS Release 11.23" negate="false"/>
          <criterion test_ref="hst-36" comment="Secure_Shell.SECURE_SHELL is installed" negate="false"/>
          <criterion test_ref="hst-35" comment="Secure_Shell.SECURE_SHELL with version less than A.04.20.005 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1346" class="vulnerability">
      <affected family="hp-ux">
        <hpux:platform>HP-UX 11</hpux:platform>
        <product>Apache</product>
      </affected>
      <dates>
        <submitted date="2005-11-30-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-12-20-11:03">DRAFT</status_change>
        <status_change date="2006-01-04-08:04">INTERIM</status_change>
        <status_change date="2006-01-25-07:30">ACCEPTED</status_change>
      </dates>
      <description>Off-by-one error in the mod_ssl Certificate Revocation List (CRL) verification callback in Apache, when configured to use a CRL, allows remote attackers to cause a denial of service (child process crash) via a CRL that causes a buffer overflow of one null byte.</description>
      <reference source="CVE">CVE-2005-1268</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-684" comment="700 Series or 800 Series OS Release 11.00, 11.11, or 11.23" negate="false"/>
          <criterion test_ref="hst-29" comment="hpuxwsAPACHE is installed" negate="false"/>
          <criterion test_ref="hst-30" comment="hpuxwsAPACHE has a version greater than or equal (A|B).2.0.55.0" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1347" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>FreeRADIUS</product>
      </affected>
      <dates>
        <submitted date="2004-11-22-12:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2005-01-12-12:41">DRAFT</status_change>
        <status_change date="2005-02-02-12:00">INTERIM</status_change>
        <status_change date="2005-02-23-09:25">ACCEPTED</status_change>
      </dates>
      <description>FreeRADIUS before 1.0.1 allows remote attackers to cause a denial of service (server crash) by sending an Ascend-Send-Secret attribute without the required leading packet.</description>
      <reference source="CVE">CVE-2004-0938</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rvt-2" comment="FreeRADIUS rpm older than 1.0.1-1" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="rlt-5" comment="radiusd is listening on the network" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1348" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>mozilla</product>
      </affected>
      <dates>
        <submitted date="2005-08-15-04:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2005-08-19-10:05">DRAFT</status_change>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Firefox before 1.0.5, Thunderbird before 1.0.5, Mozilla before 1.7.9, Netscape 8.0.2, and K-Meleon 0.9 runs XBL scripts even when Javascript has been disabled, which makes it easier for remote attackers to bypass such protection.</description>
      <reference source="CVE">CVE-2005-2261</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-216" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="rvt-31" comment="mozilla RPM is earlier than 37:1.7.10-1.1.3.1" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="upt-859" comment="/usr/bin/mozilla is executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1349" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>HTML Help ActiveX Control</product>
      </affected>
      <dates>
        <submitted date="2005-03-30-12:00">
          <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
        </submitted>
        <status_change date="2005-04-12-08:26">DRAFT</status_change>
        <status_change date="2005-04-27-12:07">INTERIM</status_change>
        <status_change date="2005-06-01-03:30">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 6.0 on Windows XP SP2 allows remote attackers to execute arbitrary code by using the "Related Topics" command in the Help ActiveX Control (hhctrl.ocx) to open a Help popup window containing the PCHealth tools.htm file in the local zone and injecting Javascript to be executed, as demonstrated using "writehta.txt" and the ADODB recordset, which saves a .HTA file to the local system, aka the "HTML Help ActiveX control Cross Domain Vulnerability."</description>
      <reference source="CVE">CVE-2004-1043</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wrt-93" comment="the patch kb890175 is installed" negate="true"/>
          <criterion test_ref="wft-390" comment="the version of hhctrl.ocx is less than 5.2.3790.233" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1351" class="compliance">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Exchange Server 2003</product>
      </affected>
      <dates>
        <submitted date="2004-12-29-12:00">
          <contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
        </submitted>
        <status_change date="2005-01-26-12:58">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Exchange Server 2003 should disallow execute permissions to the Exchange HTTP virtual directory</description>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wat-140" comment="allow script execute permissions to Exchange HTTP virtual directories" negate="true"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1352" class="compliance">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Exchange Server 2003</product>
      </affected>
      <dates>
        <submitted date="2004-12-29-12:00">
          <contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
        </submitted>
        <status_change date="2005-01-26-12:58">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Exchange Server 2003 should only allow digest or integrated windows authentication (NTLM) to connect to the Exchange HTTP virtual directories</description>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wat-850" comment="only allow integrated windows authentication (NTLM) to connect to the Exchange HTTP virtual directories" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1353" class="compliance">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Exchange Server 2003</product>
      </affected>
      <dates>
        <submitted date="2004-12-29-12:00">
          <contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
        </submitted>
        <status_change date="2005-01-26-12:58">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Exchange Server 2003 should disallow all access to Exchange HTTP virtual directories</description>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wat-860" comment="allow read access to the Exchange HTTP virtual directories" negate="true"/>
          <criterion test_ref="wat-861" comment="allow write access to the Exchange HTTP virtual directories" negate="true"/>
          <criterion test_ref="wat-862" comment="allow script source access to the Exchange HTTP virtual directories" negate="true"/>
          <criterion test_ref="wat-863" comment="allow directory browsing in the Exchange HTTP virtual directories" negate="true"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1354" class="compliance">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Exchange Server 2003</product>
      </affected>
      <dates>
        <submitted date="2004-12-29-12:00">
          <contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
        </submitted>
        <status_change date="2005-01-26-12:58">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Exchange Server 2003 should Display the routing groups in the Exchange System Manager</description>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wat-1030" comment="Display the routing groups in the Exchange System Manager" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1355" class="compliance">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Exchange Server 2003</product>
      </affected>
      <dates>
        <submitted date="2004-12-29-12:00">
          <contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
        </submitted>
        <status_change date="2005-01-26-12:58">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Exchange Server 2003 should Display the administrative groups in the Exchange System Manager</description>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wat-1040" comment="Display the administrative groups in the Exchange System Manager" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1356" class="compliance">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Exchange Server 2003</product>
      </affected>
      <dates>
        <submitted date="2004-12-29-12:00">
          <contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
        </submitted>
        <status_change date="2005-01-26-12:58">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Exchange Server 2003 should enable forms based authentication</description>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wat-1140" comment="enable forms based authentication" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1357" class="compliance">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Exchange Server 2003</product>
      </affected>
      <dates>
        <submitted date="2004-12-29-12:00">
          <contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
        </submitted>
        <status_change date="2005-01-26-12:58">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Exchange Server 2003 should only allow digest or integrated windows authentication (NTLM) to connect to the Public HTTP virtual directories</description>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wat-1150" comment="only allow integrated windows authentication (NTLM) to connect to the Public HTTP virtual directories" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1358" class="compliance">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Exchange Server 2003</product>
      </affected>
      <dates>
        <submitted date="2004-12-29-12:00">
          <contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
        </submitted>
        <status_change date="2005-01-26-12:58">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Exchange Server 2003 should disallow execute permissions to the Public HTTP virtual directory</description>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wat-1160" comment="allow script execute permissions to the Public HTTP virtual directory" negate="true"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1359" class="compliance">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Exchange Server 2003</product>
      </affected>
      <dates>
        <submitted date="2004-12-29-12:00">
          <contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
        </submitted>
        <status_change date="2005-01-26-12:58">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Exchange Server 2003 should disallow all access to Public HTTP virtual directories</description>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wat-1170" comment="allow read access to the Public HTTP virtual directories" negate="true"/>
          <criterion test_ref="wat-1171" comment="allow write access to the Public HTTP virtual directories" negate="true"/>
          <criterion test_ref="wat-1172" comment="allow script source access to the Public HTTP virtual directories" negate="true"/>
          <criterion test_ref="wat-1173" comment="allow directory browsing in the Public HTTP virtual directories" negate="true"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1360" class="compliance">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Exchange Server 2003</product>
      </affected>
      <dates>
        <submitted date="2004-12-29-12:00">
          <contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
        </submitted>
        <status_change date="2005-01-26-12:58">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Exchange Server 2003 should zero out deleted database pages</description>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wat-1185" comment="zero out deleted database pages" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1361" class="compliance">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Exchange Server 2003</product>
      </affected>
      <dates>
        <submitted date="2004-12-29-12:00">
          <contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
        </submitted>
        <status_change date="2005-01-26-12:58">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Exchange Server 2003 should disable all automated message generation</description>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wat-1190" comment="disable all automated message generation on the default domain" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1362" class="compliance">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Exchange Server 2003</product>
      </affected>
      <dates>
        <submitted date="2004-12-29-12:00">
          <contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
        </submitted>
        <status_change date="2005-01-26-12:58">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Exchange Server 2003 should only allow basic authentication with TSL encryption to connect to the IMAP4 service</description>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wat-1200" comment="allow basic authentication to connect to the IMAP4 service" negate="false"/>
          <criterion test_ref="wat-1201" comment="require TSL encryption to connect to the IMAP4 service" negate="false"/>
          <criterion test_ref="wat-1202" comment="allow simple authentication and security layer (SASL) to connect to the IMAP4 service" negate="true"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1363" class="compliance">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Exchange Server 2003</product>
      </affected>
      <dates>
        <submitted date="2004-12-29-12:00">
          <contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
        </submitted>
        <status_change date="2005-01-26-12:58">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Exchange Server 2003 should use SSL when downloading meeting requests</description>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wat-1240" comment="use SSL when downloading meeting requests using IMAP4" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1364" class="compliance">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Exchange Server 2003</product>
      </affected>
      <dates>
        <submitted date="2004-12-29-12:00">
          <contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
        </submitted>
        <status_change date="2005-01-26-12:58">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Exchange Server 2003 should use the default TCP ports for the the IMAP4 services</description>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wat-1250" comment="use TCP 143 for the IMAP4 service" negate="false"/>
          <criterion test_ref="wat-1251" comment="use TCP 993 for the secure IMAP4 service" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1365" class="compliance">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Exchange Server 2003</product>
      </affected>
      <dates>
        <submitted date="2004-12-29-12:00">
          <contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
        </submitted>
        <status_change date="2005-01-26-12:58">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Exchange Server 2003 should archive all messages received by mailboxes on this store</description>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wat-1280" comment="archive all messages received by mailboxes on this store" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1366" class="compliance">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Exchange Server 2003</product>
      </affected>
      <dates>
        <submitted date="2004-12-29-12:00">
          <contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
        </submitted>
        <status_change date="2005-01-26-12:58">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Exchange Server 2003 should have clients support S/MIME</description>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wat-1290" comment="have clients support S/MIME" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1367" class="compliance">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Exchange Server 2003</product>
      </affected>
      <dates>
        <submitted date="2004-12-29-12:00">
          <contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
        </submitted>
        <status_change date="2005-01-26-12:58">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Exchange Server 2003 should not delete mailboxes without waiting for the store to be backed up</description>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wat-1300" comment="delete mailboxes without waiting for the store to be backed up" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1368" class="compliance">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Exchange Server 2003</product>
      </affected>
      <dates>
        <submitted date="2004-12-29-12:00">
          <contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
        </submitted>
        <status_change date="2005-01-26-12:58">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Exchange Server 2003 should subscribe to a block list to block spam</description>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wat-1350" comment="subscribe to a block list to block spam" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1369" class="compliance">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Exchange Server 2003</product>
      </affected>
      <dates>
        <submitted date="2004-12-29-12:00">
          <contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
        </submitted>
        <status_change date="2005-01-26-12:58">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Exchange Server 2003 should limit the size of messages to and from the server to 30MB</description>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wat-1370" comment="limit the size of messages to the server to 30MB" negate="false"/>
          <criterion test_ref="wat-1371" comment="limit the size of messages from the server to 30MB" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1370" class="compliance">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Exchange Server 2003</product>
      </affected>
      <dates>
        <submitted date="2004-12-29-12:00">
          <contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
        </submitted>
        <status_change date="2005-01-26-12:58">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Exchange Server 2003 should limit the number of recipients in outbound messages to 5000</description>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wat-1380" comment="limit the number of recipients in outbound messages to 5000" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1371" class="compliance">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Exchange Server 2003</product>
      </affected>
      <dates>
        <submitted date="2004-12-29-12:00">
          <contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
        </submitted>
        <status_change date="2005-01-26-12:58">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Exchange Server 2003 should disable the filtering of recipients who are not in Active Directory</description>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wat-1390" comment="disable the filtering of recipients who are not in Active Directory" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1372" class="compliance">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Exchange Server 2003</product>
      </affected>
      <dates>
        <submitted date="2004-12-29-12:00">
          <contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
        </submitted>
        <status_change date="2005-01-26-12:00">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-12:00">ACCEPTED</status_change>
        <modified date="2005-06-08-12:00" comment="Previously, definition would return true if &quot;filter messages with blank sender&quot; was true. This is unrelated and hence was deleted.">
          <contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
        </modified>
        <status_change date="2005-06-08-03:17">INTERIM</status_change>
        <status_change date="2005-06-29-06:49">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Exchange Server 2003 should archive filtered messages</description>
      <reference source="MISC">1.2.9</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <notes>
        <note>Corresponds to item 1.2.9 in the Exchange 2003 Benchmark</note>
      </notes>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wat-1420" comment="archive filtered messages" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1373" class="compliance">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Exchange Server 2003</product>
      </affected>
      <dates>
        <submitted date="2004-12-29-12:00">
          <contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
        </submitted>
        <status_change date="2005-01-26-12:58">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Exchange Server 2003 should filter messages with a blank sender</description>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wat-1430" comment="filter messages with a blank sender" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1374" class="compliance">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Exchange Server 2003</product>
      </affected>
      <dates>
        <submitted date="2004-12-29-12:00">
          <contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
        </submitted>
        <status_change date="2005-01-26-12:58">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Exchange Server 2003 should drop connections if the address matches filters</description>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wat-1440" comment="do not drop connections if the address matches filters" negate="true"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1375" class="compliance">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Exchange Server 2003</product>
      </affected>
      <dates>
        <submitted date="2004-12-29-12:00">
          <contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
        </submitted>
        <status_change date="2005-01-26-12:58">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Exchange Server 2003 should accept messages without notifying the sender of filtering</description>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" negate="false"/>
        </software>
        <configuration operation="OR">
          <criterion test_ref="wat-1450" comment="accept messages without notifying the sender of filtering" negate="false"/>
          <criterion test_ref="wat-1440" comment="do not drop connections if the address matches filters" negate="true"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1376" class="compliance">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Exchange Server 2003</product>
      </affected>
      <dates>
        <submitted date="2004-12-29-12:00">
          <contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
        </submitted>
        <status_change date="2005-01-26-12:58">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Exchange Server 2003 should disable Outlook Mobile Access</description>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wat-1470" comment="disable Outlook Mobile Access" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1377" class="compliance">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Exchange Server 2003</product>
      </affected>
      <dates>
        <submitted date="2004-12-29-12:00">
          <contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
        </submitted>
        <status_change date="2005-01-26-12:58">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Exchange Server 2003 should disable ActiveSync</description>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wat-1480" comment="disable ActiveSync" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1378" class="compliance">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Exchange Server 2003</product>
      </affected>
      <dates>
        <submitted date="2004-12-29-12:00">
          <contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
        </submitted>
        <status_change date="2005-01-26-12:58">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Exchange Server 2003 should only allow basic authentication with TSL encryption to connect to the POP3 service</description>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wat-1530" comment="allow basic authentication to connect to the POP3 service" negate="false"/>
          <criterion test_ref="wat-1531" comment="require TSL encryption to connect to the POP3 service" negate="false"/>
          <criterion test_ref="wat-1532" comment="allow simple authentication and security layer (SASL) to connect to the POP3 service" negate="true"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1379" class="compliance">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Exchange Server 2003</product>
      </affected>
      <dates>
        <submitted date="2004-12-29-12:00">
          <contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
        </submitted>
        <status_change date="2005-01-26-12:58">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Exchange Server 2003 should use SSL when downloading meeting requests</description>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wat-1570" comment="use SSL when downloading meeting requests using POP3" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1380" class="compliance">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Exchange Server 2003</product>
      </affected>
      <dates>
        <submitted date="2004-12-29-12:00">
          <contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
        </submitted>
        <status_change date="2005-01-26-12:58">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Exchange Server 2003 should use TCP ports 143 and 995 for the POP3 service</description>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wat-1580" comment="use TCP port 110 for the POP3 service" negate="false"/>
          <criterion test_ref="wat-1581" comment="use TCP port 995 for the secure POP3 service" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1381" class="compliance">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Exchange Server 2003</product>
      </affected>
      <dates>
        <submitted date="2004-12-29-12:00">
          <contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
        </submitted>
        <status_change date="2005-01-26-12:58">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Exchange Server 2003 should have mailbox store clients support S/MIME signatures</description>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wat-1590" comment="don't have mailbox store clients support S/MIME signatures" negate="true"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1382" class="compliance">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Exchange Server 2003</product>
      </affected>
      <dates>
        <submitted date="2004-12-29-12:00">
          <contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
        </submitted>
        <status_change date="2005-01-26-12:58">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Exchange Server 2003 should enable subject logging and display</description>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wat-1670" comment="enable subject logging and display" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1383" class="compliance">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Exchange Server 2003</product>
      </affected>
      <dates>
        <submitted date="2004-12-29-12:00">
          <contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
        </submitted>
        <status_change date="2005-01-26-12:58">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Exchange Server 2003 should enable message tracking</description>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wat-1680" comment="enable message tracking" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1384" class="compliance">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Exchange Server 2003</product>
      </affected>
      <dates>
        <submitted date="2004-12-29-12:00">
          <contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
        </submitted>
        <status_change date="2005-01-26-12:58">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Exchange Server 2003 should disable automatic log removal</description>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wat-1690" comment="disable automatic log removal" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1385" class="compliance">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Exchange Server 2003</product>
      </affected>
      <dates>
        <submitted date="2004-12-29-12:00">
          <contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
        </submitted>
        <status_change date="2005-01-26-12:58">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Exchange Server 2003 should not disable all monitoring on this server</description>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wat-1720" comment="disable all monitoring on this server" negate="true"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1386" class="compliance">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Exchange Server 2003</product>
      </affected>
      <dates>
        <submitted date="2004-12-29-12:00">
          <contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
        </submitted>
        <status_change date="2005-01-26-12:58">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Exchange Server 2003 should change state to critical when any service stops</description>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wat-1737" comment="change state to critical when any basic Exchange service stops" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1387" class="compliance">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Exchange Server 2003</product>
      </affected>
      <dates>
        <submitted date="2004-12-29-12:00">
          <contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
        </submitted>
        <status_change date="2005-01-26-12:58">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Exchange Server 2003 should limit any connector scope to the routing group</description>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" negate="false"/>
        </software>
        <configuration operation="OR">
          <criterion test_ref="wat-1770" comment="limit SMTP connector scope to the routing group" negate="false"/>
          <criterion test_ref="wat-1771" comment="SMTP connector object exists" negate="true"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1388" class="compliance">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Exchange Server 2003</product>
      </affected>
      <dates>
        <submitted date="2004-12-29-12:00">
          <contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
        </submitted>
        <status_change date="2005-01-26-12:58">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Exchange Server 2003 should disallow unauthenticated entities to relay through this SMTP connector</description>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" negate="false"/>
        </software>
        <configuration operation="OR">
          <criterion test_ref="wat-1780" comment="allow unauthenticated entities to relay through this SMTP connector" negate="true"/>
          <criterion test_ref="wat-1771" comment="SMTP connector object exists" negate="true"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1389" class="compliance">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Exchange Server 2003</product>
      </affected>
      <dates>
        <submitted date="2004-12-29-12:00">
          <contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
        </submitted>
        <status_change date="2005-01-26-12:58">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Exchange Server 2003 should force outbound connections to use basic authentication with TLS encryption</description>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" negate="false"/>
        </software>
        <configuration operation="OR">
          <criterion test_ref="wat-1790" comment="force outbound connections to use only basic authentication with TLS encryption" negate="false"/>
          <criterion test_ref="wat-1771" comment="SMTP connector object exists" negate="true"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1390" class="compliance">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Exchange Server 2003</product>
      </affected>
      <dates>
        <submitted date="2004-12-29-12:00">
          <contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
        </submitted>
        <status_change date="2005-01-26-12:58">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Exchange Server 2003 should have any SMTP connectors use a smart host</description>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" negate="false"/>
        </software>
        <configuration operation="OR">
          <criterion test_ref="wat-1810" comment="have any SMTP connectors use a smart host" negate="false"/>
          <criterion test_ref="wat-1771" comment="SMTP connector object exists" negate="true"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1391" class="compliance">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Exchange Server 2003</product>
      </affected>
      <dates>
        <submitted date="2004-12-29-12:00">
          <contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
        </submitted>
        <status_change date="2005-01-26-12:58">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Exchange Server 2003 should only allow basic authentication with TSL encryption to connect to the SMTP server</description>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wat-1820" comment="only allow basic authentication to connect to the SMTP server" negate="false"/>
          <criterion test_ref="wat-1821" comment="require TSL encryption to connect to the SMTP server" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1392" class="compliance">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Exchange Server 2003</product>
      </affected>
      <dates>
        <submitted date="2004-12-29-12:00">
          <contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
        </submitted>
        <status_change date="2005-01-26-12:58">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Exchange Server 2003 should not resolve anonymous email</description>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wat-1830" comment="resolve anonymous email" negate="true"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1393" class="compliance">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Exchange Server 2003</product>
      </affected>
      <dates>
        <submitted date="2004-12-29-12:00">
          <contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
        </submitted>
        <status_change date="2005-01-26-12:58">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Exchange Server 2003 should only allow explicitly listed hosts to relay messages through this sever</description>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wat-1875" comment="only allow explicitly listed hosts to relay messages through this sever" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1394" class="compliance">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Exchange Server 2003</product>
      </affected>
      <dates>
        <submitted date="2004-12-29-12:00">
          <contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
        </submitted>
        <status_change date="2005-01-26-12:58">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Exchange Server 2003 should use a smart host to relay SMTP messages</description>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wat-1880" comment="use a smart host to relay SMTP messages" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1395" class="compliance">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Exchange Server 2003</product>
      </affected>
      <dates>
        <submitted date="2004-12-29-12:00">
          <contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
        </submitted>
        <status_change date="2005-01-26-12:58">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Exchange Server 2003 should not perform reverse DNS lookups on incoming messages</description>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wat-1890" comment="perform reverse DNS lookups on incoming messages" negate="true"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1396" class="compliance">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Exchange Server 2003</product>
      </affected>
      <dates>
        <submitted date="2004-12-29-12:00">
          <contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
        </submitted>
        <status_change date="2005-01-26-12:58">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Exchange Server 2003 should use port 25 for outbound SMTP connections</description>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wat-1900" comment="use port 25 for outbound SMTP connections" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1397" class="compliance">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Exchange Server 2003</product>
      </affected>
      <dates>
        <submitted date="2004-12-29-12:00">
          <contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
        </submitted>
        <status_change date="2005-01-26-12:58">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Exchange Server 2003 should use only basic authentication with TLS encryption for outbound SMTP connections</description>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wat-1910" comment="use only basic authentication with TLS encryption for outbound SMTP connections" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1398" class="compliance">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Exchange Server 2003</product>
      </affected>
      <dates>
        <submitted date="2004-12-29-12:00">
          <contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
        </submitted>
        <status_change date="2005-01-26-12:58">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Exchange Server 2003 should enable logging of connections between SMTP hosts</description>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wat-1920" comment="enable logging of connections between SMTP hosts" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1399" class="compliance">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Exchange Server 2003</product>
      </affected>
      <dates>
        <submitted date="2004-12-29-12:00">
          <contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
        </submitted>
        <status_change date="2005-01-26-12:58">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Exchange Server 2003 should use port 25 for inbound SMTP connections</description>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wat-1930" comment="use port 25 for inbound SMTP connections" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1400" class="compliance">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Exchange Server 2003</product>
      </affected>
      <dates>
        <submitted date="2004-12-29-12:00">
          <contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
        </submitted>
        <status_change date="2005-01-26-12:58">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Exchange Server 2003 should apply sender, recipient, and connection filters</description>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wat-1940" comment="apply recipient and connection filters" negate="false"/>
          <criterion test_ref="wat-1941" comment="apply sender filters" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1401" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Office</product>
      </affected>
      <dates>
        <submitted date="2006-03-15-10:53">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-03-15-07:17">DRAFT</status_change>
        <status_change date="2006-04-06-06:30">INTERIM</status_change>
        <status_change date="2006-05-03-10:06">ACCEPTED</status_change>
      </dates>
      <description>Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-complicit attackers to execute arbitrary code via an Excel file with a malformed graphic, which leads to memory corruption.</description>
      <reference source="CVE">CVE-2006-0030</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-137" comment="Excel 2000 is installed" negate="false"/>
          <criterion test_ref="wft-769" comment="the version of excel.exe is less than 9.0.0.8938" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1402" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Winamp</product>
      </affected>
      <dates>
        <submitted date="2006-02-01-08:59">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-03-09-12:19">DRAFT</status_change>
        <status_change date="2006-04-06-06:30">INTERIM</status_change>
        <status_change date="2006-05-03-10:06">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in Nullsoft Winamp 5.12 allows remote attackers to execute arbitrary code via a playlist (pls) file with a long file name (File1 field).</description>
      <reference source="CVE">CVE-2006-0476</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wft-740" comment="the version of winamp is less than or equal 5.12" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1405" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Print Spooler Service</product>
      </affected>
      <dates>
        <submitted date="2005-09-19-04:00">
          <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
        </submitted>
        <status_change date="2005-09-21-01:33">DRAFT</status_change>
        <status_change date="2005-10-12-05:49">INTERIM</status_change>
        <status_change date="2005-11-16-08:02">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the Print Spooler service (Spoolsv.exe) for Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code via a malicious message.</description>
      <reference source="CVE">CVE-2005-1984</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wrt-410" comment="Win2K/XP/2003 service pack 1 (or later) is installed" negate="true"/>
          <criterion test_ref="wft-632" comment="the version of Spoolsv.exe is less than 5.2.3790.346" negate="false"/>
          <criterion test_ref="wrt-370" comment="the patch KB896423 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1406" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2005-10-12-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-10-19-05:46">DRAFT</status_change>
        <status_change date="2005-11-16-08:02">INTERIM</status_change>
        <status_change date="2005-12-01-06:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in Collaboration Data Objects (CDO), as used in Microsoft Windows and Microsoft Exchange Server, allows remote attackers to execute arbitrary code when CDOSYS or CDOEX processes an e-mail message with a large header name, as demonstrated using the "Content-Type" string.</description>
      <reference source="CVE">CVE-2005-1987</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1058" comment="Windows XP 32-bit edition is installed" negate="false"/>
          <criterion test_ref="wrt-4" comment="Win2K/XP/2003 service pack 1 is installed" negate="false"/>
          <criterion test_ref="wft-678" comment="cdosys.dll is less than 6.1.1002.0" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1407" class="vulnerability">
      <affected family="hp-ux">
        <hpux:platform>HP-UX 11</hpux:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2006-02-01-11:45">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-03-09-12:19">DRAFT</status_change>
        <status_change date="2006-04-06-06:30">INTERIM</status_change>
        <status_change date="2006-05-03-10:06">ACCEPTED</status_change>
      </dates>
      <description>Unknown vulnerability in HP-UX B.11.00, B.11.04, B.11.11, B.11.22, and B.11.23, when running TCP/IP on IPv4, allows remote attackers to cause a denial of service via certain packets, related to the PMTU, a different vulnerability than CVE-2004-1060.</description>
      <reference source="CVE">CVE-2005-1192</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-688" comment="700 Series OS Release 11.22" negate="false"/>
          <criterion test_ref="hst-58" comment="IPSec.IPSEC2-KRN is installed" negate="false"/>
          <criterion test_ref="cmp-761" comment="IPSec.IPSEC2-KRN version is under A.2.00.01 or TOUR version is under 3.0 or patch PHNE_32606 is not installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1409" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Solaris Management Console</product>
      </affected>
      <dates>
        <submitted date="2006-01-11-12:56">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-01-12-09:18">DRAFT</status_change>
        <status_change date="2006-02-01-09:08">INTERIM</status_change>
        <status_change date="2006-02-22-08:27">ACCEPTED</status_change>
      </dates>
      <description>The (1) slsmgr and (2) slsadmin programs in Sun Solaris PC NetLink 2.0 create temporary files insecurely, which allows local users to gain privileges.</description>
      <reference source="CVE">CVE-2005-4552</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" negate="false"/>
          <criterion test_ref="uut-10003" comment="sparc architecture" negate="false"/>
          <criterion test_ref="sat-51" comment="the SUNWlzas package (for slsadmin) is installed" negate="false"/>
          <criterion test_ref="spt-154" comment="Patch 121332-01 or later installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1411" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Office</product>
      </affected>
      <dates>
        <submitted date="2006-03-15-10:53">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-03-15-07:17">DRAFT</status_change>
        <status_change date="2006-04-06-06:30">INTERIM</status_change>
        <status_change date="2006-05-03-10:06">ACCEPTED</status_change>
      </dates>
      <description>Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-complicit attackers to execute arbitrary code via a BIFF parsing format file containing malformed BOOLERR records that lead to memory corruption, probably involving invalid pointers.</description>
      <reference source="CVE">CVE-2006-0028</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-649" comment="Excel 2002 is installed" negate="false"/>
          <criterion test_ref="wft-771" comment="the version of excel.exe is less than 10.0.6789.0" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1412" class="vulnerability">
      <affected family="hp-ux">
        <hpux:platform>HP-UX 11</hpux:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2006-03-29-06:11">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-04-06-06:30">DRAFT</status_change>
        <status_change date="2006-05-03-10:06">INTERIM</status_change>
      </dates>
      <description>'An undisclosed vulnerability has been identified in /sbin/passwd which could be exploited to create a Denial of Service condition..'</description>
      <reference source="MISC">http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00619550</reference>
      <status>INTERIM</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-619" comment="700 Series or 800 Series OS Release 11.00" negate="false"/>
          <criterion test_ref="hst-81" comment="OS-Core.UX-CORE is installed" negate="false"/>
          <criterion test_ref="hpt-57" comment="Patch PHCO_33219 or subsequent is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1413" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>TIP</product>
      </affected>
      <dates>
        <submitted date="2005-10-12-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-10-19-05:46">DRAFT</status_change>
        <status_change date="2005-11-16-08:02">INTERIM</status_change>
        <status_change date="2005-12-01-06:00">ACCEPTED</status_change>
      </dates>
      <description>Distributed Transaction Controller in Microsoft Windows allows remote servers to cause a denial of service (MSDTC service hang) via a crafted Transaction Internet Protocol (TIP) message that causes DTC to repeatedly connect to a target IP and port number after an error occurs, aka the "Distributed TIP Vulnerability."</description>
      <reference source="CVE">CVE-2005-1980</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wrt-10026" comment="Win2K/XP/2003 is patched" negate="true"/>
          <criterion test_ref="cmp-609" comment="Either ole32.dll or rpcss.dll has a version less than 5.2.3790.374" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1415" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 4</redhat:platform>
        <product>mozilla</product>
      </affected>
      <dates>
        <submitted date="2005-08-15-04:00">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2005-08-19-10:05">DRAFT</status_change>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Firefox before 1.0.5 and Mozilla before 1.7.9 allows a child frame to call top.focus and other methods in a parent frame, even when the parent is in a different domain, which violates the same origin policy and allows remote attackers to steal sensitive information such as cookies and passwords from web sites whose child frames do not verify that they are in the same domain as their parents.</description>
      <reference source="CVE">CVE-2005-2266</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-1" comment="Red Hat Enterprise 4 is installed" negate="false"/>
          <criterion test_ref="rvt-32" comment="mozilla RPM is earlier than 37:1.7.10-1.4.1" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="upt-859" comment="/usr/bin/mozilla is executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1416" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2005-10-12-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-10-19-05:46">DRAFT</status_change>
        <status_change date="2005-11-16-08:02">INTERIM</status_change>
        <status_change date="2005-12-01-06:00">ACCEPTED</status_change>
      </dates>
      <description>The FTP client in Windows XP SP1 and Server 2003, and Internet Explorer 6 SP1 on Windows 2000 SP4, when "Enable Folder View for FTP Sites" is enabled and the user manually initiates a file transfer, allows user-complicit, remote FTP servers to overwrite files in arbitrary locations via crafted filenames.</description>
      <reference source="CVE">CVE-2005-2126</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-2" comment="Windows XP is installed" negate="false"/>
          <criterion test_ref="wrt-4" comment="Win2K/XP/2003 service pack 1 is installed" negate="false"/>
          <criterion test_ref="wft-690" comment="msieftp.dll is less than 6.0.2800.1724" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1417" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>Microsoft Word for Windows 6.0 Converter</product>
      </affected>
      <dates>
        <submitted date="2005-01-05-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2005-01-12-12:41">DRAFT</status_change>
        <status_change date="2005-02-02-12:00">INTERIM</status_change>
        <status_change date="2005-02-23-09:25">ACCEPTED</status_change>
        <modified date="2005-12-20-07:05" comment="Edited criteria. 1) dropped explicit check for Hotfix kb885836, 2) check version of wordpad.exe rather than mswrd wpc files.">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </modified>
        <status_change date="2006-01-04-08:04">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Word for Windows 6.0 Converter does not properly validate certain data lengths, which allows remote attackers to execute arbitrary code via a .wri, .rtf, and .doc file sent by email or malicious web site, aka "Table Conversion Vulnerability," a different vulnerability than CVE-2004-0901.</description>
      <reference source="CVE">CVE-2004-0571</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-45" comment="Windows NT Server 4.0, Terminal Server Edition is installed" negate="false"/>
          <criterion test_ref="wft-711" comment="the version of wordpad.exe is less than 4.0.1381.33598" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1420" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2005-10-12-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-10-19-05:46">DRAFT</status_change>
        <status_change date="2005-11-16-08:02">INTERIM</status_change>
        <status_change date="2005-12-01-06:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in Collaboration Data Objects (CDO), as used in Microsoft Windows and Microsoft Exchange Server, allows remote attackers to execute arbitrary code when CDOSYS or CDOEX processes an e-mail message with a large header name, as demonstrated using the "Content-Type" string.</description>
      <reference source="CVE">CVE-2005-1987</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
          <criterion test_ref="wrt-432" comment="Win2K/XP/2003 service pack 4 is installed" negate="false"/>
          <criterion test_ref="wft-677" comment="cdosys.dll is less than 6.1.3940.42" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1424" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>DirectX</product>
      </affected>
      <dates>
        <submitted date="2005-10-12-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-10-19-05:46">DRAFT</status_change>
        <status_change date="2005-11-16-08:02">INTERIM</status_change>
        <status_change date="2005-12-01-06:00">ACCEPTED</status_change>
      </dates>
      <description>QUARTZ.DLL in Microsoft Windows Media Player 9 allows remote attackers to write a null byte to arbitrary memory via an AVI file with a crafted strn element with a modified length value.</description>
      <reference source="CVE">CVE-2005-2128</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-603" comment="DirectX packaged with Windows Server 2003 has DirectShow Vulnerability" negate="false"/>
          <criterion test_ref="cmp-598" comment="Standalone DirectX 8 has DirectShow Vulnerability" negate="false"/>
          <criterion test_ref="cmp-599" comment="Standalone DirectX 9 has DirectShow Vulnerability" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1425" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2006-02-17-07:36">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-02-22-08:27">DRAFT</status_change>
        <status_change date="2006-03-09-12:19">INTERIM</status_change>
        <status_change date="2006-04-06-06:30">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Windows XP SP1 and SP2, and Server 2003 up to SP1, allows remote attackers to cause a denial of service (hang) via certain malformed IGMP packets, aka the "IGMP v3 DoS Vulnerability."</description>
      <reference source="CVE">CVE-2006-0021</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-2" comment="Windows XP is installed" negate="false"/>
          <criterion test_ref="wrt-250" comment="Win2K/XP/2003 service pack 2 is installed" negate="false"/>
          <criterion test_ref="wft-757" comment="the version of Tcpip.sys is less than 5.1.2600.2827 (XP,SP2)" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1426" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Internet Explorer</product>
      </affected>
      <dates>
        <submitted date="2005-12-13-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-12-16-01:03">DRAFT</status_change>
        <status_change date="2006-01-04-08:04">INTERIM</status_change>
        <status_change date="2006-01-25-07:30">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not intended for use within Internet Explorer, aka a variant of the "COM Object Instantiation Memory Corruption Vulnerability," a different vulnerability than CVE-2005-2127.</description>
      <reference source="CVE">CVE-2005-2831</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-35" comment="Windows XP 32 bit Service Pack 2" negate="false"/>
          <criterion test_ref="wrt-10027" comment="Internet Explorer 6 is installed" negate="false"/>
          <criterion test_ref="wft-706" comment="the version of mshtml.dll is less than 6.0.2900.2802" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1427" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>IIS 5.1</product>
      </affected>
      <dates>
        <submitted date="2004-10-13-11:09">
          <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
        </submitted>
        <status_change date="2004-10-13-01:15">DRAFT</status_change>
        <status_change date="2004-10-27-12:00">INTERIM</status_change>
        <status_change date="2004-11-17-10:00">ACCEPTED</status_change>
      </dates>
      <description>The WebDAV Message Handler for Internet Information Services (IIS) 5.0, 5.1, and 6.0 allows remote attackers to cause a denial of service (memory and CPU exhaustion, application crash) via a PROPFIND request with an XML message containing XML elements with a large number of attributes.</description>
      <reference source="CVE">CVE-2003-0718</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-2" comment="Windows XP is installed" negate="false"/>
          <criterion test_ref="cmp-1110" comment="a vulnerable version of httpext.dll exists" negate="false"/>
          <criterion test_ref="wrt-549" comment="the patch KB824151 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1429" class="vulnerability">
      <affected family="hp-ux">
        <hpux:platform>HP-UX 11</hpux:platform>
        <product>envd</product>
      </affected>
      <dates>
        <submitted date="2005-11-30-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-12-20-11:03">DRAFT</status_change>
        <status_change date="2006-01-04-08:04">INTERIM</status_change>
        <status_change date="2006-01-25-07:30">ACCEPTED</status_change>
      </dates>
      <description>envd daemon in HP-UX B.11.00 through B.11.11 allows local users to obtain privileges via unknown attack vectors.</description>
      <reference source="CVE">CVE-2005-3564</reference>
      <status>ACCEPTED</status>
      <version>5</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-619" comment="700 Series or 800 Series OS Release 11.00" negate="false"/>
          <criterion test_ref="cmp-679" comment="OS-Core.CORE-ENG-A-MAN or OS-Core.UX-CORE (B.11.00) is installed" negate="false"/>
          <criterion test_ref="hpt-11" comment="Patch PHCO_33989 or later is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1431" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2006-01-07-07:15">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-01-12-09:25">DRAFT</status_change>
        <status_change date="2006-02-01-09:08">INTERIM</status_change>
        <status_change date="2006-02-22-08:27">ACCEPTED</status_change>
      </dates>
      <description>The Windows Graphical Device Interface library (GDI32.DLL) in Microsoft Windows allows remote attackers to execute arbitrary code via a Windows Metafile (WMF) format image with a crafted SETABORTPROC GDI Escape function call, related to the Windows Picture and Fax Viewer (SHIMGVW.DLL), a different vulnerability than CVE-2005-2123 and CVE-2005-2124, and as originally discovered in the wild on unionseek.com.</description>
      <reference source="CVE">CVE-2005-4560</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-212" comment="Windows 2000 Service Pack 4 (or later) is installed" negate="false"/>
          <criterion test_ref="wft-717" comment="the version of Gdi32.dll is less than 5.0.2195.7073" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1433" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2005-12-28-10:07">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-12-29-11:27">DRAFT</status_change>
        <modified date="2006-01-07-07:17" comment="New definition.">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </modified>
        <status_change date="2006-01-25-07:30">INTERIM</status_change>
        <status_change date="2006-02-22-08:27">ACCEPTED</status_change>
      </dates>
      <description>The Windows Graphical Device Interface library (GDI32.DLL) in Microsoft Windows allows remote attackers to execute arbitrary code via a Windows Metafile (WMF) format image with a crafted SETABORTPROC GDI Escape function call, related to the Windows Picture and Fax Viewer (SHIMGVW.DLL), a different vulnerability than CVE-2005-2123 and CVE-2005-2124, and as originally discovered in the wild on unionseek.com.</description>
      <reference source="CVE">CVE-2005-4560</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-2" comment="Windows XP is installed" negate="false"/>
          <criterion test_ref="wrt-250" comment="Win2K/XP/2003 service pack 2 is installed" negate="false"/>
          <criterion test_ref="wft-720" comment="the version of Gdi32.dll is less than 5.1.2600.2818" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1434" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>DirectX</product>
      </affected>
      <dates>
        <submitted date="2005-10-12-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-10-19-05:46">DRAFT</status_change>
        <status_change date="2005-11-16-08:02">INTERIM</status_change>
        <status_change date="2005-12-01-06:00">ACCEPTED</status_change>
      </dates>
      <description>QUARTZ.DLL in Microsoft Windows Media Player 9 allows remote attackers to write a null byte to arbitrary memory via an AVI file with a crafted strn element with a modified length value.</description>
      <reference source="CVE">CVE-2005-2128</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-601" comment="DirectX packaged with Windows XP,SP1 has DirectShow Vulnerability" negate="false"/>
          <criterion test_ref="cmp-598" comment="Standalone DirectX 8 has DirectShow Vulnerability" negate="false"/>
          <criterion test_ref="cmp-599" comment="Standalone DirectX 9 has DirectShow Vulnerability" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1435" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Internet Explorer</product>
      </affected>
      <dates>
        <submitted date="2005-12-13-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-12-16-01:03">DRAFT</status_change>
        <status_change date="2006-01-04-08:04">INTERIM</status_change>
        <status_change date="2006-01-25-07:30">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Internet Explorer 5.01, 5.5, and 6, when using an HTTPS proxy server that requires Basic Authentication, sends URLs in cleartext, which allows remote attackers to obtain sensitive information, aka "HTTPS Proxy Vulnerability."</description>
      <reference source="CVE">CVE-2005-2830</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-35" comment="Windows XP 32 bit Service Pack 2" negate="false"/>
          <criterion test_ref="wrt-10027" comment="Internet Explorer 6 is installed" negate="false"/>
          <criterion test_ref="wft-706" comment="the version of mshtml.dll is less than 6.0.2900.2802" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1436" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>CDE</product>
      </affected>
      <dates>
        <submitted date="2004-10-12-12:37">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <modified date="2004-10-12-12:47" comment="Added patch 107180-31 test for Solaris 7.  Changed vulnerable software test logic a little">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </modified>
        <status_change date="2004-10-13-01:15">DRAFT</status_change>
        <status_change date="2004-10-27-12:00">INTERIM</status_change>
        <status_change date="2004-11-17-10:00">ACCEPTED</status_change>
      </dates>
      <description>Double-free vulnerability in dtlogin in CDE on Solaris, HP-UX, and other operating systems allows remote attackers to execute arbitrary code via a crafted XDMCP packet.</description>
      <reference source="CVE">CVE-2004-0368</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uft-23" comment="File /usr/dt/bin/dtlogin exists" negate="false"/>
          <criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" negate="false"/>
          <criterion test_ref="spt-231" comment="Patch 108919-21 or later installed" negate="false"/>
          <criterion test_ref="spt-232" comment="Patch 112807-09 or later installed" negate="false"/>
          <criterion test_ref="spt-249" comment="Patch 107180-31 or later installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-9" comment="dtlogin running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1439" class="vulnerability">
      <affected family="hp-ux">
        <hpux:platform>HP-UX 11</hpux:platform>
        <product>ftpd</product>
      </affected>
      <dates>
        <submitted date="2005-11-30-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-12-20-11:03">DRAFT</status_change>
        <status_change date="2006-01-04-08:04">INTERIM</status_change>
        <status_change date="2006-01-25-07:30">ACCEPTED</status_change>
      </dates>
      <description>The FTP server in HP-UX 10.20, B.11.00, and B.11.11, allows remote attackers to list arbitrary directories as root by running the LIST command before logging in.</description>
      <reference source="CVE">CVE-2005-3296</reference>
      <status>ACCEPTED</status>
      <version>5</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-618" comment="700 Series or 800 Series OS Release 11.11" negate="false"/>
          <criterion test_ref="cmp-667" comment="InternetSrvcs.INETSVCS-RUN or InternetSrvcs.INET-ENG-A-MAN (B.11.11) is installed" negate="false"/>
          <criterion test_ref="hpt-6" comment="Patch PHNE_23950 or later is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1443" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>mozilla</product>
      </affected>
      <dates>
        <submitted date="2005-11-11-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-12-12-10:00">DRAFT</status_change>
        <status_change date="2005-12-28-04:28">INTERIM</status_change>
        <status_change date="2006-01-12-08:59">ACCEPTED</status_change>
      </dates>
      <description>Firefox before 1.0.7 and Mozilla before Suite 1.7.12 allows remote attackers to execute Javascript with chrome privileges via an about: page such as about:mozilla.</description>
      <reference source="CVE">CVE-2005-2706</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-621" comment="Mozilla Suite version 1.7.10 or earlier is installed" negate="false"/>
          <criterion test_ref="cmp-631" comment="Mozilla Firefox version 1.0.6 or earlier is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1445" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <solaris:platform>Sun Solaris 10</solaris:platform>
        <product>Solaris Management Console</product>
      </affected>
      <dates>
        <submitted date="2006-01-11-12:56">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-01-12-09:18">DRAFT</status_change>
        <status_change date="2006-02-01-09:08">INTERIM</status_change>
        <status_change date="2006-02-22-08:27">ACCEPTED</status_change>
      </dates>
      <description>The default configuration of the web server for the Solaris Management Console (SMC) in Solaris 8, 9, and 10 enables the HTTP TRACE method, which could allow remote attackers to obtain sensitive information such as cookies and authentication data from HTTP headers.</description>
      <reference source="CVE">CVE-2005-3398</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-695" comment="Solaris 8 (SPARC) meets Sun Alert ID 102016 criteria." negate="false"/>
          <criterion test_ref="cmp-696" comment="Solaris 8 (x86) meets Sun Alert ID 102016 criteria." negate="false"/>
          <criterion test_ref="cmp-697" comment="Solaris 9 (SPARC) meets Sun Alert ID 102016 criteria." negate="false"/>
          <criterion test_ref="cmp-698" comment="Solaris 9 (x86) meets Sun Alert ID 102016 criteria." negate="false"/>
          <criterion test_ref="cmp-699" comment="Solaris 10 (SPARC) meets Sun Alert ID 102016 criteria." negate="false"/>
          <criterion test_ref="cmp-700" comment="Solaris 10 (x86) meets Sun Alert ID 102016 criteria." negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1446" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Internet Explorer</product>
      </affected>
      <dates>
        <submitted date="2006-04-12-12:55">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-04-12-05:16">DRAFT</status_change>
        <status_change date="2006-05-03-10:06">INTERIM</status_change>
      </dates>
      <description>Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via by instantiating the (1) Mdt2gddr.dll, (2) Mdt2dd.dll, and (3) Mdt2gddo.dll COM objects as ActiveX controls, which leads to memory corruption.</description>
      <reference source="CVE">CVE-2006-1186</reference>
      <status>INTERIM</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-212" comment="Windows 2000 Service Pack 4 (or later) is installed" negate="false"/>
          <criterion test_ref="wrt-651" comment="Internet Explorer 5.01 (any patch level) is installed" negate="false"/>
          <criterion test_ref="wft-775" comment="the version of mshtml.dll is less than 5.0.3839.2200" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1448" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2006-04-12-12:55">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-04-12-05:16">DRAFT</status_change>
        <status_change date="2006-05-03-10:06">INTERIM</status_change>
      </dates>
      <description>Unspecified vulnerability in Windows Explorer in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote attackers to execute arbitrary code via attack vectors involving COM objects and "crafted files and directories," aka the "Windows Shell Vulnerability."</description>
      <reference source="CVE">CVE-2006-0012</reference>
      <status>INTERIM</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-2" comment="Windows XP is installed" negate="false"/>
          <criterion test_ref="wrt-250" comment="Win2K/XP/2003 service pack 2 is installed" negate="false"/>
          <criterion test_ref="wft-790" comment="the version of shell32.dll is less than 6.0.2900.2869" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1451" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Internet Explorer</product>
      </affected>
      <dates>
        <submitted date="2006-04-12-12:55">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-04-12-05:16">DRAFT</status_change>
        <status_change date="2006-05-03-10:06">INTERIM</status_change>
      </dates>
      <description>Buffer overflow in mshtml.dll in Microsoft Internet Explorer 6.0.2900.2180, and probably other versions, allows remote attackers to execute arbitrary code via an HTML tag with a large number of script action handlers such as onload and onmouseover, as demonstrated using onclick, aka the "Multiple Event Handler Memory Corruption Vulnerability."</description>
      <reference source="CVE">CVE-2006-1245</reference>
      <status>INTERIM</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-212" comment="Windows 2000 Service Pack 4 (or later) is installed" negate="false"/>
          <criterion test_ref="wrt-651" comment="Internet Explorer 5.01 (any patch level) is installed" negate="false"/>
          <criterion test_ref="wft-775" comment="the version of mshtml.dll is less than 5.0.3839.2200" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1452" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>MSDTC</product>
      </affected>
      <dates>
        <submitted date="2005-10-12-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-10-19-05:46">DRAFT</status_change>
        <status_change date="2005-11-16-08:02">INTERIM</status_change>
        <status_change date="2005-12-01-06:00">ACCEPTED</status_change>
      </dates>
      <description>The MIDL_user_allocate function in the Microsoft Distributed Transaction Coordinator (MSDTC) proxy (MSDTCPRX.DLL) allocates a 4K page of memory regardless of the required size, which allows attackers to overwrite arbitrary memory locations using an incorrect size value that is provided to the NdrAllocate function, which writes management data to memory outside of the allocated buffer.</description>
      <reference source="CVE">CVE-2005-2119</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wrt-10026" comment="Win2K/XP/2003 is patched" negate="true"/>
          <criterion test_ref="cmp-609" comment="Either ole32.dll or rpcss.dll has a version less than 5.2.3790.374" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1453" class="vulnerability">
      <affected family="hp-ux">
        <hpux:platform>HP-UX 11</hpux:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2006-01-30-07:20">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-02-01-09:08">DRAFT</status_change>
        <status_change date="2006-02-22-08:27">INTERIM</status_change>
        <status_change date="2006-03-09-12:19">ACCEPTED</status_change>
      </dates>
      <description>Unspecified vulnerability in HP HP-UX B.11.00, B.11.04, and B.11.11 allows local users to gain privileges via unknown attack vectors.</description>
      <reference source="CVE">CVE-2006-0436</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-618" comment="700 Series or 800 Series OS Release 11.11" negate="false"/>
          <criterion test_ref="hpt-38" comment="Patch PHCO_30402 or later is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1454" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Internet Explorer</product>
      </affected>
      <dates>
        <submitted date="2005-10-12-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-10-19-05:46">DRAFT</status_change>
        <status_change date="2005-11-16-08:02">INTERIM</status_change>
        <status_change date="2005-12-01-06:00">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not intended for use within Internet Explorer, as originally demonstrated using the (1) DDS Library Shape Control (Msdds.dll) COM object, and other objects including (2) Blnmgrps.dll, (3) Ciodm.dll, (4) Comsvcs.dll, (5) Danim.dll, (6) Htmlmarq.ocx, (7) Mdt2dd.dll (as demonstrated using a heap corruption attack with uninitialized memory), (8) Mdt2qd.dll, (9) Mpg4ds32.ax, (10) Msadds32.ax, (11) Msb1esen.dll, (12) Msb1fren.dll, (13) Msb1geen.dll, (14) Msdtctm.dll, (15) Mshtml.dll, (16) Msoeacct.dll, (17) Msosvfbr.dll, (18) Mswcrun.dll, (19) Netshell.dll, (20) Ole2disp.dll, (21) Outllib.dll, (22) Psisdecd.dll, (23) Qdvd.dll, (24) Repodbc.dll, (25) Shdocvw.dll, (26) Shell32.dll, (27) Soa.dll, (28) Srchui.dll, (29) Stobject.dll, (30) Vdt70.dll, (31) Vmhelper.dll, and (32) Wbemads.dll, aka a variant of the "COM Object Instantiation Memory Corruption vulnerability."</description>
      <reference source="CVE">CVE-2005-2127</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wrt-10026" comment="Win2K/XP/2003 is patched" negate="true"/>
          <criterion test_ref="wft-666" comment="mshtml.dll is less than 6.0.3790.418" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1455" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>Certificate Validation</product>
      </affected>
      <dates>
        <submitted date="2004-07-12-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <modified date="2004-07-13-12:00" comment="Added superceding patch info.">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <modified date="2004-07-14-12:00" comment="Changed to DRAFT">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2004-08-04-12:00">INTERIM</status_change>
        <status_change date="2004-08-25-12:00">ACCEPTED</status_change>
        <modified date="2005-06-02-12:00" comment="Added product">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-06-08-03:17">INTERIM</status_change>
        <status_change date="2005-06-29-06:49">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Windows 98 and Windows NT 4.0 do not properly verify the Basic Constraints of digital certificates, allowing remote attackers to execute code, aka "New Variant of Certificate Validation Flaw Could Enable Identity Spoofing" (CAN-2002-0862).</description>
      <reference source="CVE">CVE-2002-1183</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-44" comment="Windows NT Server 4.0 is installed" negate="false"/>
          <criterion test_ref="wft-434" comment="the version of cryptdlg.dll is less then 5.0.1558.6072" negate="false"/>
          <criterion test_ref="wrt-477" comment="the patch Q329115 is installed" negate="true"/>
          <criterion test_ref="wrt-187" comment="the patch kb835732 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1456" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Outlook</product>
      </affected>
      <dates>
        <submitted date="2006-01-11-12:56">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-01-12-09:21">DRAFT</status_change>
        <status_change date="2006-02-01-09:08">INTERIM</status_change>
        <status_change date="2006-02-22-08:27">ACCEPTED</status_change>
      </dates>
      <description>Unspecified vulnerability in Microsoft Outlook 2000 through 2003, Exchange 5.0 Server SP2 and 5.5 SP4, Exchange 2000 SP3, and Office allows remote attackers to execute arbitrary code via an e-mail message with a crafted Transport Neutral Encapsulation Format (TNEF) MIME attachment, related to message length validation.</description>
      <reference source="CVE">CVE-2006-0002</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-630" comment="Outlook 2003 is installed" negate="false"/>
          <criterion test_ref="wft-732" comment="the version of msmapi32.dll is greater than 11.0.6566.0" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1458" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Internet Explorer</product>
      </affected>
      <dates>
        <submitted date="2005-12-13-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-12-16-01:03">DRAFT</status_change>
        <status_change date="2006-01-04-08:04">INTERIM</status_change>
        <status_change date="2006-01-25-07:30">ACCEPTED</status_change>
      </dates>
      <description>Multiple design errors in Microsoft Internet Explorer 5.01, 5.5, and 6 allow user-complicit attackers to execute arbitrary code by (1) overlaying a malicious new window above a file download box, then (2) using a keyboard shortcut and delaying the display of the file download box until the user hits a shortcut that activates the "Run" button, aka "File Download Dialog Box Manipulation Vulnerability."</description>
      <reference source="CVE">CVE-2005-2829</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wrt-10027" comment="Internet Explorer 6 is installed" negate="false"/>
          <criterion test_ref="wft-708" comment="the version of mshtml.dll is less than 6.0.3790.449" negate="false"/>
          <criterion test_ref="wrt-3" comment="a Win2K/XP/2003 service pack is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1459" class="vulnerability">
      <affected family="hp-ux">
        <hpux:platform>HP-UX 11</hpux:platform>
        <product>Samba</product>
      </affected>
      <dates>
        <submitted date="2006-01-13-02:24">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-01-25-07:30">DRAFT</status_change>
        <status_change date="2006-02-22-08:27">INTERIM</status_change>
        <status_change date="2006-03-09-12:19">ACCEPTED</status_change>
      </dates>
      <description>Integer overflow in the Samba daemon (smbd) in Samba 2.x and 3.0.x through 3.0.9 allows remote authenticated users to cause a denial of service (application crash) and possibly execute arbitrary code via a Samba request with a large number of security descriptors that triggers a heap-based buffer overflow.</description>
      <reference source="CVE">CVE-2004-1154</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-691" comment="700 Series or 800 Series OS Release 11.00, 11.11, 11.22, or 11.23" negate="false"/>
          <criterion test_ref="cmp-717" comment="Any of the CIFS components has a version less than A.01.11.04" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1460" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2006-01-07-07:15">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-01-12-09:26">DRAFT</status_change>
        <status_change date="2006-02-01-09:08">INTERIM</status_change>
        <status_change date="2006-02-22-08:27">ACCEPTED</status_change>
      </dates>
      <description>The Windows Graphical Device Interface library (GDI32.DLL) in Microsoft Windows allows remote attackers to execute arbitrary code via a Windows Metafile (WMF) format image with a crafted SETABORTPROC GDI Escape function call, related to the Windows Picture and Fax Viewer (SHIMGVW.DLL), a different vulnerability than CVE-2005-2123 and CVE-2005-2124, and as originally discovered in the wild on unionseek.com.</description>
      <reference source="CVE">CVE-2005-4560</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wrt-4" comment="Win2K/XP/2003 service pack 1 is installed" negate="false"/>
          <criterion test_ref="wft-718" comment="the version of Gdi32.dll is less than 5.2.3790.2606" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1461" class="vulnerability">
      <affected family="hp-ux">
        <hpux:platform>HP-UX 11</hpux:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2006-01-11-12:55">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-01-12-09:18">DRAFT</status_change>
        <modified date="2006-01-26-01:55" comment="Updated to CVE-2005-3779.  HP is so vague that it's not completely certain.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2006-02-22-08:27">INTERIM</status_change>
        <status_change date="2006-03-09-12:19">ACCEPTED</status_change>
      </dates>
      <description>Unspecified vulnerability in xterm for HP-UX 11.00, 11.11, and 11.23 allows local users to gain privileges via unknown vectors.</description>
      <reference source="CVE">CVE-2005-3779</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-618" comment="700 Series or 800 Series OS Release 11.11" negate="false"/>
          <criterion test_ref="hpt-24" comment="Patch PHSS_34102 or later is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1462" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2006-01-11-12:56">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-01-12-09:18">DRAFT</status_change>
        <status_change date="2006-02-01-09:08">INTERIM</status_change>
        <status_change date="2006-02-22-08:27">ACCEPTED</status_change>
      </dates>
      <description>Heap-based buffer overflow in T2EMBED.DLL in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 up to SP1, Windows 98, and Windows ME allows remote attackers to execute arbitrary code via an e-mail message or web page with a crafted Embedded Open Type (EOT) web font that triggers the overflow during decompression.</description>
      <reference source="CVE">CVE-2006-0010</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-2" comment="Windows XP is installed" negate="false"/>
          <criterion test_ref="wrt-4" comment="Win2K/XP/2003 service pack 1 is installed" negate="false"/>
          <criterion test_ref="wrt-70" comment="64-Bit version of Windows is installed" negate="false"/>
          <criterion test_ref="cmp-710" comment="Fontsub.dll &lt; 5.2.3790.2549 or T2embed.dll &lt;5.2.3790.2549 (WinXP,64-bit and S03,SP1)" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1464" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Internet Explorer</product>
      </affected>
      <dates>
        <submitted date="2005-10-12-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-10-19-05:46">DRAFT</status_change>
        <status_change date="2005-11-16-08:02">INTERIM</status_change>
        <status_change date="2005-12-01-06:00">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not intended for use within Internet Explorer, as originally demonstrated using the (1) DDS Library Shape Control (Msdds.dll) COM object, and other objects including (2) Blnmgrps.dll, (3) Ciodm.dll, (4) Comsvcs.dll, (5) Danim.dll, (6) Htmlmarq.ocx, (7) Mdt2dd.dll (as demonstrated using a heap corruption attack with uninitialized memory), (8) Mdt2qd.dll, (9) Mpg4ds32.ax, (10) Msadds32.ax, (11) Msb1esen.dll, (12) Msb1fren.dll, (13) Msb1geen.dll, (14) Msdtctm.dll, (15) Mshtml.dll, (16) Msoeacct.dll, (17) Msosvfbr.dll, (18) Mswcrun.dll, (19) Netshell.dll, (20) Ole2disp.dll, (21) Outllib.dll, (22) Psisdecd.dll, (23) Qdvd.dll, (24) Repodbc.dll, (25) Shdocvw.dll, (26) Shell32.dll, (27) Soa.dll, (28) Srchui.dll, (29) Stobject.dll, (30) Vdt70.dll, (31) Vmhelper.dll, and (32) Wbemads.dll, aka a variant of the "COM Object Instantiation Memory Corruption vulnerability."</description>
      <reference source="CVE">CVE-2005-2127</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wrt-4" comment="Win2K/XP/2003 service pack 1 is installed" negate="false"/>
          <criterion test_ref="wft-668" comment="mshtml.dll is less than 6.0.3790.2541" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1466" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2005-10-12-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-10-19-05:46">DRAFT</status_change>
        <status_change date="2005-11-16-08:02">INTERIM</status_change>
        <status_change date="2005-12-01-06:00">ACCEPTED</status_change>
      </dates>
      <description>COM+ in Microsoft Windows does not properly "create and use memory structures," which allows local users or remote attackers to execute arbitrary code.</description>
      <reference source="CVE">CVE-2005-1978</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wrt-10026" comment="Win2K/XP/2003 is patched" negate="true"/>
          <criterion test_ref="cmp-609" comment="Either ole32.dll or rpcss.dll has a version less than 5.2.3790.374" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1467" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Samba</product>
      </affected>
      <dates>
        <submitted date="2005-01-19-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-24-03:40">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in samba 2.2.2 through 2.2.6 allows remote attackers to cause a denial of service and possibly execute arbitrary code via an encrypted password that causes the overflow during decryption in which a DOS codepage string is converted to a little-endian UCS2 unicode string.</description>
      <reference source="CVE">CVE-2002-1318</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-6" comment="Solaris 9 Installed" negate="false"/>
          <criterion test_ref="sat-28" comment="Samba - Usr (SUNWsmbau) installed" negate="false"/>
          <criterion test_ref="spt-48" comment="Patch 114684-01 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-15" comment="smbd running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1468" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Internet Explorer</product>
      </affected>
      <dates>
        <submitted date="2005-10-12-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-10-19-05:46">DRAFT</status_change>
        <status_change date="2005-11-16-08:02">INTERIM</status_change>
        <status_change date="2005-12-01-06:00">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not intended for use within Internet Explorer, as originally demonstrated using the (1) DDS Library Shape Control (Msdds.dll) COM object, and other objects including (2) Blnmgrps.dll, (3) Ciodm.dll, (4) Comsvcs.dll, (5) Danim.dll, (6) Htmlmarq.ocx, (7) Mdt2dd.dll (as demonstrated using a heap corruption attack with uninitialized memory), (8) Mdt2qd.dll, (9) Mpg4ds32.ax, (10) Msadds32.ax, (11) Msb1esen.dll, (12) Msb1fren.dll, (13) Msb1geen.dll, (14) Msdtctm.dll, (15) Mshtml.dll, (16) Msoeacct.dll, (17) Msosvfbr.dll, (18) Mswcrun.dll, (19) Netshell.dll, (20) Ole2disp.dll, (21) Outllib.dll, (22) Psisdecd.dll, (23) Qdvd.dll, (24) Repodbc.dll, (25) Shdocvw.dll, (26) Shell32.dll, (27) Soa.dll, (28) Srchui.dll, (29) Stobject.dll, (30) Vdt70.dll, (31) Vmhelper.dll, and (32) Wbemads.dll, aka a variant of the "COM Object Instantiation Memory Corruption vulnerability."</description>
      <reference source="CVE">CVE-2005-2127</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1058" comment="Windows XP 32-bit edition is installed" negate="false"/>
          <criterion test_ref="cmp-35" comment="Windows XP 32 bit Service Pack 2" negate="false"/>
          <criterion test_ref="wft-667" comment="mshtml.dll is less than 6.0.2900.2769" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1470" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2006-03-28-09:02">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-04-06-06:30">DRAFT</status_change>
        <status_change date="2006-05-03-10:06">INTERIM</status_change>
      </dates>
      <description>'An unspecified vulnerability in the \"/usr/ucb/ps\" command could allow unprivileged local users to see environment settings for processes of other users.  When the \'e\' flag is used, a low-privileged user can see environment variables and values for processes that belong to root and any other system users. NOTE: \"/usr/bin/ps\" is the default \'ps\' command for most users per the command search path and is not affected by this vulnerability'</description>
      <reference source="MISC">http://sunsolve9.sun.com/search/document.do?assetkey=1-26-102215-1&amp;amp;searchclause=</reference>
      <status>INTERIM</status>
      <version>0</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-812" comment="Solaris 8 (SPARC) meets Sun Alert ID 102215 criteria." negate="false"/>
          <criterion test_ref="cmp-813" comment="Solaris 9 (SPARC) meets Sun Alert ID 102215 criteria." negate="false"/>
          <criterion test_ref="cmp-814" comment="Solaris 8 (x86) meets Sun Alert ID 102215 criteria." negate="false"/>
          <criterion test_ref="cmp-817" comment="Solaris 9 (x86) meets Sun Alert ID 102215 criteria." negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1472" class="vulnerability">
      <affected family="hp-ux">
        <hpux:platform>HP-UX 10</hpux:platform>
        <product>ftpd</product>
      </affected>
      <dates>
        <submitted date="2005-11-30-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-12-20-11:03">DRAFT</status_change>
        <status_change date="2006-01-04-08:04">INTERIM</status_change>
        <status_change date="2006-01-25-07:30">ACCEPTED</status_change>
      </dates>
      <description>The FTP server in HP-UX 10.20, B.11.00, and B.11.11, allows remote attackers to list arbitrary directories as root by running the LIST command before logging in.</description>
      <reference source="CVE">CVE-2005-3296</reference>
      <status>ACCEPTED</status>
      <version>5</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-633" comment="700 Series or 800 Series OS Release 10.20" negate="false"/>
          <criterion test_ref="cmp-668" comment="InternetSrvcs.INETSVCS-RUN or InternetSrvcs.INET-ENG-A-MAN (B.10.20) is installed" negate="false"/>
          <criterion test_ref="hpt-7" comment="Patch PHNE_23948 or later is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1475" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Internet Explorer</product>
      </affected>
      <dates>
        <submitted date="2005-12-13-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-12-16-01:03">DRAFT</status_change>
        <status_change date="2006-01-04-08:04">INTERIM</status_change>
        <status_change date="2006-01-25-07:30">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not intended for use within Internet Explorer, aka a variant of the "COM Object Instantiation Memory Corruption Vulnerability," a different vulnerability than CVE-2005-2127.</description>
      <reference source="CVE">CVE-2005-2831</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wrt-10027" comment="Internet Explorer 6 is installed" negate="false"/>
          <criterion test_ref="wft-708" comment="the version of mshtml.dll is less than 6.0.3790.449" negate="false"/>
          <criterion test_ref="wrt-3" comment="a Win2K/XP/2003 service pack is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1479" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>libpng</product>
      </affected>
      <dates>
        <submitted date="2004-12-12-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-24-12:04">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Multiple integer overflows in the (1) png_read_png in pngread.c or (2) png_handle_sPLT functions in pngrutil.c or (3) progressive display image reading capability in libpng 1.2.5 and earlier allow remote attackers to cause a denial of service (application crash) via a malformed PNG image.</description>
      <reference source="CVE">CVE-2004-0599</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" negate="false"/>
          <criterion test_ref="sat-11" comment="Netscape installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1480" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>mozilla</product>
      </affected>
      <dates>
        <submitted date="2005-11-11-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-12-12-10:00">DRAFT</status_change>
        <status_change date="2005-12-28-04:28">INTERIM</status_change>
        <status_change date="2006-01-12-08:59">ACCEPTED</status_change>
      </dates>
      <description>Heap-based buffer overflow in Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to execute arbitrary code via an XBM image file that ends in a large number of spaces instead of the expected end tag.</description>
      <reference source="CVE">CVE-2005-2701</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-621" comment="Mozilla Suite version 1.7.10 or earlier is installed" negate="false"/>
          <criterion test_ref="cmp-631" comment="Mozilla Firefox version 1.0.6 or earlier is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1482" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Solaris Management Console (SMC)</product>
      </affected>
      <dates>
        <submitted date="2005-04-13-04:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-04-20-04:00">DRAFT</status_change>
        <status_change date="2005-05-11-04:00">INTERIM</status_change>
        <status_change date="2005-06-01-04:00">ACCEPTED</status_change>
        <modified date="2005-08-22-04:00" comment="Affected product changed to Sun Management Console (SMC); mistakenly was .NET framework">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2005-08-25-10:03">INTERIM</status_change>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>The Solaris Management Console (SMC) in Sun Solaris 8 and 9 generates different 404 error messages when a file does not exist versus when a file exists but is otherwise inacessible, which could allow remote attackers to obtain sensitive information in conjunction with a directory traversal (..) attack.</description>
      <reference source="CVE">CVE-2004-1354</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" negate="false"/>
          <criterion test_ref="sat-40" comment="Solaris Management Console Web Components (SUNWwbmc) installed" negate="false"/>
          <criterion test_ref="spt-76" comment="Patch 111313-02 or later installed" negate="true"/>
          <criterion test_ref="spt-77" comment="Patch 116807-01 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-20" comment="smcboot running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1484" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Internet Explorer</product>
      </affected>
      <dates>
        <submitted date="2006-04-12-12:55">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-04-12-05:16">DRAFT</status_change>
        <status_change date="2006-05-03-10:06">INTERIM</status_change>
      </dates>
      <description>Unspecified vulnerability in Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via a crafted URL with double-byte characters, aka the "Double Byte Character Parsing Memory Corruption Vulnerability."</description>
      <reference source="CVE">CVE-2006-1189</reference>
      <status>INTERIM</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wrt-10026" comment="Win2K/XP/2003 is patched" negate="true"/>
          <criterion test_ref="wft-778" comment="the version of mshtml.dll is less than 6.0.3790.507" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1485" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Outlook</product>
      </affected>
      <dates>
        <submitted date="2006-01-11-12:56">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-01-12-09:21">DRAFT</status_change>
        <status_change date="2006-02-01-09:08">INTERIM</status_change>
        <status_change date="2006-02-22-08:27">ACCEPTED</status_change>
      </dates>
      <description>Unspecified vulnerability in Microsoft Outlook 2000 through 2003, Exchange 5.0 Server SP2 and 5.5 SP4, Exchange 2000 SP3, and Office allows remote attackers to execute arbitrary code via an e-mail message with a crafted Transport Neutral Encapsulation Format (TNEF) MIME attachment, related to message length validation.</description>
      <reference source="CVE">CVE-2006-0002</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-632" comment="Outlook 2000 is installed" negate="false"/>
          <criterion test_ref="wft-733" comment="the version of msmapi32.dll is less than 5.5.3201.0" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1488" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2005-10-12-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-10-19-05:46">DRAFT</status_change>
        <status_change date="2005-11-16-08:02">INTERIM</status_change>
        <status_change date="2005-12-01-06:00">ACCEPTED</status_change>
      </dates>
      <description>Windows Shell for Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 allows remote attackers to execute arbitrary commands via a shortcut (.lnk) file with long font properties that lead to a buffer overflow in the Client/Server Runtime Server Subsystem (CSRSS), a different vulnerability than CVE-2005-2118.</description>
      <reference source="CVE">CVE-2005-2122</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
          <criterion test_ref="wrt-432" comment="Win2K/XP/2003 service pack 4 is installed" negate="false"/>
          <criterion test_ref="wft-683" comment="shell32.dll is less than 5.0.3900.7071" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1489" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Internet Explorer</product>
      </affected>
      <dates>
        <submitted date="2005-11-11-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-12-12-10:00">DRAFT</status_change>
        <modified date="2005-12-14-12:00" comment="Updated with newly available information.">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </modified>
        <status_change date="2006-01-04-08:04">INTERIM</status_change>
        <status_change date="2006-01-25-07:30">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Internet Explorer 6 SP2 6.0.2900.2180 and 6.0.2800.1106, and earlier versions, allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a Javascript BODY onload event that calls the window function, aka "Mismatched Document Object Model Objects Memory Corruption Vulnerability."</description>
      <reference source="CVE">CVE-2005-1790</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-212" comment="Windows 2000 Service Pack 4 (or later) is installed" negate="false"/>
          <criterion test_ref="wrt-54" comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false"/>
          <criterion test_ref="wft-704" comment="the version of mshtml.dll is less than 5.0.3835.2200" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1490" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Internet Explorer</product>
      </affected>
      <dates>
        <submitted date="2005-12-13-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-12-16-01:03">DRAFT</status_change>
        <status_change date="2006-01-04-08:04">INTERIM</status_change>
        <status_change date="2006-01-25-07:30">ACCEPTED</status_change>
      </dates>
      <description>Multiple design errors in Microsoft Internet Explorer 5.01, 5.5, and 6 allow user-complicit attackers to execute arbitrary code by (1) overlaying a malicious new window above a file download box, then (2) using a keyboard shortcut and delaying the display of the file download box until the user hits a shortcut that activates the "Run" button, aka "File Download Dialog Box Manipulation Vulnerability."</description>
      <reference source="CVE">CVE-2005-2829</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-212" comment="Windows 2000 Service Pack 4 (or later) is installed" negate="false"/>
          <criterion test_ref="wrt-54" comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false"/>
          <criterion test_ref="wft-704" comment="the version of mshtml.dll is less than 5.0.3835.2200" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1491" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2006-01-11-12:56">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-01-12-09:18">DRAFT</status_change>
        <status_change date="2006-02-01-09:08">INTERIM</status_change>
        <status_change date="2006-02-22-08:27">ACCEPTED</status_change>
      </dates>
      <description>Heap-based buffer overflow in T2EMBED.DLL in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 up to SP1, Windows 98, and Windows ME allows remote attackers to execute arbitrary code via an e-mail message or web page with a crafted Embedded Open Type (EOT) web font that triggers the overflow during decompression.</description>
      <reference source="CVE">CVE-2006-0010</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-2" comment="Windows XP is installed" negate="false"/>
          <criterion test_ref="wrt-4" comment="Win2K/XP/2003 service pack 1 is installed" negate="false"/>
          <criterion test_ref="wrt-70" comment="64-Bit version of Windows is installed" negate="true"/>
          <criterion test_ref="cmp-708" comment="Fontsub.dll &lt; 5.1.2600.1762 or T2embed.dll &lt;5.1.2600.1762 (WinXP,SP1)" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1492" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2006-01-07-07:15">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-01-12-09:25">DRAFT</status_change>
        <status_change date="2006-02-01-09:08">INTERIM</status_change>
        <status_change date="2006-02-22-08:27">ACCEPTED</status_change>
      </dates>
      <description>The Windows Graphical Device Interface library (GDI32.DLL) in Microsoft Windows allows remote attackers to execute arbitrary code via a Windows Metafile (WMF) format image with a crafted SETABORTPROC GDI Escape function call, related to the Windows Picture and Fax Viewer (SHIMGVW.DLL), a different vulnerability than CVE-2005-2123 and CVE-2005-2124, and as originally discovered in the wild on unionseek.com.</description>
      <reference source="CVE">CVE-2005-4560</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-2" comment="Windows XP is installed" negate="false"/>
          <criterion test_ref="wrt-4" comment="Win2K/XP/2003 service pack 1 is installed" negate="false"/>
          <criterion test_ref="wrt-70" comment="64-Bit version of Windows is installed" negate="false"/>
          <criterion test_ref="wft-718" comment="the version of Gdi32.dll is less than 5.2.3790.2606" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1493" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>mozilla</product>
      </affected>
      <dates>
        <submitted date="2006-02-07-06:13">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-02-22-08:27">DRAFT</status_change>
        <status_change date="2006-03-09-12:19">INTERIM</status_change>
        <status_change date="2006-04-06-06:30">ACCEPTED</status_change>
      </dates>
      <description>The XULDocument.persist function in Mozilla, Firefox before 1.5.0.1, and SeaMonkey before 1.0 does not validate the attribute name, which allows remote attackers to execute arbitrary Javascript by injecting RDF data into the user's localstore.rdf file.</description>
      <reference source="CVE">CVE-2006-0296</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-748" comment="Mozilla Firefox pre-1.5 is installed" negate="false"/>
          <criterion test_ref="cmp-744" comment="Mozilla Firefox version 1.5 is installed and has NOT been patched with version 1.5.0.1" negate="false"/>
          <criterion test_ref="cmp-746" comment="Mozilla Suite is installed" negate="false"/>
          <criterion test_ref="cmp-747" comment="A pre-release of SeaMonkey 1.0 is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1494" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>mozilla</product>
      </affected>
      <dates>
        <submitted date="2006-02-07-06:13">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-02-22-08:27">DRAFT</status_change>
        <status_change date="2006-03-09-12:19">INTERIM</status_change>
        <status_change date="2006-04-06-06:30">ACCEPTED</status_change>
      </dates>
      <description>The function allocation code (js_NewFunction in jsfun.c) in Firefox 1.5 allows attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via user-defined methods that trigger garbage collection in a way that operates on freed objects.</description>
      <reference source="CVE">CVE-2006-0293</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-744" comment="Mozilla Firefox version 1.5 is installed and has NOT been patched with version 1.5.0.1" negate="false"/>
          <criterion test_ref="cmp-747" comment="A pre-release of SeaMonkey 1.0 is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1496" class="vulnerability">
      <affected family="hp-ux">
        <hpux:platform>HP-UX 11</hpux:platform>
        <product>Apache</product>
      </affected>
      <dates>
        <submitted date="2006-03-18-07:24">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-03-22-11:10">DRAFT</status_change>
        <status_change date="2006-04-06-06:31">INTERIM</status_change>
        <status_change date="2006-05-03-10:06">ACCEPTED</status_change>
      </dates>
      <description>Integer overflow in pcre_compile.c in Perl Compatible Regular Expressions (PCRE) before 6.2, as used in multiple products such as Python, Ethereal, and PHP, allows attackers to execute arbitrary code via quantifier values in regular expressions, which leads to a heap-based buffer overflow.</description>
      <reference source="CVE">CVE-2005-2491</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-672" comment="700 Series OS Release 11.04" negate="false"/>
          <criterion test_ref="hst-70" comment="Webproxy is installed" negate="false"/>
          <criterion test_ref="hpt-40" comment="Patch PHSS_34163 or later is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1497" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>mozilla</product>
      </affected>
      <dates>
        <submitted date="2006-02-07-06:13">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-02-22-08:27">DRAFT</status_change>
        <status_change date="2006-03-09-12:19">INTERIM</status_change>
        <status_change date="2006-04-06-06:30">ACCEPTED</status_change>
      </dates>
      <description>'mozilla.org has launched and delivered SeaMonkey, a community effort to deliver production-quality releases of code derived from the \"Mozilla Application Suite\".  This equates to a cessation in software and security patches for that baseline.  Using an unsupported software represents a high security risk because no fixes or patches will be made available in response to new vulnerabilities.'</description>
      <reference source="MISC">http://www.mozilla.org/projects/seamonkey/</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-746" comment="Mozilla Suite is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1498" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Internet Explorer</product>
      </affected>
      <dates>
        <submitted date="2006-04-12-12:55">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-04-12-05:16">DRAFT</status_change>
        <status_change date="2006-05-03-10:06">INTERIM</status_change>
      </dates>
      <description>Microsoft Internet Explorer 5.01 through 6 allows remote attackers to conduct phishing attacks by spoofing the address bar and other parts of the trust UI via unknown methods that allow "window content to persist" after the user has navigated to another site, aka the "Address Bar Spoofing Vulnerability."  NOTE: this is a different vulnerability than CVE-2006-1626.</description>
      <reference source="CVE">CVE-2006-1192</reference>
      <status>INTERIM</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wrt-10026" comment="Win2K/XP/2003 is patched" negate="true"/>
          <criterion test_ref="wft-778" comment="the version of mshtml.dll is less than 6.0.3790.507" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1499" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2005-10-12-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-10-19-05:46">DRAFT</status_change>
        <status_change date="2005-11-16-08:02">INTERIM</status_change>
        <status_change date="2005-12-01-06:00">ACCEPTED</status_change>
      </dates>
      <description>COM+ in Microsoft Windows does not properly "create and use memory structures," which allows local users or remote attackers to execute arbitrary code.</description>
      <reference source="CVE">CVE-2005-1978</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1058" comment="Windows XP 32-bit edition is installed" negate="false"/>
          <criterion test_ref="cmp-35" comment="Windows XP 32 bit Service Pack 2" negate="false"/>
          <criterion test_ref="cmp-607" comment="Either ole32.dll or rpcss.dll has a version less than 5.1.2600.2726" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1503" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>HTML Help Facility</product>
      </affected>
      <dates>
        <submitted date="2004-07-14-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <status_change date="2004-08-04-12:00">INTERIM</status_change>
        <status_change date="2004-08-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Heap-based buffer overflow in the HtmlHelp program (hh.exe) in HTML Help for Microsoft Windows 98, Me, NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary commands via a .CHM file with a large length field, a different vulnerability than CVE-2003-1041.</description>
      <reference source="CVE">CVE-2004-0201</reference>
      <status>ACCEPTED</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
          <criterion test_ref="wft-444" comment="the version of itss.dll is less than 5.2.3790.185" negate="false"/>
          <criterion test_ref="wrt-482" comment="the patch kb840315 is installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-491" comment="HTML Help is registered" negate="true"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1504" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Office</product>
      </affected>
      <dates>
        <submitted date="2006-03-15-10:53">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-03-15-07:17">DRAFT</status_change>
        <status_change date="2006-04-06-06:31">INTERIM</status_change>
        <status_change date="2006-05-03-10:06">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in Microsoft Office 2000 SP3, XP SP3, and other versions and packages, allows user-complicit attackers to execute arbitrary code via a routing slip that is longer than specified by the provided length field.</description>
      <reference source="CVE">CVE-2006-0009</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-650" comment="Excel 2003 is installed" negate="false"/>
          <criterion test_ref="wft-773" comment="the version of excel.exe is less than 11.0.8012.0" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1505" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Internet Explorer</product>
      </affected>
      <dates>
        <submitted date="2005-12-13-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-12-16-01:03">DRAFT</status_change>
        <status_change date="2006-01-04-08:04">INTERIM</status_change>
        <status_change date="2006-01-25-07:30">ACCEPTED</status_change>
      </dates>
      <description>Multiple design errors in Microsoft Internet Explorer 5.01, 5.5, and 6 allow user-complicit attackers to execute arbitrary code by (1) overlaying a malicious new window above a file download box, then (2) using a keyboard shortcut and delaying the display of the file download box until the user hits a shortcut that activates the "Run" button, aka "File Download Dialog Box Manipulation Vulnerability."</description>
      <reference source="CVE">CVE-2005-2829</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-613" comment="Win2K or XP,SP1 is installed" negate="false"/>
          <criterion test_ref="wrt-50" comment="Internet Explorer 6 Service Pack 1 is installed" negate="false"/>
          <criterion test_ref="wft-705" comment="the version of mshtml.dll is less than 6.0.2800.1528" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1506" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Internet Explorer</product>
      </affected>
      <dates>
        <submitted date="2005-12-26-09:36">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-01-04-08:04">DRAFT</status_change>
        <status_change date="2006-01-25-07:30">INTERIM</status_change>
        <status_change date="2006-02-22-08:27">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 5.01 SP4 up to 6 on various Windows operating systems, including IE 6.0.2900.2180 on Windows XP, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not ActiveX controls, as demonstrated using the JVIEW Profiler (Javaprxy.dll).  NOTE: the researcher says that the vendor could not reproduce this problem.</description>
      <reference source="CVE">CVE-2005-2087</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-50" comment="Internet Explorer 6 Service Pack 1 is installed" negate="false"/>
          <criterion test_ref="cmp-317" comment="the version of mshtml.dll is less than 6.0.2800.1515 or 6.0.2800.1516 " negate="false"/>
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1507" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Internet Explorer</product>
      </affected>
      <dates>
        <submitted date="2005-12-13-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-12-16-01:03">DRAFT</status_change>
        <status_change date="2006-01-04-08:04">INTERIM</status_change>
        <status_change date="2006-01-25-07:30">ACCEPTED</status_change>
      </dates>
      <description>Multiple design errors in Microsoft Internet Explorer 5.01, 5.5, and 6 allow user-complicit attackers to execute arbitrary code by (1) overlaying a malicious new window above a file download box, then (2) using a keyboard shortcut and delaying the display of the file download box until the user hits a shortcut that activates the "Run" button, aka "File Download Dialog Box Manipulation Vulnerability."</description>
      <reference source="CVE">CVE-2005-2829</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-35" comment="Windows XP 32 bit Service Pack 2" negate="false"/>
          <criterion test_ref="wrt-10027" comment="Internet Explorer 6 is installed" negate="false"/>
          <criterion test_ref="wft-706" comment="the version of mshtml.dll is less than 6.0.2900.2802" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1508" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Internet Explorer</product>
      </affected>
      <dates>
        <submitted date="2005-11-11-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-12-12-10:00">DRAFT</status_change>
        <modified date="2005-12-14-12:00" comment="Updated with newly available information.">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </modified>
        <status_change date="2006-01-04-08:04">INTERIM</status_change>
        <status_change date="2006-01-25-07:30">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Internet Explorer 6 SP2 6.0.2900.2180 and 6.0.2800.1106, and earlier versions, allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a Javascript BODY onload event that calls the window function, aka "Mismatched Document Object Model Objects Memory Corruption Vulnerability."</description>
      <reference source="CVE">CVE-2005-1790</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wrt-10027" comment="Internet Explorer 6 is installed" negate="false"/>
          <criterion test_ref="wft-707" comment="the version of mshtml.dll is less than 6.0.3790.2577" negate="false"/>
          <criterion test_ref="wrt-4" comment="Win2K/XP/2003 service pack 1 is installed" negate="false"/>
          <criterion test_ref="cmp-686" comment="Server 2003 IE Enhanced Security is installed and set." negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1509" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Office</product>
      </affected>
      <dates>
        <submitted date="2006-03-15-10:53">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-03-15-07:17">DRAFT</status_change>
        <status_change date="2006-04-06-06:30">INTERIM</status_change>
        <status_change date="2006-05-03-10:06">ACCEPTED</status_change>
      </dates>
      <description>Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-complicit attackers to execute arbitrary code via a BIFF parsing format file containing malformed BOOLERR records that lead to memory corruption, probably involving invalid pointers.</description>
      <reference source="CVE">CVE-2006-0028</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-650" comment="Excel 2003 is installed" negate="false"/>
          <criterion test_ref="wft-773" comment="the version of excel.exe is less than 11.0.8012.0" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1510" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Office</product>
      </affected>
      <dates>
        <submitted date="2006-03-15-10:53">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-03-15-07:17">DRAFT</status_change>
        <status_change date="2006-04-06-06:30">INTERIM</status_change>
        <status_change date="2006-05-03-10:06">ACCEPTED</status_change>
      </dates>
      <description>Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-complicit attackers to execute arbitrary code via an Excel file with a malformed graphic, which leads to memory corruption.</description>
      <reference source="CVE">CVE-2006-0030</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-650" comment="Excel 2003 is installed" negate="false"/>
          <criterion test_ref="wft-773" comment="the version of excel.exe is less than 11.0.8012.0" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1511" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>MDAC</product>
      </affected>
      <dates>
        <submitted date="2006-04-12-12:55">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-04-12-05:16">DRAFT</status_change>
        <status_change date="2006-05-03-10:06">INTERIM</status_change>
      </dates>
      <description>Unspecified vulnerability in the RDS.Dataspace ActiveX control, which is contained in ActiveX Data Objects (ADO) and distributed in Microsoft Data Access Components (MDAC) 2.7 and 2.8, allows remote attackers to execute arbitrary code via unknown attack vectors.</description>
      <reference source="CVE">CVE-2006-0003</reference>
      <status>INTERIM</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-2" comment="Windows XP is installed" negate="false"/>
          <criterion test_ref="wrt-4" comment="Win2K/XP/2003 service pack 1 is installed" negate="false"/>
          <criterion test_ref="wrt-70" comment="64-Bit version of Windows is installed" negate="true"/>
          <criterion test_ref="wft-784" comment="the version of msadco.dll is less than 2.71.9053.0" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1512" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>VDM</product>
      </affected>
      <dates>
        <submitted date="2004-06-11-12:00">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </submitted>
        <modified date="2004-07-19-12:00" comment="Modifed without comment">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <status_change date="2004-08-04-12:00">ACCEPTED</status_change>
      </dates>
      <description>The component for the Virtual DOS Machine (VDM) subsystem in Windows NT 4.0 and Windows 2000 does not properly validate system structures, which allows local users to access protected kernel memory and execute arbitrary code.</description>
      <reference source="CVE">CVE-2004-0118</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wft-342" comment="The version of Ntoskrnl.exe is less than 5.0.2195.6902" negate="false"/>
          <criterion test_ref="wrt-187" comment="the patch kb835732 is installed" negate="true"/>
          <criterion test_ref="cmp-933" comment="Windows NT or 2000 Installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1513" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>TIP</product>
      </affected>
      <dates>
        <submitted date="2005-10-12-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-10-19-05:46">DRAFT</status_change>
        <status_change date="2005-11-16-08:02">INTERIM</status_change>
        <status_change date="2005-12-01-06:00">ACCEPTED</status_change>
      </dates>
      <description>Distributed Transaction Controller in Microsoft Windows allows remote servers to cause a denial of service (MSDTC service exception and exit) via an "unexpected protocol command during the reconnection request," which is not properly handled by the Transaction Internet Protocol (TIP) functionality.</description>
      <reference source="CVE">CVE-2005-1979</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1112" comment="Windows XP 64-bit" negate="false"/>
          <criterion test_ref="wrt-4" comment="Win2K/XP/2003 service pack 1 is installed" negate="false"/>
          <criterion test_ref="cmp-608" comment="Either ole32.dll or rpcss.dll has a version less than 5.2.3790.2492" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1514" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>mozilla</product>
      </affected>
      <dates>
        <submitted date="2006-02-07-06:13">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-02-22-08:27">DRAFT</status_change>
        <status_change date="2006-03-09-12:19">INTERIM</status_change>
        <status_change date="2006-04-06-06:30">ACCEPTED</status_change>
      </dates>
      <description>Mozilla Firefox before 1.5.0.1, Thunderbird 1.5 if running Javascript in mail, and SeaMonkey before 1.0 allow remote attackers to execute arbitrary code by changing an element's style from position:relative to position:static, which causes Gecko to operate on freed memory.</description>
      <reference source="CVE">CVE-2006-0294</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-744" comment="Mozilla Firefox version 1.5 is installed and has NOT been patched with version 1.5.0.1" negate="false"/>
          <criterion test_ref="cmp-747" comment="A pre-release of SeaMonkey 1.0 is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1515" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2005-10-12-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-10-19-05:46">DRAFT</status_change>
        <status_change date="2005-11-16-08:02">INTERIM</status_change>
        <status_change date="2005-12-01-06:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in Collaboration Data Objects (CDO), as used in Microsoft Windows and Microsoft Exchange Server, allows remote attackers to execute arbitrary code when CDOSYS or CDOEX processes an e-mail message with a large header name, as demonstrated using the "Content-Type" string.</description>
      <reference source="CVE">CVE-2005-1987</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1058" comment="Windows XP 32-bit edition is installed" negate="false"/>
          <criterion test_ref="cmp-35" comment="Windows XP 32 bit Service Pack 2" negate="false"/>
          <criterion test_ref="wft-679" comment="cdosys.dll is less than 6.2.4.0" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1517" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2005-10-12-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-10-19-05:46">DRAFT</status_change>
        <status_change date="2005-11-16-08:02">INTERIM</status_change>
        <status_change date="2005-12-01-06:00">ACCEPTED</status_change>
      </dates>
      <description>Windows Shell for Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 allows remote attackers to execute arbitrary commands via a shortcut (.lnk) file with long font properties that lead to a buffer overflow in the Client/Server Runtime Server Subsystem (CSRSS), a different vulnerability than CVE-2005-2118.</description>
      <reference source="CVE">CVE-2005-2122</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1058" comment="Windows XP 32-bit edition is installed" negate="false"/>
          <criterion test_ref="cmp-35" comment="Windows XP 32 bit Service Pack 2" negate="false"/>
          <criterion test_ref="wft-685" comment="shell32.dll is less than 6.0.2900.2763" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1518" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Internet Explorer</product>
      </affected>
      <dates>
        <submitted date="2005-12-26-09:36">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-01-04-08:04">DRAFT</status_change>
        <status_change date="2006-01-25-07:30">INTERIM</status_change>
        <status_change date="2006-02-22-08:27">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 5.01 SP4 up to 6 on various Windows operating systems, including IE 6.0.2900.2180 on Windows XP, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not ActiveX controls, as demonstrated using the JVIEW Profiler (Javaprxy.dll).  NOTE: the researcher says that the vendor could not reproduce this problem.</description>
      <reference source="CVE">CVE-2005-2087</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-51" comment="Internet Explorer 6  for Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="cmp-315" comment="a vulnerable version of mshtml.dll exisits" negate="false"/>
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1519" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2005-10-12-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-10-19-05:46">DRAFT</status_change>
        <status_change date="2005-11-16-08:02">INTERIM</status_change>
        <status_change date="2005-12-01-06:00">ACCEPTED</status_change>
      </dates>
      <description>Stack-based buffer overflow in the Plug and Play (PnP) service (UMPNPMGR.DLL) in Microsoft Windows 2000 SP4, and XP SP1 and SP2, allows remote or local authenticated attackers to execute arbitrary code via a large number of "\" (backslash) characters in a registry key name, which triggers the overflow in a wsprintfW function call.</description>
      <reference source="CVE">CVE-2005-2120</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-2" comment="Windows XP is installed" negate="false"/>
          <criterion test_ref="wrt-250" comment="Win2K/XP/2003 service pack 2 is installed" negate="false"/>
          <criterion test_ref="wft-676" comment="umpnpmgr.dll is less than 5.1.2600.2744" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1520" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Internet Explorer</product>
      </affected>
      <dates>
        <submitted date="2005-12-13-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-12-16-01:03">DRAFT</status_change>
        <status_change date="2006-01-04-08:04">INTERIM</status_change>
        <status_change date="2006-01-25-07:30">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not intended for use within Internet Explorer, aka a variant of the "COM Object Instantiation Memory Corruption Vulnerability," a different vulnerability than CVE-2005-2127.</description>
      <reference source="CVE">CVE-2005-2831</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1066" comment="Windows XP 64-bit with Service Pack 1" negate="false"/>
          <criterion test_ref="wrt-10027" comment="Internet Explorer 6 is installed" negate="false"/>
          <criterion test_ref="wrt-4" comment="Win2K/XP/2003 service pack 1 is installed" negate="false"/>
          <criterion test_ref="wft-707" comment="the version of mshtml.dll is less than 6.0.3790.2577" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1521" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Internet Explorer</product>
      </affected>
      <dates>
        <submitted date="2005-12-13-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-12-16-01:03">DRAFT</status_change>
        <status_change date="2006-01-04-08:04">INTERIM</status_change>
        <status_change date="2006-01-25-07:30">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Internet Explorer 5.01, 5.5, and 6, when using an HTTPS proxy server that requires Basic Authentication, sends URLs in cleartext, which allows remote attackers to obtain sensitive information, aka "HTTPS Proxy Vulnerability."</description>
      <reference source="CVE">CVE-2005-2830</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-212" comment="Windows 2000 Service Pack 4 (or later) is installed" negate="false"/>
          <criterion test_ref="wrt-54" comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false"/>
          <criterion test_ref="wft-704" comment="the version of mshtml.dll is less than 5.0.3835.2200" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1522" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Office</product>
      </affected>
      <dates>
        <submitted date="2006-03-15-10:53">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-03-15-07:17">DRAFT</status_change>
        <status_change date="2006-04-06-06:31">INTERIM</status_change>
        <status_change date="2006-05-03-10:06">ACCEPTED</status_change>
      </dates>
      <description>Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-complicit attackers to execute arbitrary code via an Excel file with a malformed description, which leads to memory corruption.</description>
      <reference source="CVE">CVE-2006-0029</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-649" comment="Excel 2002 is installed" negate="false"/>
          <criterion test_ref="wft-771" comment="the version of excel.exe is less than 10.0.6789.0" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1523" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2005-10-12-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-10-19-05:46">DRAFT</status_change>
        <status_change date="2005-11-16-08:02">INTERIM</status_change>
        <status_change date="2005-12-01-06:00">ACCEPTED</status_change>
      </dates>
      <description>'As Service Packs released by Microsft mature, earlier versions and releases become unspported.  This equates to a cessation in software and security patches for that baseline.  Using an unsupported version of Windows represents a severe security risk.'</description>
      <reference source="MISC">http://www.microsoft.com/sp</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-611" comment="An unsupported version of Windows XP is installed" negate="false"/>
          <criterion test_ref="cmp-65" comment="Windows 2000 (sp3 or earlier) is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1525" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Office</product>
      </affected>
      <dates>
        <submitted date="2006-03-15-10:53">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-03-15-07:17">DRAFT</status_change>
        <status_change date="2006-04-06-06:31">INTERIM</status_change>
        <status_change date="2006-05-03-10:06">ACCEPTED</status_change>
      </dates>
      <description>Stack-based buffer overflow in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-complicit attackers to execute arbitrary code via an Excel file with a malformed record with a modified length value, which leads to memory corruption.</description>
      <reference source="CVE">CVE-2006-0031</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wft-774" comment="Xlview.exe is installed with a version less than 11.0.8012.0" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1526" class="vulnerability">
      <affected family="hp-ux">
        <hpux:platform>HP-UX 11</hpux:platform>
        <product>Apache</product>
      </affected>
      <dates>
        <submitted date="2006-03-18-07:24">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-03-22-11:10">DRAFT</status_change>
        <status_change date="2006-04-06-06:31">INTERIM</status_change>
        <status_change date="2006-05-03-10:06">ACCEPTED</status_change>
      </dates>
      <description>The Apache HTTP server before 1.3.34, and 2.0.x before 2.0.55, when acting as an HTTP proxy, allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes Apache to incorrectly handle and forward the body of the request in a way that causes the receiving server to process it as a separate HTTP request, aka "HTTP Request Smuggling."</description>
      <reference source="CVE">CVE-2005-2088</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-672" comment="700 Series OS Release 11.04" negate="false"/>
          <criterion test_ref="hst-69" comment="VirusVault is installed" negate="false"/>
          <criterion test_ref="hpt-39" comment="Patch PHSS_34123 or later is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1528" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>tcsh</product>
      </affected>
      <dates>
        <submitted date="2005-04-13-04:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-04-20-04:00">DRAFT</status_change>
        <status_change date="2005-05-11-04:00">INTERIM</status_change>
        <status_change date="2005-06-01-04:00">ACCEPTED</status_change>
        <modified date="2005-08-22-04:00" comment="Affected product changed to tcsh; mistakenly was .NET framework">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2005-08-25-10:03">INTERIM</status_change>
        <status_change date="2005-08-25-10:05">DRAFT</status_change>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Unknown vulnerability in the ls-F builtin function in tcsh on Solaris 8 allows local users to create or delete files as other users, and gain privileges.</description>
      <reference source="CVE">CVE-2003-1024</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="spt-95" comment="Patch 110943-02 or later installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1530" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>HTML Help Facility</product>
      </affected>
      <dates>
        <submitted date="2004-07-13-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <modified date="2004-07-14-12:00" comment="added the unregistered HTML Help criterion to the configuration section of the criteria">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <status_change date="2004-08-04-12:00">INTERIM</status_change>
        <status_change date="2004-08-25-12:00">ACCEPTED</status_change>
        <modified date="2004-09-13-11:37" comment="cmp-66 added">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2004-09-15-12:00">INTERIM</status_change>
        <status_change date="2004-09-29-12:00">ACCEPTED</status_change>
      </dates>
      <description>Heap-based buffer overflow in the HtmlHelp program (hh.exe) in HTML Help for Microsoft Windows 98, Me, NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary commands via a .CHM file with a large length field, a different vulnerability than CVE-2003-1041.</description>
      <reference source="CVE">CVE-2004-0201</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wft-444" comment="the version of itss.dll is less than 5.2.3790.185" negate="false"/>
          <criterion test_ref="wrt-482" comment="the patch kb840315 is installed" negate="true"/>
          <criterion test_ref="cmp-66" comment="Windows XP (sp1 or earlier) is installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-491" comment="HTML Help is registered" negate="true"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1532" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2005-10-12-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-10-19-05:46">DRAFT</status_change>
        <status_change date="2005-11-16-08:02">INTERIM</status_change>
        <status_change date="2005-12-01-06:00">ACCEPTED</status_change>
      </dates>
      <description>netman.dll in Microsoft Windows Connections Manager Library allows local users to cause a denial of service (Network Connections Service crash) via a large integer argument to a particular function.</description>
      <reference source="CVE">CVE-2005-2307</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-2" comment="Windows XP is installed" negate="false"/>
          <criterion test_ref="wrt-250" comment="Win2K/XP/2003 service pack 2 is installed" negate="false"/>
          <criterion test_ref="wft-694" comment="netman.dll is less than 5.1.2600.2743" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1533" class="vulnerability">
      <affected family="hp-ux">
        <hpux:platform>HP-UX 11</hpux:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2006-02-01-11:45">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-03-09-12:19">DRAFT</status_change>
        <status_change date="2006-04-06-06:30">INTERIM</status_change>
        <status_change date="2006-05-03-10:06">ACCEPTED</status_change>
      </dates>
      <description>Unknown vulnerability in HP-UX B.11.00, B.11.04, B.11.11, B.11.22, and B.11.23, when running TCP/IP on IPv4, allows remote attackers to cause a denial of service via certain packets, related to the PMTU, a different vulnerability than CVE-2004-1060.</description>
      <reference source="CVE">CVE-2005-1192</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-618" comment="700 Series or 800 Series OS Release 11.11" negate="false"/>
          <criterion test_ref="hst-58" comment="IPSec.IPSEC2-KRN is installed" negate="false"/>
          <criterion test_ref="cmp-760" comment="IPSec.IPSEC2-KRN version is under A.2.00.01 or TOUR version is under 3.0" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1534" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2006-01-11-12:56">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-01-12-09:18">DRAFT</status_change>
        <modified date="2006-01-17-01:07" comment="Updated reference to CVE-2006-0161, per Rob Hollis.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2006-02-01-09:08">INTERIM</status_change>
        <status_change date="2006-02-22-08:27">ACCEPTED</status_change>
      </dates>
      <description>Unspecified vulnerability in uucp in Sun Solaris 8 and 9 has unknown impact and attack vectors.  NOTE: due to the vagueness of the vendor advisory, it is not clear whether this is related to CVE-2004-0780.</description>
      <reference source="CVE">CVE-2006-0161</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-703" comment="Solaris 8 (SPARC) meets Sun Alert ID 101933 criteria." negate="false"/>
          <criterion test_ref="cmp-704" comment="Solaris 8 (x86) meets Sun Alert ID 101933 criteria." negate="false"/>
          <criterion test_ref="cmp-705" comment="Solaris 9 (SPARC) meets Sun Alert ID 101933 criteria." negate="false"/>
          <criterion test_ref="cmp-612" comment="Solaris 9 (x86) meets Sun Alert ID 101933 criteria." negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1535" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Internet Explorer</product>
      </affected>
      <dates>
        <submitted date="2005-10-12-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-10-19-05:46">DRAFT</status_change>
        <status_change date="2005-11-16-08:02">INTERIM</status_change>
        <status_change date="2005-12-01-06:00">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not intended for use within Internet Explorer, as originally demonstrated using the (1) DDS Library Shape Control (Msdds.dll) COM object, and other objects including (2) Blnmgrps.dll, (3) Ciodm.dll, (4) Comsvcs.dll, (5) Danim.dll, (6) Htmlmarq.ocx, (7) Mdt2dd.dll (as demonstrated using a heap corruption attack with uninitialized memory), (8) Mdt2qd.dll, (9) Mpg4ds32.ax, (10) Msadds32.ax, (11) Msb1esen.dll, (12) Msb1fren.dll, (13) Msb1geen.dll, (14) Msdtctm.dll, (15) Mshtml.dll, (16) Msoeacct.dll, (17) Msosvfbr.dll, (18) Mswcrun.dll, (19) Netshell.dll, (20) Ole2disp.dll, (21) Outllib.dll, (22) Psisdecd.dll, (23) Qdvd.dll, (24) Repodbc.dll, (25) Shdocvw.dll, (26) Shell32.dll, (27) Soa.dll, (28) Srchui.dll, (29) Stobject.dll, (30) Vdt70.dll, (31) Vmhelper.dll, and (32) Wbemads.dll, aka a variant of the "COM Object Instantiation Memory Corruption vulnerability."</description>
      <reference source="CVE">CVE-2005-2127</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
          <criterion test_ref="wrt-432" comment="Win2K/XP/2003 service pack 4 is installed" negate="false"/>
          <criterion test_ref="wft-665" comment="mshtml.dll is less than 5.0.3833.200" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1536" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>NetWare</product>
      </affected>
      <dates>
        <submitted date="2005-10-12-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-10-19-05:46">DRAFT</status_change>
        <status_change date="2005-11-16-08:02">INTERIM</status_change>
        <status_change date="2005-12-01-06:00">ACCEPTED</status_change>
      </dates>
      <description>The Client Service for NetWare (CSNW) on Microsoft Windows 2000 SP4, XP SP1 and Sp2, and Server 2003 SP1 and earlier, allows remote attackers to execute arbitrary code due to an "unchecked buffer" when processing certain crafted network messages.</description>
      <reference source="CVE">CVE-2005-1985</reference>
      <status>ACCEPTED</status>
      <version>4</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
          <criterion test_ref="wrt-432" comment="Win2K/XP/2003 service pack 4 is installed" negate="false"/>
          <criterion test_ref="wft-669" comment="nwwks.dll is less than 5.0.2195.7065" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1537" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2005-10-12-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-10-19-05:46">DRAFT</status_change>
        <status_change date="2005-11-16-08:02">INTERIM</status_change>
        <status_change date="2005-12-01-06:00">ACCEPTED</status_change>
      </dates>
      <description>Windows Shell for Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 allows remote attackers to execute arbitrary commands via a shortcut (.lnk) file with long font properties that lead to a buffer overflow in the Client/Server Runtime Server Subsystem (CSRSS), a different vulnerability than CVE-2005-2118.</description>
      <reference source="CVE">CVE-2005-2122</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wrt-10026" comment="Win2K/XP/2003 is patched" negate="true"/>
          <criterion test_ref="wft-687" comment="shell32.dll is less than 6.0.3790.413" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1538" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Internet Explorer</product>
      </affected>
      <dates>
        <submitted date="2005-10-12-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-10-19-05:46">DRAFT</status_change>
        <status_change date="2005-11-16-08:02">INTERIM</status_change>
        <status_change date="2005-12-01-06:00">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not intended for use within Internet Explorer, as originally demonstrated using the (1) DDS Library Shape Control (Msdds.dll) COM object, and other objects including (2) Blnmgrps.dll, (3) Ciodm.dll, (4) Comsvcs.dll, (5) Danim.dll, (6) Htmlmarq.ocx, (7) Mdt2dd.dll (as demonstrated using a heap corruption attack with uninitialized memory), (8) Mdt2qd.dll, (9) Mpg4ds32.ax, (10) Msadds32.ax, (11) Msb1esen.dll, (12) Msb1fren.dll, (13) Msb1geen.dll, (14) Msdtctm.dll, (15) Mshtml.dll, (16) Msoeacct.dll, (17) Msosvfbr.dll, (18) Mswcrun.dll, (19) Netshell.dll, (20) Ole2disp.dll, (21) Outllib.dll, (22) Psisdecd.dll, (23) Qdvd.dll, (24) Repodbc.dll, (25) Shdocvw.dll, (26) Shell32.dll, (27) Soa.dll, (28) Srchui.dll, (29) Stobject.dll, (30) Vdt70.dll, (31) Vmhelper.dll, and (32) Wbemads.dll, aka a variant of the "COM Object Instantiation Memory Corruption vulnerability."</description>
      <reference source="CVE">CVE-2005-2127</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-613" comment="Win2K or XP,SP1 is installed" negate="false"/>
          <criterion test_ref="cmp-610" comment="a vulnerable version of mshtml.dll exists GDR/QFE" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1541" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Internet Explorer</product>
      </affected>
      <dates>
        <submitted date="2006-04-12-12:55">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-04-12-05:16">DRAFT</status_change>
        <status_change date="2006-05-03-10:06">INTERIM</status_change>
      </dates>
      <description>Microsoft Internet Explorer 5.01 through 6 does not always return the correct IOleClientSite information when dynamically creating an embedded object, which could cause Internet Explorer to run the object in the wrong security context or zone, and allow remote attackers to execute arbitrary code.</description>
      <reference source="CVE">CVE-2006-1190</reference>
      <status>INTERIM</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wrt-4" comment="Win2K/XP/2003 service pack 1 is installed" negate="false"/>
          <criterion test_ref="wft-779" comment="the version of mshtml.dll is less than 6.0.3790.2666" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1542" class="vulnerability">
      <affected family="hp-ux">
        <hpux:platform>HP-UX 11</hpux:platform>
        <product>SecureShell</product>
      </affected>
      <dates>
        <submitted date="2006-01-11-12:55">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-01-12-09:18">DRAFT</status_change>
        <status_change date="2006-02-01-09:08">INTERIM</status_change>
        <status_change date="2006-02-22-08:27">ACCEPTED</status_change>
      </dates>
      <description>zlib 1.2 and later versions allows remote attackers to cause a denial of service (crash) via a crafted compressed stream with an incomplete code description of a length greater than 1, which leads to a buffer overflow, as demonstrated using a crafted PNG file.</description>
      <reference source="CVE">CVE-2005-2096</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-706" comment="700 Series or 800 Series OS Release 11.00 or 11.11" negate="false"/>
          <criterion test_ref="hst-36" comment="Secure_Shell.SECURE_SHELL is installed" negate="false"/>
          <criterion test_ref="hst-34" comment="Secure_Shell.SECURE_SHELL with version less than A.04.20.004 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1543" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Internet Explorer</product>
      </affected>
      <dates>
        <submitted date="2005-12-13-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-12-16-01:03">DRAFT</status_change>
        <status_change date="2006-01-04-08:04">INTERIM</status_change>
        <status_change date="2006-01-25-07:30">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not intended for use within Internet Explorer, aka a variant of the "COM Object Instantiation Memory Corruption Vulnerability," a different vulnerability than CVE-2005-2127.</description>
      <reference source="CVE">CVE-2005-2831</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wrt-10027" comment="Internet Explorer 6 is installed" negate="false"/>
          <criterion test_ref="wft-707" comment="the version of mshtml.dll is less than 6.0.3790.2577" negate="false"/>
          <criterion test_ref="wrt-4" comment="Win2K/XP/2003 service pack 1 is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1544" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>NetWare</product>
      </affected>
      <dates>
        <submitted date="2005-10-12-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-10-19-05:46">DRAFT</status_change>
        <status_change date="2005-11-16-08:02">INTERIM</status_change>
        <status_change date="2005-12-01-06:00">ACCEPTED</status_change>
      </dates>
      <description>The Client Service for NetWare (CSNW) on Microsoft Windows 2000 SP4, XP SP1 and Sp2, and Server 2003 SP1 and earlier, allows remote attackers to execute arbitrary code due to an "unchecked buffer" when processing certain crafted network messages.</description>
      <reference source="CVE">CVE-2005-1985</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wrt-10026" comment="Win2K/XP/2003 is patched" negate="true"/>
          <criterion test_ref="wft-672" comment="nwwks.dll is less than 5.2.3790.386" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1546" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2005-11-09-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-11-10-07:06">DRAFT</status_change>
        <status_change date="2005-12-01-06:00">INTERIM</status_change>
        <status_change date="2005-12-16-01:04">ACCEPTED</status_change>
      </dates>
      <description>Multiple integer overflows in the Graphics Rendering Engine (GDI32.DLL) in Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allow remote attackers to execute arbitrary code via crafted Windows Metafile (WMF) and Enhanced Metafile (EMF) format images that lead to heap-based buffer overflows, as demonstrated using MRBP16::bCheckRecord.</description>
      <reference source="CVE">CVE-2005-2123</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-2" comment="Windows XP is installed" negate="false"/>
          <criterion test_ref="wrt-4" comment="Win2K/XP/2003 service pack 1 is installed" negate="false"/>
          <criterion test_ref="wrt-70" comment="64-Bit version of Windows is installed" negate="true"/>
          <criterion test_ref="cmp-645" comment="version of Gdi32.dll is less than 5.1.2600.1755 OR the version of Mf3216.dll is less than 5.1.2600.1331" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1547" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2006-02-17-07:36">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-02-22-08:27">DRAFT</status_change>
        <status_change date="2006-03-09-12:19">INTERIM</status_change>
        <status_change date="2006-04-06-06:30">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the Web Client service (WebClnt.dll) for Microsoft Windows XP SP1 and SP2, and Server 2003 up to SP1, allows remote authenticated users or Guests to execute arbitrary code via crafted RPC requests, a different vulnerability than CVE-2005-1207.</description>
      <reference source="CVE">CVE-2006-0013</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wrt-10026" comment="Win2K/XP/2003 is patched" negate="true"/>
          <criterion test_ref="wft-763" comment="the version of webclnt.dll is less than 5.2.3790.453 (S03-Gold)" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1549" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Windows Internet Naming Service (WINS)</product>
      </affected>
      <dates>
        <submitted date="2005-01-03-12:00">
          <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
        </submitted>
        <status_change date="2005-01-12-12:41">DRAFT</status_change>
        <status_change date="2005-02-02-12:00">INTERIM</status_change>
        <status_change date="2005-02-23-09:25">ACCEPTED</status_change>
      </dates>
      <description>The WINS service (wins.exe) on Microsoft Windows NT Server 4.0, Windows 2000 Server, and Windows Server 2003 allows remote attackers to write to arbitrary memory locations and possibly execute arbitrary code via a modified memory pointer in a WINS replication packet to TCP port 42, aka the "Association Context Vulnerability."</description>
      <reference source="CVE">CVE-2004-1080</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-34" comment="Microsoft Windows Server 2003 64-Bit Edition " negate="false"/>
          <criterion test_ref="wft-350" comment="the version of wins.exe is less than 5.2.3790.239" negate="false"/>
          <criterion test_ref="wrt-38" comment="the patch KB870763 is installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-98" comment="the wins service is enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1550" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>TIP</product>
      </affected>
      <dates>
        <submitted date="2005-10-12-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-10-19-05:46">DRAFT</status_change>
        <status_change date="2005-11-16-08:02">INTERIM</status_change>
        <status_change date="2005-12-01-06:00">ACCEPTED</status_change>
      </dates>
      <description>Distributed Transaction Controller in Microsoft Windows allows remote servers to cause a denial of service (MSDTC service exception and exit) via an "unexpected protocol command during the reconnection request," which is not properly handled by the Transaction Internet Protocol (TIP) functionality.</description>
      <reference source="CVE">CVE-2005-1979</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wrt-10026" comment="Win2K/XP/2003 is patched" negate="true"/>
          <criterion test_ref="cmp-609" comment="Either ole32.dll or rpcss.dll has a version less than 5.2.3790.374" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1551" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2005-10-12-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-10-19-05:46">DRAFT</status_change>
        <status_change date="2005-11-16-08:02">INTERIM</status_change>
        <status_change date="2005-12-01-06:00">ACCEPTED</status_change>
      </dates>
      <description>Windows Shell for Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 allows remote attackers to execute arbitrary commands via a shortcut (.lnk) file with long font properties that lead to a buffer overflow in the Client/Server Runtime Server Subsystem (CSRSS), a different vulnerability than CVE-2005-2118.</description>
      <reference source="CVE">CVE-2005-2122</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wrt-4" comment="Win2K/XP/2003 service pack 1 is installed" negate="false"/>
          <criterion test_ref="wft-688" comment="shell32.dll is less than 6.0.3790.2534" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1552" class="vulnerability">
      <affected family="hp-ux">
        <hpux:platform>HP-UX 11</hpux:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2006-02-01-11:45">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-03-09-12:19">DRAFT</status_change>
        <status_change date="2006-04-06-06:30">INTERIM</status_change>
        <status_change date="2006-05-03-10:06">ACCEPTED</status_change>
      </dates>
      <description>Unknown vulnerability in HP-UX B.11.00, B.11.04, B.11.11, B.11.22, and B.11.23, when running TCP/IP on IPv4, allows remote attackers to cause a denial of service via certain packets, related to the PMTU, a different vulnerability than CVE-2004-1060.</description>
      <reference source="CVE">CVE-2005-1192</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-688" comment="700 Series OS Release 11.22" negate="false"/>
          <criterion test_ref="hst-57" comment="Networking.NET2-KRN is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1553" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Office</product>
      </affected>
      <dates>
        <submitted date="2006-03-15-10:53">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-03-15-07:17">DRAFT</status_change>
        <status_change date="2006-04-06-06:30">INTERIM</status_change>
        <status_change date="2006-05-03-10:06">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in Microsoft Office 2000 SP3, XP SP3, and other versions and packages, allows user-complicit attackers to execute arbitrary code via a routing slip that is longer than specified by the provided length field.</description>
      <reference source="CVE">CVE-2006-0009</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-10014" comment="Microsoft Office 2000 is installed" negate="false"/>
          <criterion test_ref="wft-770" comment="the version of Winword.exe is less than 9.0.0.8938" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1555" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>PowerPoint</product>
      </affected>
      <dates>
        <submitted date="2006-02-17-07:36">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-02-22-08:27">DRAFT</status_change>
        <status_change date="2006-03-09-12:19">INTERIM</status_change>
        <status_change date="2006-04-06-06:30">ACCEPTED</status_change>
      </dates>
      <description>Microsoft PowerPoint 2000 in Office 2000 SP3 has an interaction with Internet Explorer that allows remote attackers to obtain sensitive information via a PowerPoint presentation that attempts to access objects in the Temporary Internet Files Folder (TIFF).</description>
      <reference source="CVE">CVE-2006-0004</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-644" comment="PowerPoint 2000 is installed" negate="false"/>
          <criterion test_ref="wft-768" comment="the version of PowerPnt.exe is less than 9.0.0.8936" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1558" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Internet Explorer</product>
      </affected>
      <dates>
        <submitted date="2005-12-13-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-12-16-01:03">DRAFT</status_change>
        <status_change date="2006-01-04-08:04">INTERIM</status_change>
        <status_change date="2006-01-25-07:30">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not intended for use within Internet Explorer, aka a variant of the "COM Object Instantiation Memory Corruption Vulnerability," a different vulnerability than CVE-2005-2127.</description>
      <reference source="CVE">CVE-2005-2831</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-212" comment="Windows 2000 Service Pack 4 (or later) is installed" negate="false"/>
          <criterion test_ref="wrt-54" comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false"/>
          <criterion test_ref="wft-704" comment="the version of mshtml.dll is less than 5.0.3835.2200" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1559" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Windows Media Player</product>
      </affected>
      <dates>
        <submitted date="2006-02-17-07:36">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-02-22-08:27">DRAFT</status_change>
        <status_change date="2006-03-09-12:19">INTERIM</status_change>
        <status_change date="2006-04-06-06:30">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the plug-in for Microsoft Windows Media Player (WMP) 9 and 10, when used in browsers other than Internet Explorer and set as the default application to handle media files, allows remote attackers to execute arbitrary code via HTML with an EMBED element containing a long src attribute.</description>
      <reference source="CVE">CVE-2006-0005</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wft-755" comment="the version of Npdsplay.dll is less than 3.0.2.629" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1561" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Windows kernel</product>
      </affected>
      <dates>
        <submitted date="2004-12-16-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2005-01-12-12:00">DRAFT</status_change>
        <status_change date="2005-02-02-12:00">INTERIM</status_change>
        <status_change date="2005-02-23-12:00">ACCEPTED</status_change>
        <modified date="2005-06-17-12:00" comment="modified cmp-1106 - Replaced the test that checks for the service pack level, instead of checking for sp4 or ealier (did not check for GOLD edition) it is now negating the test that checks for sp5 for later.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <status_change date="2005-06-22-12:35">INTERIM</status_change>
        <status_change date="2005-07-27-10:37">ACCEPTED</status_change>
      </dates>
      <description>The Local Procedure Call (LPC) interface of the Windows Kernel for Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 does not properly validate the lengths of messages sent to the LPC port, which allows local users to gain privileges, aka "Windows Kernel Vulnerability."</description>
      <reference source="CVE">CVE-2004-0893</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1106" comment="Windows 2000 (sp4 or earlier) is installed" negate="false"/>
          <criterion test_ref="wft-148" comment="The version of Ntoskrnl.exe is less than 5.0.2195.6992" negate="false"/>
          <criterion test_ref="wrt-36" comment="the patch kb885835is installed (Hotfix key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1562" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>mozilla</product>
      </affected>
      <dates>
        <submitted date="2006-02-07-06:13">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-02-22-08:27">DRAFT</status_change>
        <status_change date="2006-03-09-12:19">INTERIM</status_change>
        <status_change date="2006-04-06-06:30">ACCEPTED</status_change>
      </dates>
      <description>Mozilla Firefox 1.5, Thunderbird 1.5 if Javascript is enabled in mail, and SeaMonkey before 1.0 might allow remote attackers to execute arbitrary code via the QueryInterface method of the built-in Location and Navigator objects, which leads to memory corruption.</description>
      <reference source="CVE">CVE-2006-0295</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-744" comment="Mozilla Firefox version 1.5 is installed and has NOT been patched with version 1.5.0.1" negate="false"/>
          <criterion test_ref="cmp-747" comment="A pre-release of SeaMonkey 1.0 is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1563" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows ME</windows:platform>
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Internet Explorer 6 SP1</product>
      </affected>
      <dates>
        <submitted date="2004-10-25-04:59">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2004-10-27-01:04">DRAFT</status_change>
        <status_change date="2004-11-17-10:00">INTERIM</status_change>
        <status_change date="2004-12-09-08:46">ACCEPTED</status_change>
        <modified date="2005-09-27-10:50" comment="modified wft-564 - Changed test to match comment">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-28-01:04">INTERIM</status_change>
        <status_change date="2005-10-19-05:47">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer in Windows XP SP2, and other versions including 5.01 and 5.5, allows remote attackers to install arbitrary programs via a web page that uses certain styles and the AnchorClick behavior, popup windows, and drag-and-drop capabilities to drop the program in the local startup folder, as demonstrated by "wottapoop.html".</description>
      <reference source="CVE">CVE-2004-0839</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-50" comment="Internet Explorer 6 Service Pack 1 is installed" negate="false"/>
          <criterion test_ref="wft-564" comment="the version of mshtml.dll is less than 6.0.2800.1476   " negate="false"/>
          <criterion test_ref="wrt-561" comment="the patch kb834707 is installed (Installed Components key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1564" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2006-01-07-07:15">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-01-12-09:25">DRAFT</status_change>
        <status_change date="2006-02-01-09:08">INTERIM</status_change>
        <status_change date="2006-02-22-08:27">ACCEPTED</status_change>
      </dates>
      <description>The Windows Graphical Device Interface library (GDI32.DLL) in Microsoft Windows allows remote attackers to execute arbitrary code via a Windows Metafile (WMF) format image with a crafted SETABORTPROC GDI Escape function call, related to the Windows Picture and Fax Viewer (SHIMGVW.DLL), a different vulnerability than CVE-2005-2123 and CVE-2005-2124, and as originally discovered in the wild on unionseek.com.</description>
      <reference source="CVE">CVE-2005-4560</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-2" comment="Windows XP is installed" negate="false"/>
          <criterion test_ref="wrt-4" comment="Win2K/XP/2003 service pack 1 is installed" negate="false"/>
          <criterion test_ref="wrt-70" comment="64-Bit version of Windows is installed" negate="true"/>
          <criterion test_ref="wft-719" comment="the version of Gdi32.dll is less than 5.1.2600.1789" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1566" class="vulnerability">
      <affected family="hp-ux">
        <hpux:platform>HP-UX 11</hpux:platform>
        <product>SecureShell</product>
      </affected>
      <dates>
        <submitted date="2006-01-11-12:55">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-01-12-09:18">DRAFT</status_change>
        <status_change date="2006-02-01-09:08">INTERIM</status_change>
        <status_change date="2006-02-22-08:27">ACCEPTED</status_change>
      </dates>
      <description>sshd in OpenSSH before 4.2, when GSSAPIDelegateCredentials is enabled, allows GSSAPI credentials to be delegated to clients who log in using non-GSSAPI methods, which could cause those credentials to be exposed to untrusted users or hosts.</description>
      <reference source="CVE">CVE-2005-2798</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-706" comment="700 Series or 800 Series OS Release 11.00 or 11.11" negate="false"/>
          <criterion test_ref="hst-36" comment="Secure_Shell.SECURE_SHELL is installed" negate="false"/>
          <criterion test_ref="hst-34" comment="Secure_Shell.SECURE_SHELL with version less than A.04.20.004 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1568" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Windows Media Player 9</product>
      </affected>
      <dates>
        <submitted date="2005-02-22-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <modified date="2005-02-22-11:11" comment="changed product affected">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <modified date="2005-02-22-11:18" comment="modified wrt-169 - fixed version">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <modified date="2005-02-22-11:20" comment="modified wrt-169 - fixed pattern match">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <modified date="2005-02-22-11:32" comment="modified wrt-174 - modified name">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <modified date="2005-02-22-11:35" comment="modified wrt-175 - modified name">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <modified date="2005-02-22-01:35" comment="modified wrt-176 - modified name">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <modified date="2005-02-22-01:40" comment="modified wrt-177 - modified name">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <modified date="2005-02-22-01:51" comment="modified wrt-178 - modified name ">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-02-23-08:48">DRAFT</status_change>
        <status_change date="2005-03-23-08:09">INTERIM</status_change>
        <status_change date="2005-04-13-12:15">ACCEPTED</status_change>
      </dates>
      <description>Windows Media Player 9 allows remote attackers to execute arbitrary code via a PNG file containing large (1) width or (2) height values, aka the "PNG Processing Vulnerability."</description>
      <reference source="CVE">CVE-2004-1244</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-82" comment="Windows Media Player 9.0 installed" negate="false"/>
          <criterion test_ref="wft-374" comment="the version of wmp.dll is les than 9.0.0.3250" negate="false"/>
          <criterion test_ref="wrt-167" comment="The patch KB885492 is installed on Windows Server 2003" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-188" comment="The files .asx, .wax, .wvx, .wpl, .wmx, .wms, .wmz EXIST" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1569" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Internet Explorer</product>
      </affected>
      <dates>
        <submitted date="2006-04-12-12:55">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-04-12-05:16">DRAFT</status_change>
        <status_change date="2006-05-03-10:06">INTERIM</status_change>
      </dates>
      <description>Buffer overflow in mshtml.dll in Microsoft Internet Explorer 6.0.2900.2180, and probably other versions, allows remote attackers to execute arbitrary code via an HTML tag with a large number of script action handlers such as onload and onmouseover, as demonstrated using onclick, aka the "Multiple Event Handler Memory Corruption Vulnerability."</description>
      <reference source="CVE">CVE-2006-1245</reference>
      <status>INTERIM</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-613" comment="Win2K or XP,SP1 is installed" negate="false"/>
          <criterion test_ref="wrt-652" comment="Internet Explorer 6 (any patch level) is installed" negate="false"/>
          <criterion test_ref="wft-776" comment="the version of mshtml.dll is less than 6.0.2800.1543" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1570" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Office</product>
      </affected>
      <dates>
        <submitted date="2006-03-15-10:53">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-03-15-07:17">DRAFT</status_change>
        <status_change date="2006-04-06-06:31">INTERIM</status_change>
        <status_change date="2006-05-03-10:06">ACCEPTED</status_change>
      </dates>
      <description>Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-complicit attackers to execute arbitrary code via an Excel file with a malformed description, which leads to memory corruption.</description>
      <reference source="CVE">CVE-2006-0029</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wft-774" comment="Xlview.exe is installed with a version less than 11.0.8012.0" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1572" class="vulnerability">
      <affected family="hp-ux">
        <hpux:platform>HP-UX 11</hpux:platform>
        <product>envd</product>
      </affected>
      <dates>
        <submitted date="2005-11-30-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-12-20-11:03">DRAFT</status_change>
        <status_change date="2006-01-04-08:04">INTERIM</status_change>
        <status_change date="2006-01-25-07:30">ACCEPTED</status_change>
      </dates>
      <description>envd daemon in HP-UX B.11.00 through B.11.11 allows local users to obtain privileges via unknown attack vectors.</description>
      <reference source="CVE">CVE-2005-3564</reference>
      <status>ACCEPTED</status>
      <version>5</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-618" comment="700 Series or 800 Series OS Release 11.11" negate="false"/>
          <criterion test_ref="cmp-678" comment="OS-Core.CORE-ENG-A-MAN or OS-Core.UX-CORE (B.11.11) is installed" negate="false"/>
          <criterion test_ref="hpt-10" comment="Patch PHCO_33967 or later is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1576" class="vulnerability">
      <affected family="hp-ux">
        <hpux:platform>HP-UX 11</hpux:platform>
        <product>remshd</product>
      </affected>
      <dates>
        <submitted date="2005-11-30-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-12-20-11:03">DRAFT</status_change>
        <status_change date="2006-01-04-08:04">INTERIM</status_change>
        <status_change date="2006-01-25-07:30">ACCEPTED</status_change>
      </dates>
      <description>Unknown vulnerability in remshd daemon in HP-UX B.11.00, B.11.11, and B.11.23 while running in "Trusted Mode" allows remote attackers to gain unauthorized system access via unknown attack vectors.</description>
      <reference source="CVE">CVE-2005-3565</reference>
      <status>ACCEPTED</status>
      <version>5</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-682" comment="700 Series or 800 Series OS Release 11.23" negate="false"/>
          <criterion test_ref="cmp-683" comment="InternetSrvcs.INETSVCS2-RUN or InternetSrvcs.INET-ENG-A-MAN (B.11.23) is installed" negate="false"/>
          <criterion test_ref="hpt-14" comment="Patch PHNE_33792 or later is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1577" class="vulnerability">
      <affected family="hp-ux">
        <hpux:platform>HP-UX 11</hpux:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2006-01-30-07:20">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-02-01-09:08">DRAFT</status_change>
        <status_change date="2006-02-22-08:27">INTERIM</status_change>
        <status_change date="2006-03-09-12:19">ACCEPTED</status_change>
      </dates>
      <description>Unspecified vulnerability in HP HP-UX B.11.00, B.11.04, and B.11.11 allows local users to gain privileges via unknown attack vectors.</description>
      <reference source="CVE">CVE-2006-0436</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-619" comment="700 Series or 800 Series OS Release 11.00" negate="false"/>
          <criterion test_ref="hpt-36" comment="Patch PHCO_29249 or later is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1578" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Windows Media Player</product>
      </affected>
      <dates>
        <submitted date="2006-02-17-07:36">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-02-22-08:27">DRAFT</status_change>
        <status_change date="2006-03-09-12:19">INTERIM</status_change>
        <status_change date="2006-04-06-06:30">ACCEPTED</status_change>
      </dates>
      <description>Heap-based buffer overflow in the bitmap processing routine in Microsoft Windows Media Player 7.1 on Windows 2000 SP4, Media Player 9 on Windows 200 SP4 and XP SP1, and Media Player 10 on XP SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted bitmap (.BMP) file that specifies a size of 0 but contains additional data.</description>
      <reference source="CVE">CVE-2006-0006</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-10030" comment="Windows Media Player 7.1 is installed" negate="false"/>
          <criterion test_ref="wft-743" comment="the version of Wmpui.dll is less than 7.10.0.3077" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1579" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Office</product>
      </affected>
      <dates>
        <submitted date="2006-03-15-10:53">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-03-15-07:17">DRAFT</status_change>
        <status_change date="2006-04-06-06:30">INTERIM</status_change>
        <status_change date="2006-05-03-10:06">ACCEPTED</status_change>
      </dates>
      <description>Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-complicit attackers to execute arbitrary code via an Excel file with a malformed description, which leads to memory corruption.</description>
      <reference source="CVE">CVE-2006-0029</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-650" comment="Excel 2003 is installed" negate="false"/>
          <criterion test_ref="wft-773" comment="the version of excel.exe is less than 11.0.8012.0" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1580" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 10</solaris:platform>
        <product>X</product>
      </affected>
      <dates>
        <submitted date="2006-02-19-05:38">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-02-22-08:27">DRAFT</status_change>
        <status_change date="2006-03-09-12:19">INTERIM</status_change>
        <status_change date="2006-04-06-06:30">ACCEPTED</status_change>
      </dates>
      <description>Unspecified vulnerability in in.rexecd in Solaris 10 allows local users to gain privileges on Kerberos systems via unknown attack vectors.</description>
      <reference source="CVE">CVE-2006-0769</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-758" comment="Solaris 10 (SPARC) meets Sun Alert ID 102186 criteria." negate="false"/>
          <criterion test_ref="cmp-759" comment="Solaris 10 (x86) meets Sun Alert ID 102186 criteria." negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="tft-15" comment="Target is configured to reference pam_krb5" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1581" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Windows kernel</product>
      </affected>
      <dates>
        <submitted date="2005-01-05-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2005-01-06-09:32">DRAFT</status_change>
        <status_change date="2005-02-02-12:00">INTERIM</status_change>
        <status_change date="2005-02-23-09:25">ACCEPTED</status_change>
      </dates>
      <description>The Local Procedure Call (LPC) interface of the Windows Kernel for Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 does not properly validate the lengths of messages sent to the LPC port, which allows local users to gain privileges, aka "Windows Kernel Vulnerability."</description>
      <reference source="CVE">CVE-2004-0893</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wft-160" comment="the version of lsasrv.dll is less than 5.2.3790.220" negate="false"/>
          <criterion test_ref="wrt-36" comment="the patch kb885835is installed (Hotfix key)" negate="true"/>
          <criterion test_ref="cmp-34" comment="Microsoft Windows Server 2003 64-Bit Edition " negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1582" class="vulnerability">
      <affected family="hp-ux">
        <hpux:platform>HP-UX 11</hpux:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2006-01-30-07:20">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-02-01-09:08">DRAFT</status_change>
        <status_change date="2006-02-22-08:27">INTERIM</status_change>
        <status_change date="2006-03-09-12:19">ACCEPTED</status_change>
      </dates>
      <description>Unknown vulnerability in the login page for HP Systems Insight Manager (SIM) 4.0 and 4.1, when accessed by Microsoft Internet Explorer with the MS04-025 patch, leads to a denial of service (browser hang). NOTE: although the advisory is vague, this issue does not appear to involve an attacker at all.  If not, then this issue is not a vulnerability.</description>
      <reference source="CVE">CVE-2005-3983</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="hst-55" comment="SysMgmtServer.MX-PORTAL (C.04.00.00.00) is installed" negate="false"/>
          <criterion test_ref="hst-56" comment="SysMgmtServer.MX-PORTAL (C.04.01.00.00) is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1583" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2005-12-13-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-12-16-01:03">DRAFT</status_change>
        <status_change date="2006-01-04-08:04">INTERIM</status_change>
        <status_change date="2006-01-25-07:30">ACCEPTED</status_change>
      </dates>
      <description>The thread termination routine in the kernel for Windows NT 4.0 and 2000 (NTOSKRNL.EXE) allows local users to modify kernel memory and execution flow via steps in which a terminating thread causes Asynchronous Procedure Call (APC) entries to free the wrong data, aka the "Windows Kernel Vulnerability."</description>
      <reference source="CVE">CVE-2005-2827</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
          <criterion test_ref="wft-709" comment="The version of Ntkrnlpa.exe is less than 5.0.2195.7071" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1586" class="vulnerability">
      <affected family="hp-ux">
        <hpux:platform>HP-UX 11</hpux:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2006-01-30-07:20">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-02-01-09:08">DRAFT</status_change>
        <status_change date="2006-02-22-08:27">INTERIM</status_change>
        <status_change date="2006-03-09-12:19">ACCEPTED</status_change>
      </dates>
      <description>Unspecified vulnerability in HP HP-UX B.11.00, B.11.04, and B.11.11 allows local users to gain privileges via unknown attack vectors.</description>
      <reference source="CVE">CVE-2006-0436</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-671" comment="InternetSrvcs.INETSVCS-RUN, InternetSrvcs.INET-ENG-A-MAN, or VirtualVaultOS.VVOS-AUX-IA (B.11.04) is installed" negate="false"/>
          <criterion test_ref="hpt-37" comment="Patch PHCO_32280 or later is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1589" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Internet Explorer</product>
      </affected>
      <dates>
        <submitted date="2006-04-12-12:55">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-04-12-05:16">DRAFT</status_change>
        <status_change date="2006-05-03-10:06">INTERIM</status_change>
      </dates>
      <description>Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via by instantiating the (1) Mdt2gddr.dll, (2) Mdt2dd.dll, and (3) Mdt2gddo.dll COM objects as ActiveX controls, which leads to memory corruption.</description>
      <reference source="CVE">CVE-2006-1186</reference>
      <status>INTERIM</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-613" comment="Win2K or XP,SP1 is installed" negate="false"/>
          <criterion test_ref="wrt-652" comment="Internet Explorer 6 (any patch level) is installed" negate="false"/>
          <criterion test_ref="wft-776" comment="the version of mshtml.dll is less than 6.0.2800.1543" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1591" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Internet Explorer</product>
      </affected>
      <dates>
        <submitted date="2006-04-12-12:55">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-04-12-05:16">DRAFT</status_change>
        <status_change date="2006-05-03-10:06">INTERIM</status_change>
      </dates>
      <description>Unspecified vulnerability in Microsoft Internet Explorer 6.0 allows remote attackers to execute HTA files via unknown vectors.</description>
      <reference source="CVE">CVE-2006-1388</reference>
      <status>INTERIM</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-692" comment="Windows XP (64-bit,SP1 or 32-bit,SP2) is installed" negate="false"/>
          <criterion test_ref="wft-777" comment="the version of mshtml.dll is less than 6.0.2900.2873" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1595" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2006-02-17-07:36">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-02-22-08:27">DRAFT</status_change>
        <status_change date="2006-03-09-12:19">INTERIM</status_change>
        <status_change date="2006-04-06-06:30">ACCEPTED</status_change>
      </dates>
      <description>The ShellAbout API call in Korean Input Method Editor (IME) in Korean versions of Microsoft Windows XP SP1 and SP2, Windows Server 2003 up to SP1, and Office 2003, allows local users to gain privileges by launching the "shell about dialog box" and clicking the "End-User License Agreement" link, which executes Notepad with the privileges of the program that displays the about box.</description>
      <reference source="CVE">CVE-2006-0008</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-2" comment="Windows XP is installed" negate="false"/>
          <criterion test_ref="wrt-4" comment="Win2K/XP/2003 service pack 1 is installed" negate="false"/>
          <criterion test_ref="wrt-70" comment="64-Bit version of Windows is installed" negate="false"/>
          <criterion test_ref="wft-766" comment="the version of Imekr61.ime is less than 6.2.2551.0 (64-bit)" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1597" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Internet Explorer</product>
      </affected>
      <dates>
        <submitted date="2005-12-13-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-12-16-01:03">DRAFT</status_change>
        <status_change date="2006-01-04-08:04">INTERIM</status_change>
        <status_change date="2006-01-25-07:30">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not intended for use within Internet Explorer, aka a variant of the "COM Object Instantiation Memory Corruption Vulnerability," a different vulnerability than CVE-2005-2127.</description>
      <reference source="CVE">CVE-2005-2831</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-613" comment="Win2K or XP,SP1 is installed" negate="false"/>
          <criterion test_ref="wrt-50" comment="Internet Explorer 6 Service Pack 1 is installed" negate="false"/>
          <criterion test_ref="wft-705" comment="the version of mshtml.dll is less than 6.0.2800.1528" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1598" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Windows Media Player</product>
      </affected>
      <dates>
        <submitted date="2006-02-17-07:36">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-02-22-08:27">DRAFT</status_change>
        <status_change date="2006-03-09-12:19">INTERIM</status_change>
        <status_change date="2006-04-06-06:30">ACCEPTED</status_change>
      </dates>
      <description>Heap-based buffer overflow in the bitmap processing routine in Microsoft Windows Media Player 7.1 on Windows 2000 SP4, Media Player 9 on Windows 200 SP4 and XP SP1, and Media Player 10 on XP SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted bitmap (.BMP) file that specifies a size of 0 but contains additional data.</description>
      <reference source="CVE">CVE-2006-0006</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-646" comment="Windows Media Player 10 is installed" negate="false"/>
          <criterion test_ref="wft-746" comment="the version of Wmp.dll is less than 10.0.0.3990" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1599" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Internet Explorer</product>
      </affected>
      <dates>
        <submitted date="2006-04-12-12:55">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-04-12-05:16">DRAFT</status_change>
        <status_change date="2006-05-03-10:06">INTERIM</status_change>
      </dates>
      <description>Buffer overflow in mshtml.dll in Microsoft Internet Explorer 6.0.2900.2180, and probably other versions, allows remote attackers to execute arbitrary code via an HTML tag with a large number of script action handlers such as onload and onmouseover, as demonstrated using onclick, aka the "Multiple Event Handler Memory Corruption Vulnerability."</description>
      <reference source="CVE">CVE-2006-1245</reference>
      <status>INTERIM</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-692" comment="Windows XP (64-bit,SP1 or 32-bit,SP2) is installed" negate="false"/>
          <criterion test_ref="wft-777" comment="the version of mshtml.dll is less than 6.0.2900.2873" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1601" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows ME</windows:platform>
        <product>Windows Shell</product>
      </affected>
      <dates>
        <submitted date="2004-10-14-03:37">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <status_change date="2004-10-20-02:35">DRAFT</status_change>
        <status_change date="2004-11-03-12:00">INTERIM</status_change>
        <status_change date="2004-12-09-08:46">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in Microsoft Internet Explorer and Explorer on Windows XP SP1, WIndows 2000, Windows 98, and Windows Me may allow remote malicious servers to cause a denial of service (application crash) and possibly execute arbitrary code via long share names, as demonstrated using Samba.</description>
      <reference source="CVE">CVE-2004-0214</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-550" comment="Windows ME Installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1602" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2006-02-17-07:36">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-02-22-08:27">DRAFT</status_change>
        <status_change date="2006-03-09-12:19">INTERIM</status_change>
        <status_change date="2006-04-06-06:30">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the Web Client service (WebClnt.dll) for Microsoft Windows XP SP1 and SP2, and Server 2003 up to SP1, allows remote authenticated users or Guests to execute arbitrary code via crafted RPC requests, a different vulnerability than CVE-2005-1207.</description>
      <reference source="CVE">CVE-2006-0013</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-2" comment="Windows XP is installed" negate="false"/>
          <criterion test_ref="wrt-250" comment="Win2K/XP/2003 service pack 2 is installed" negate="false"/>
          <criterion test_ref="wft-761" comment="the version of webclnt.dll is less than 5.1.2600.2821 (XP,SP2)" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1603" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>HyperTerminal</product>
      </affected>
      <dates>
        <submitted date="2004-12-17-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2005-01-18-12:00">DRAFT</status_change>
        <modified date="2005-01-27-12:00" comment="Change OS test to include XP gold in addition to XP SP1">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </modified>
        <modified date="2005-03-02-12:00" comment="modified wft-175 - Access DLL via HKLM">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </modified>
        <status_change date="2005-03-23-12:00">INTERIM</status_change>
        <modified date="2005-03-29-12:00" comment="modified wrt-45 - deleted an extra space after Filelist">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <modified date="2005-04-22-12:00" comment="modified wrt-45 - Removed extra space between 'Windows XP' in the key field">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </modified>
        <status_change date="2005-05-11-05:41">ACCEPTED</status_change>
      </dates>
      <description>HyperTerminal application for Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 does not properly validate the length of a value that is saved in a session file, which allows remote attackers to execute arbitrary code via a malicious HyperTerminal session file (.ht), web site, or Telnet URL contained in an e-mail message, triggering a buffer overflow.</description>
      <reference source="CVE">CVE-2004-0568</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wft-175" comment="the version of hypertrm.dll is less than 5.1.2600.1609" negate="false"/>
          <criterion test_ref="wrt-45" comment="the patch WindowsXP-KB87339-x86-ENU.exe is installed " negate="false"/>
          <criterion test_ref="cmp-66" comment="Windows XP (sp1 or earlier) is installed" negate="false"/>
        </software>
        <configuration operation="OR">
          <criterion test_ref="wrt-39" comment="If key present hyperterminal will automatically open session files" negate="false"/>
          <criterion test_ref="wrt-67" comment="If the Hyperterminal client is registered as the default telnet client" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1606" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>SMB (Server Message Block)</product>
      </affected>
      <dates>
        <submitted date="2005-02-15-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2005-02-18-10:39">DRAFT</status_change>
        <status_change date="2005-03-09-07:56">INTERIM</status_change>
        <status_change date="2005-03-29-07:59">ACCEPTED</status_change>
      </dates>
      <description>The Server Message Block (SMB) implementation for Windows NT 4.0, 2000, XP, and Server 2003 does not properly validate certain SMB packets, which allows remote attackers to execute arbitrary code via Transaction responses containing (1) Trans or (2) Trans2 commands, aka the "Server Message Block Vulnerability," and as demonstrated using Trans2 FIND_FIRST2 responses with large file name length fields.</description>
      <reference source="CVE">CVE-2005-0045</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-35" comment="Windows XP 32 bit Service Pack 2" negate="false"/>
          <criterion test_ref="wft-380" comment="the version of mrxsmb.sys is less than 5.1.2600.2598" negate="false"/>
          <criterion test_ref="wrt-90" comment="the patch KB885250 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1607" class="vulnerability">
      <affected family="hp-ux">
        <hpux:platform>HP-UX 11</hpux:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2006-02-01-11:45">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-03-09-12:19">DRAFT</status_change>
        <status_change date="2006-04-06-06:30">INTERIM</status_change>
        <status_change date="2006-05-03-10:06">ACCEPTED</status_change>
      </dates>
      <description>Unknown vulnerability in HP-UX B.11.00, B.11.04, B.11.11, B.11.22, and B.11.23, when running TCP/IP on IPv4, allows remote attackers to cause a denial of service via certain packets, related to the PMTU, a different vulnerability than CVE-2004-1060.</description>
      <reference source="CVE">CVE-2005-1192</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-618" comment="700 Series or 800 Series OS Release 11.11" negate="false"/>
          <criterion test_ref="hst-57" comment="Networking.NET2-KRN is installed" negate="false"/>
          <criterion test_ref="hpt-22" comment="Patch PHNE_33159 or later is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1608" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 10</solaris:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2006-01-12-11:25">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-01-25-07:30">DRAFT</status_change>
        <status_change date="2006-02-22-08:27">INTERIM</status_change>
        <status_change date="2006-03-09-12:19">ACCEPTED</status_change>
      </dates>
      <description>Unspecified vulnerability in Sun Solaris 10 allows local users to cause a denial of service (null dereference) via unspecified vectors involving the use of the find command on the "/proc" filesystem. NOTE: due to the vagueness of the vendor advisory, it is not clear whether this is related to CVE-2005-3250.</description>
      <reference source="CVE">CVE-2006-0191</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-715" comment="Solaris 10 (sparc) meets Sun Alert ID 102108 criteria." negate="false"/>
          <criterion test_ref="cmp-714" comment="Solaris 10 (x86) meets Sun Alert ID 102066 and 102108 criteria." negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1611" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Outlook Express</product>
      </affected>
      <dates>
        <submitted date="2006-04-12-12:55">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-04-12-05:16">DRAFT</status_change>
        <status_change date="2006-05-03-10:06">INTERIM</status_change>
      </dates>
      <description>Buffer overflow in Microsoft Outlook Express 5.5 and 6 allows remote attackers to execute arbitrary code via a crafted Windows Address Book (WAB) file containing "certain Unicode strings" and modified length values.</description>
      <reference source="CVE">CVE-2006-0014</reference>
      <status>INTERIM</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-2" comment="Windows XP is installed" negate="false"/>
          <criterion test_ref="wrt-250" comment="Win2K/XP/2003 service pack 2 is installed" negate="false"/>
          <criterion test_ref="wrt-10004" comment="Outlook Express 6.0 is installed" negate="false"/>
          <criterion test_ref="wft-795" comment="the version of inetcomm.dll is less than 6.0.2900.2869" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1612" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2006-01-07-07:15">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-01-12-09:25">DRAFT</status_change>
        <status_change date="2006-02-01-09:08">INTERIM</status_change>
        <status_change date="2006-02-22-08:27">ACCEPTED</status_change>
      </dates>
      <description>The Windows Graphical Device Interface library (GDI32.DLL) in Microsoft Windows allows remote attackers to execute arbitrary code via a Windows Metafile (WMF) format image with a crafted SETABORTPROC GDI Escape function call, related to the Windows Picture and Fax Viewer (SHIMGVW.DLL), a different vulnerability than CVE-2005-2123 and CVE-2005-2124, and as originally discovered in the wild on unionseek.com.</description>
      <reference source="CVE">CVE-2005-4560</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wrt-10026" comment="Win2K/XP/2003 is patched" negate="true"/>
          <criterion test_ref="wft-721" comment="the version of Gdi32.dll is less than 5.2.3790.462" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1617" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2006-03-21-04:03">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-03-22-11:10">DRAFT</status_change>
        <status_change date="2006-04-06-06:31">INTERIM</status_change>
        <status_change date="2006-05-03-10:06">ACCEPTED</status_change>
      </dates>
      <description>Integer overflow in pixbuf_create_from_xpm (io-xpm.c) in the XPM image decoder for gtk+ 2.4.4 (gtk2) and earlier, and gdk-pixbuf before 0.22, allows remote attackers to execute arbitrary code via certain n_col and cpp values that enable a heap-based buffer overflow.  NOTE: this identifier is ONLY for gtk+.  It was incorrectly referenced in an advisory for a different issue (CVE-2004-0687).</description>
      <reference source="CVE">CVE-2004-0782</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-792" comment="GNOME 2.0 Solaris 8 (SPARC) meets Sun Alert ID 101776 criteria." negate="false"/>
          <criterion test_ref="cmp-793" comment="GNOME 2.0 Solaris 8 (x86) meets Sun Alert ID 101776 criteria." negate="false"/>
          <criterion test_ref="cmp-794" comment="GNOME 2.0 Solaris 9 (SPARC) meets Sun Alert ID 101776 criteria." negate="false"/>
          <criterion test_ref="cmp-795" comment="GNOME 2.0.2 Solaris 9 (SPARC) meets Sun Alert ID 101776 criteria." negate="false"/>
          <criterion test_ref="cmp-796" comment="GNOME 2.0 Solaris 9 (x86) meets Sun Alert ID 101776 criteria." negate="false"/>
          <criterion test_ref="cmp-797" comment="GNOME 2.0.2 Solaris 9 (x86) meets Sun Alert ID 101776 criteria." negate="false"/>
          <criterion test_ref="cmp-798" comment="Solaris 9 (x86) with JDS release 2 meets Sun Alert ID 101776 criteria." negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1618" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <solaris:platform>Sun Solaris 10</solaris:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2006-03-04-10:16">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-03-09-12:19">DRAFT</status_change>
        <status_change date="2006-04-06-06:30">INTERIM</status_change>
        <status_change date="2006-05-03-10:06">ACCEPTED</status_change>
      </dates>
      <description>'An undisclosed vulnerability in the pagedata subsystem in /proc may allow a local unprivileged user to cause significant performance degradation and even panic the system.'</description>
      <reference source="MISC">http://sunsolve9.sun.com/search/document.do?assetkey=1-26-102159-1&amp;amp;searchclause=</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-771" comment="Solaris 8 (SPARC) meets Sun Alert ID 102159 criteria." negate="false"/>
          <criterion test_ref="cmp-772" comment="Solaris 9 (SPARC) meets Sun Alert ID 102159 criteria." negate="false"/>
          <criterion test_ref="cmp-773" comment="Solaris 10 (SPARC) meets Sun Alert ID 102159 criteria." negate="false"/>
          <criterion test_ref="cmp-774" comment="Solaris 8 (x86) meets Sun Alert ID 102159 criteria." negate="false"/>
          <criterion test_ref="cmp-775" comment="Solaris 9 (x86) meets Sun Alert ID 102159 criteria." negate="false"/>
          <criterion test_ref="cmp-776" comment="Solaris 10 (x86) meets Sun Alert ID 102159 criteria." negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1619" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>mozilla</product>
        <product>Firefox</product>
      </affected>
      <dates>
        <submitted date="2006-01-07-07:15">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-01-12-09:21">DRAFT</status_change>
        <modified date="2006-01-26-01:41" comment="Updated reference to CVE-2005-4134">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <modified date="2006-02-01-05:57" comment="Changed affected products to Firefox, Mozilla.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <modified date="2006-02-07-06:26" comment="Updated criteria to reflect Mozilla Security Advisories dated February 1, 2006">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </modified>
        <status_change date="2006-02-22-08:27">INTERIM</status_change>
        <status_change date="2006-03-09-12:19">ACCEPTED</status_change>
      </dates>
      <description>Mozilla Firefox 1.5, Netscape 8.0.4 and 7.2, and K-Meleon before 0.9.12 allows remote attackers to cause a denial of service (CPU consumption and delayed application startup) via a web site with a large title, which is recorded in history.dat but not processed efficiently during startup.  NOTE: despite initial reports, the Mozilla vendor does not believe that this issue can be used to trigger a crash or buffer overflow in Firefox.  Also, it has been independently reported that Netscape 8.1 does not have this issue.</description>
      <reference source="CVE">CVE-2005-4134</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-748" comment="Mozilla Firefox pre-1.5 is installed" negate="false"/>
          <criterion test_ref="cmp-744" comment="Mozilla Firefox version 1.5 is installed and has NOT been patched with version 1.5.0.1" negate="false"/>
          <criterion test_ref="cmp-746" comment="Mozilla Suite is installed" negate="false"/>
          <criterion test_ref="cmp-747" comment="A pre-release of SeaMonkey 1.0 is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1625" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>mozilla</product>
      </affected>
      <dates>
        <submitted date="2006-02-07-06:13">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-02-22-08:27">DRAFT</status_change>
        <status_change date="2006-03-09-12:19">INTERIM</status_change>
        <status_change date="2006-04-06-06:30">ACCEPTED</status_change>
      </dates>
      <description>The E4X implementation in Mozilla Firefox before 1.5.0.1, Thunderbird 1.5 if running Javascript in mail, and SeaMonkey before 1.0 exposes the internal "AnyName" object to external interfaces, which allows multiple cooperating domains to exchange information in violation of the same origin restrictions.</description>
      <reference source="CVE">CVE-2006-0299</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-744" comment="Mozilla Firefox version 1.5 is installed and has NOT been patched with version 1.5.0.1" negate="false"/>
          <criterion test_ref="cmp-747" comment="A pre-release of SeaMonkey 1.0 is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1628" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <solaris:platform>Sun Solaris 10</solaris:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2006-02-26-12:31">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-03-09-12:19">DRAFT</status_change>
        <status_change date="2006-04-06-06:30">INTERIM</status_change>
        <status_change date="2006-05-03-10:06">ACCEPTED</status_change>
      </dates>
      <description>Unspecified vulnerability in the hsfs filesystem in Solaris 8, 9, and 10 allows unspecified attackers to cause a denial of service (panic) or execute arbitrary code.</description>
      <reference source="CVE">CVE-2006-0901</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-763" comment="Solaris 8 (SPARC) meets Sun Alert ID 102161 criteria." negate="false"/>
          <criterion test_ref="cmp-764" comment="Solaris 9 (SPARC) meets Sun Alert ID 102161 criteria." negate="false"/>
          <criterion test_ref="cmp-765" comment="Solaris 10 (SPARC) meets Sun Alert ID 102161 criteria." negate="false"/>
          <criterion test_ref="cmp-766" comment="Solaris 8 (x86) meets Sun Alert ID 102161 criteria." negate="false"/>
          <criterion test_ref="cmp-767" comment="Solaris 9 (x86) meets Sun Alert ID 102161 criteria." negate="false"/>
          <criterion test_ref="cmp-768" comment="Solaris 10 (x86) meets Sun Alert ID 102161 criteria." negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1629" class="vulnerability">
      <affected family="hp-ux">
        <hpux:platform>HP-UX 11</hpux:platform>
        <product>Apache</product>
      </affected>
      <dates>
        <submitted date="2006-03-18-07:24">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-03-22-11:10">DRAFT</status_change>
        <status_change date="2006-04-06-06:31">INTERIM</status_change>
        <status_change date="2006-05-03-10:06">ACCEPTED</status_change>
      </dates>
      <description>The Apache HTTP server before 1.3.34, and 2.0.x before 2.0.55, when acting as an HTTP proxy, allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes Apache to incorrectly handle and forward the body of the request in a way that causes the receiving server to process it as a separate HTTP request, aka "HTTP Request Smuggling."</description>
      <reference source="CVE">CVE-2005-2088</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-672" comment="700 Series OS Release 11.04" negate="false"/>
          <criterion test_ref="hst-70" comment="Webproxy is installed" negate="false"/>
          <criterion test_ref="hpt-40" comment="Patch PHSS_34163 or later is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1630" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Office</product>
      </affected>
      <dates>
        <submitted date="2006-03-15-10:53">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-03-15-07:17">DRAFT</status_change>
        <status_change date="2006-04-06-06:30">INTERIM</status_change>
        <status_change date="2006-05-03-10:06">ACCEPTED</status_change>
      </dates>
      <description>Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-complicit attackers to execute arbitrary code via an Excel file with a malformed graphic, which leads to memory corruption.</description>
      <reference source="CVE">CVE-2006-0030</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wft-774" comment="Xlview.exe is installed with a version less than 11.0.8012.0" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1632" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Internet Explorer</product>
      </affected>
      <dates>
        <submitted date="2006-04-12-12:55">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-04-12-05:16">DRAFT</status_change>
        <status_change date="2006-05-03-10:06">INTERIM</status_change>
      </dates>
      <description>Buffer overflow in mshtml.dll in Microsoft Internet Explorer 6.0.2900.2180, and probably other versions, allows remote attackers to execute arbitrary code via an HTML tag with a large number of script action handlers such as onload and onmouseover, as demonstrated using onclick, aka the "Multiple Event Handler Memory Corruption Vulnerability."</description>
      <reference source="CVE">CVE-2006-1245</reference>
      <status>INTERIM</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wrt-10026" comment="Win2K/XP/2003 is patched" negate="true"/>
          <criterion test_ref="wft-778" comment="the version of mshtml.dll is less than 6.0.3790.507" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1633" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Office</product>
      </affected>
      <dates>
        <submitted date="2006-03-15-10:53">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-03-15-07:17">DRAFT</status_change>
        <status_change date="2006-04-06-06:30">INTERIM</status_change>
        <status_change date="2006-05-03-10:06">ACCEPTED</status_change>
      </dates>
      <description>Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-complicit attackers to execute arbitrary code via an Excel file with a malformed description, which leads to memory corruption.</description>
      <reference source="CVE">CVE-2006-0029</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-137" comment="Excel 2000 is installed" negate="false"/>
          <criterion test_ref="wft-769" comment="the version of excel.exe is less than 9.0.0.8938" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1635" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Office</product>
      </affected>
      <dates>
        <submitted date="2006-03-15-10:53">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-03-15-07:17">DRAFT</status_change>
        <status_change date="2006-04-06-06:30">INTERIM</status_change>
        <status_change date="2006-05-03-10:06">ACCEPTED</status_change>
      </dates>
      <description>Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-complicit attackers to execute arbitrary code via a BIFF parsing format file containing malformed BOOLERR records that lead to memory corruption, probably involving invalid pointers.</description>
      <reference source="CVE">CVE-2006-0028</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wft-774" comment="Xlview.exe is installed with a version less than 11.0.8012.0" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1636" class="vulnerability">
      <affected family="hp-ux">
        <hpux:platform>HP-UX 11</hpux:platform>
        <product>ftpd</product>
      </affected>
      <dates>
        <submitted date="2006-01-30-07:20">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-02-01-09:08">DRAFT</status_change>
        <status_change date="2006-02-22-08:27">INTERIM</status_change>
        <status_change date="2006-03-09-12:19">ACCEPTED</status_change>
      </dates>
      <description>wu-ftpd 2.6.2 and earlier, with the restricted-gid option enabled, allows local users to bypass access restrictions by changing the permissions to prevent access to their home directory, which causes wu-ftpd to use the root directory instead.</description>
      <reference source="CVE">CVE-2004-0148</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-688" comment="700 Series OS Release 11.22" negate="false"/>
          <criterion test_ref="hst-53" comment="InternetSrvcs.INETSVCS2-RUN (B.11.22) is installed" negate="false"/>
          <criterion test_ref="hpt-35" comment="Patch PHNE_29462 or later is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1637" class="vulnerability">
      <affected family="hp-ux">
        <hpux:platform>HP-UX 11</hpux:platform>
        <product>ftpd</product>
      </affected>
      <dates>
        <submitted date="2006-01-30-07:20">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-02-01-09:08">DRAFT</status_change>
        <status_change date="2006-02-22-08:27">INTERIM</status_change>
        <status_change date="2006-03-09-12:19">ACCEPTED</status_change>
      </dates>
      <description>wu-ftpd 2.6.2 and earlier, with the restricted-gid option enabled, allows local users to bypass access restrictions by changing the permissions to prevent access to their home directory, which causes wu-ftpd to use the root directory instead.</description>
      <reference source="CVE">CVE-2004-0148</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-619" comment="700 Series or 800 Series OS Release 11.00" negate="false"/>
          <criterion test_ref="hst-52" comment="WUFTP-26.INETSVCS-FTP with version less than B.11.00.01.004 is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1638" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Internet Explorer</product>
      </affected>
      <dates>
        <submitted date="2006-02-17-07:36">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-02-22-08:27">DRAFT</status_change>
        <status_change date="2006-03-09-12:19">INTERIM</status_change>
        <status_change date="2006-04-06-06:30">ACCEPTED</status_change>
      </dates>
      <description>An unspecified Microsoft WMF parsing application, as used in Internet Explorer 5.01 SP4 on Windows 2000 SP4, and 5.5 SP2 on Windows Millennium, and possibly other versions, allows attackers to cause a denial of service (crash) and possibly execute code via a crafted WMF file with a manipulated WMF header size, possibly involving an integer overflow, a different vulnerability than CVE-2005-4560, and aka "WMF Image Parsing Memory Corruption Vulnerability."</description>
      <reference source="CVE">CVE-2006-0020</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-54" comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false"/>
          <criterion test_ref="wft-742" comment="the version of mshtml.dll is less than 5.0.3837.1200" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1642" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Internet Explorer</product>
      </affected>
      <dates>
        <submitted date="2006-04-12-12:55">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-04-12-05:16">DRAFT</status_change>
        <status_change date="2006-05-03-10:06">INTERIM</status_change>
      </dates>
      <description>Unspecified vulnerability in Microsoft Internet Explorer 6.0 allows remote attackers to execute HTA files via unknown vectors.</description>
      <reference source="CVE">CVE-2006-1388</reference>
      <status>INTERIM</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-613" comment="Win2K or XP,SP1 is installed" negate="false"/>
          <criterion test_ref="wrt-652" comment="Internet Explorer 6 (any patch level) is installed" negate="false"/>
          <criterion test_ref="wft-776" comment="the version of mshtml.dll is less than 6.0.2800.1543" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1645" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Internet Explorer</product>
      </affected>
      <dates>
        <submitted date="2006-04-12-12:55">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-04-12-05:16">DRAFT</status_change>
        <status_change date="2006-05-03-10:06">INTERIM</status_change>
      </dates>
      <description>Microsoft Internet Explorer 5.01 through 6 allows remote attackers to conduct phishing attacks by spoofing the address bar and other parts of the trust UI via unknown methods that allow "window content to persist" after the user has navigated to another site, aka the "Address Bar Spoofing Vulnerability."  NOTE: this is a different vulnerability than CVE-2006-1626.</description>
      <reference source="CVE">CVE-2006-1192</reference>
      <status>INTERIM</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-692" comment="Windows XP (64-bit,SP1 or 32-bit,SP2) is installed" negate="false"/>
          <criterion test_ref="wft-777" comment="the version of mshtml.dll is less than 6.0.2900.2873" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1647" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2006-02-17-07:36">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-02-22-08:27">DRAFT</status_change>
        <status_change date="2006-03-09-12:19">INTERIM</status_change>
        <status_change date="2006-04-06-06:30">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Windows XP SP1 and SP2, and Server 2003 up to SP1, allows remote attackers to cause a denial of service (hang) via certain malformed IGMP packets, aka the "IGMP v3 DoS Vulnerability."</description>
      <reference source="CVE">CVE-2006-0021</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-2" comment="Windows XP is installed" negate="false"/>
          <criterion test_ref="wrt-4" comment="Win2K/XP/2003 service pack 1 is installed" negate="false"/>
          <criterion test_ref="wrt-70" comment="64-Bit version of Windows is installed" negate="false"/>
          <criterion test_ref="wft-758" comment="the version of Tcpip.sys is less than 5.2.3790.2617 (64-bit,SP1)" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1650" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2006-02-17-07:36">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-02-22-08:27">DRAFT</status_change>
        <status_change date="2006-03-09-12:19">INTERIM</status_change>
        <status_change date="2006-04-06-06:30">ACCEPTED</status_change>
      </dates>
      <description>The ShellAbout API call in Korean Input Method Editor (IME) in Korean versions of Microsoft Windows XP SP1 and SP2, Windows Server 2003 up to SP1, and Office 2003, allows local users to gain privileges by launching the "shell about dialog box" and clicking the "End-User License Agreement" link, which executes Notepad with the privileges of the program that displays the about box.</description>
      <reference source="CVE">CVE-2006-0008</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wrt-10026" comment="Win2K/XP/2003 is patched" negate="true"/>
          <criterion test_ref="wft-767" comment="the version of Imekr61.ime is less than 6.1.3790.1 (S03-Gold)" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1651" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Internet Explorer</product>
      </affected>
      <dates>
        <submitted date="2006-04-12-12:55">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-04-12-05:16">DRAFT</status_change>
        <status_change date="2006-05-03-10:06">INTERIM</status_change>
      </dates>
      <description>Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via by instantiating the (1) Mdt2gddr.dll, (2) Mdt2dd.dll, and (3) Mdt2gddo.dll COM objects as ActiveX controls, which leads to memory corruption.</description>
      <reference source="CVE">CVE-2006-1186</reference>
      <status>INTERIM</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wrt-10026" comment="Win2K/XP/2003 is patched" negate="true"/>
          <criterion test_ref="wft-778" comment="the version of mshtml.dll is less than 6.0.3790.507" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1653" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Office</product>
      </affected>
      <dates>
        <submitted date="2006-03-15-10:53">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-03-15-07:17">DRAFT</status_change>
        <status_change date="2006-04-06-06:31">INTERIM</status_change>
        <status_change date="2006-05-03-10:06">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in Microsoft Office 2000 SP3, XP SP3, and other versions and packages, allows user-complicit attackers to execute arbitrary code via a routing slip that is longer than specified by the provided length field.</description>
      <reference source="CVE">CVE-2006-0009</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wft-774" comment="Xlview.exe is installed with a version less than 11.0.8012.0" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1654" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>Licence Logging Service</product>
      </affected>
      <dates>
        <submitted date="2005-04-13-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-04-20-12:13">DRAFT</status_change>
        <status_change date="2005-05-11-05:41">INTERIM</status_change>
        <status_change date="2005-06-01-03:30">ACCEPTED</status_change>
      </dates>
      <description>gzip before 1.3 in Solaris 8, when called with the -f or -force flags, will change the permissions of files that are hard linked to the target files, which allows local users to view or modify these files.</description>
      <reference source="CVE">CVE-2004-1349</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="sat-36" comment="GNU Zip (gzip, SUNWgzip) installed" negate="false"/>
          <criterion test_ref="spt-67" comment="Patch 112668-02 or later installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1655" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Word for Windows 6.0 Converter</product>
      </affected>
      <dates>
        <submitted date="2005-01-05-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2005-01-06-09:32">DRAFT</status_change>
        <status_change date="2005-02-02-12:00">INTERIM</status_change>
        <status_change date="2005-02-23-09:25">ACCEPTED</status_change>
        <modified date="2005-12-20-07:05" comment="Replaced all criteria. 1) Included all S03 versions, 2) dropped explicit check for Hotfix kb885836, 3) check version of wordpad.exe rather than mswrd wpc files.">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </modified>
        <status_change date="2006-01-04-08:04">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Word for Windows 6.0 Converter (MSWRD632.WPC), as used in WordPad, does not properly validate certain data lengths, which allows remote attackers to execute arbitrary code via a .wri, .rtf, and .doc file sent by email or malicious web site, aka "Font Conversion Vulnerability," a different vulnerability than CVE-2004-0571.</description>
      <reference source="CVE">CVE-2004-0901</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wft-713" comment="the version of wordpad.exe is less than 5.2.3790.224" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1656" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Windows kernel</product>
      </affected>
      <dates>
        <submitted date="2005-05-02-12:00">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </submitted>
        <status_change date="2005-05-04-12:00">DRAFT</status_change>
        <status_change date="2005-06-01-12:00">INTERIM</status_change>
        <modified date="2005-06-02-12:00" comment="Added product">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-06-22-12:38">ACCEPTED</status_change>
      </dates>
      <description>The kernel of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via certain access requests.</description>
      <reference source="CVE">CVE-2005-0061</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-35" comment="Windows XP 32 bit Service Pack 2" negate="false"/>
          <criterion test_ref="wft-581" comment="The version of Ntoskrnl.exe is less than 5.1.2600.2622" negate="false"/>
          <criterion test_ref="wrt-427" comment="the patch KB890859 is installed (Hotfix key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1657" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Internet Explorer</product>
      </affected>
      <dates>
        <submitted date="2006-04-12-12:55">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-04-12-05:16">DRAFT</status_change>
        <status_change date="2006-05-03-10:06">INTERIM</status_change>
      </dates>
      <description>Microsoft Internet Explorer 6 and 7 Beta 2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a certain createTextRange call on a checkbox object, which results in a dereference of an invalid table pointer.</description>
      <reference source="CVE">CVE-2006-1359</reference>
      <status>INTERIM</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wrt-4" comment="Win2K/XP/2003 service pack 1 is installed" negate="false"/>
          <criterion test_ref="wft-779" comment="the version of mshtml.dll is less than 6.0.3790.2666" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1659" class="vulnerability">
      <affected family="hp-ux">
        <hpux:platform>HP-UX 11</hpux:platform>
        <product>Apache</product>
      </affected>
      <dates>
        <submitted date="2006-03-18-07:24">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-03-22-11:10">DRAFT</status_change>
        <status_change date="2006-04-06-06:31">INTERIM</status_change>
        <status_change date="2006-05-03-10:06">ACCEPTED</status_change>
      </dates>
      <description>Integer overflow in pcre_compile.c in Perl Compatible Regular Expressions (PCRE) before 6.2, as used in multiple products such as Python, Ethereal, and PHP, allows attackers to execute arbitrary code via quantifier values in regular expressions, which leads to a heap-based buffer overflow.</description>
      <reference source="CVE">CVE-2005-2491</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-672" comment="700 Series OS Release 11.04" negate="false"/>
          <criterion test_ref="hst-69" comment="VirusVault is installed" negate="false"/>
          <criterion test_ref="hpt-39" comment="Patch PHSS_34123 or later is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1660" class="vulnerability">
      <affected family="hp-ux">
        <hpux:platform>HP-UX 11</hpux:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2006-03-29-06:11">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-04-06-06:30">DRAFT</status_change>
        <status_change date="2006-05-03-10:06">INTERIM</status_change>
      </dates>
      <description>An undisclosed vulnerability has been identified in /sbin/passwd which could be exploited to create a Denial of Service condition..</description>
      <reference source="MISC">http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00619550</reference>
      <status>INTERIM</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-618" comment="700 Series or 800 Series OS Release 11.11" negate="false"/>
          <criterion test_ref="hst-81" comment="OS-Core.UX-CORE is installed" negate="false"/>
          <criterion test_ref="hpt-58" comment="Patch PHCO_33214 or subsequent is installed" negate="true"/>
          <criterion test_ref="hpt-59" comment="Patch PHCO_33215 or subsequent is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1661" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Windows Media Player</product>
      </affected>
      <dates>
        <submitted date="2006-02-17-07:36">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-02-22-08:27">DRAFT</status_change>
        <status_change date="2006-03-09-12:19">INTERIM</status_change>
        <status_change date="2006-04-06-06:30">ACCEPTED</status_change>
      </dates>
      <description>Heap-based buffer overflow in the bitmap processing routine in Microsoft Windows Media Player 7.1 on Windows 2000 SP4, Media Player 9 on Windows 200 SP4 and XP SP1, and Media Player 10 on XP SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted bitmap (.BMP) file that specifies a size of 0 but contains additional data.</description>
      <reference source="CVE">CVE-2006-0006</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-10031" comment="Windows Media Player 9 is installed" negate="false"/>
          <criterion test_ref="wft-745" comment="the version of Wmp.dll is less than 9.0.0.3344" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1662" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2006-02-17-07:36">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-02-22-08:27">DRAFT</status_change>
        <status_change date="2006-03-09-12:19">INTERIM</status_change>
        <status_change date="2006-04-06-06:30">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Windows XP SP1 and SP2, and Server 2003 up to SP1, allows remote attackers to cause a denial of service (hang) via certain malformed IGMP packets, aka the "IGMP v3 DoS Vulnerability."</description>
      <reference source="CVE">CVE-2006-0021</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-2" comment="Windows XP is installed" negate="false"/>
          <criterion test_ref="wrt-4" comment="Win2K/XP/2003 service pack 1 is installed" negate="false"/>
          <criterion test_ref="wrt-70" comment="64-Bit version of Windows is installed" negate="true"/>
          <criterion test_ref="wft-756" comment="the version of Tcpip.sys is less than 5.1.2600.1792 (XP,SP1)" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1664" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2006-02-17-07:36">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-02-22-08:27">DRAFT</status_change>
        <status_change date="2006-03-09-12:19">INTERIM</status_change>
        <status_change date="2006-04-06-06:30">ACCEPTED</status_change>
      </dates>
      <description>The ShellAbout API call in Korean Input Method Editor (IME) in Korean versions of Microsoft Windows XP SP1 and SP2, Windows Server 2003 up to SP1, and Office 2003, allows local users to gain privileges by launching the "shell about dialog box" and clicking the "End-User License Agreement" link, which executes Notepad with the privileges of the program that displays the about box.</description>
      <reference source="CVE">CVE-2006-0008</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-2" comment="Windows XP is installed" negate="false"/>
          <criterion test_ref="wrt-70" comment="64-Bit version of Windows is installed" negate="true"/>
          <criterion test_ref="wft-765" comment="the version of Imekr61.ime is less than 6.1.2600.3 (WinXP)" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1666" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Office</product>
      </affected>
      <dates>
        <submitted date="2006-03-15-10:53">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-03-15-07:17">DRAFT</status_change>
        <status_change date="2006-04-06-06:30">INTERIM</status_change>
        <status_change date="2006-05-03-10:06">ACCEPTED</status_change>
      </dates>
      <description>Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-complicit attackers to execute arbitrary code via an Excel file with a malformed graphic, which leads to memory corruption.</description>
      <reference source="CVE">CVE-2006-0030</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-649" comment="Excel 2002 is installed" negate="false"/>
          <criterion test_ref="wft-771" comment="the version of excel.exe is less than 10.0.6789.0" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1671" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2006-03-15-10:53">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-03-15-07:17">DRAFT</status_change>
        <status_change date="2006-04-06-06:30">INTERIM</status_change>
        <status_change date="2006-05-03-10:06">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Windows XP SP1 and SP2 before August 2004, and possibly other operating systems and versions, uses insecure default ACLs that allow the Authenticated Users group to gain privileges by modifying critical configuration information for the (1) Simple Service Discovery Protocol (SSDP), (2) Universal Plug and Play Device Host (UPnP), (3) NetBT, (4) SCardSvr, (5) DHCP, and (6) DnsCache services, aka "Permissive Windows Services DACLs."  NOTE: the NetBT, SCardSvr, DHCP, DnsCache already require privileged access to exploit.</description>
      <reference source="CVE">CVE-2006-0023</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wrt-10026" comment="Win2K/XP/2003 is patched" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-648" comment="Patch S03-KB914798 is installed." negate="true"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1676" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Internet Explorer</product>
      </affected>
      <dates>
        <submitted date="2006-04-12-12:55">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-04-12-05:16">DRAFT</status_change>
        <status_change date="2006-05-03-10:06">INTERIM</status_change>
      </dates>
      <description>Unspecified vulnerability in Microsoft Internet Explorer 6.0 allows remote attackers to execute HTA files via unknown vectors.</description>
      <reference source="CVE">CVE-2006-1388</reference>
      <status>INTERIM</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wrt-4" comment="Win2K/XP/2003 service pack 1 is installed" negate="false"/>
          <criterion test_ref="wft-779" comment="the version of mshtml.dll is less than 6.0.3790.2666" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1677" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Internet Explorer</product>
      </affected>
      <dates>
        <submitted date="2006-04-12-12:55">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-04-12-05:16">DRAFT</status_change>
        <status_change date="2006-05-03-10:06">INTERIM</status_change>
      </dates>
      <description>Unspecified vulnerability in Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via certain invalid HTML that causes memory corruption.</description>
      <reference source="CVE">CVE-2006-1185</reference>
      <status>INTERIM</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wrt-4" comment="Win2K/XP/2003 service pack 1 is installed" negate="false"/>
          <criterion test_ref="wft-779" comment="the version of mshtml.dll is less than 6.0.3790.2666" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1678" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Internet Explorer</product>
      </affected>
      <dates>
        <submitted date="2006-04-12-12:55">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-04-12-05:16">DRAFT</status_change>
        <status_change date="2006-05-03-10:06">INTERIM</status_change>
      </dates>
      <description>Microsoft Internet Explorer 6 and 7 Beta 2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a certain createTextRange call on a checkbox object, which results in a dereference of an invalid table pointer.</description>
      <reference source="CVE">CVE-2006-1359</reference>
      <status>INTERIM</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-212" comment="Windows 2000 Service Pack 4 (or later) is installed" negate="false"/>
          <criterion test_ref="wrt-651" comment="Internet Explorer 5.01 (any patch level) is installed" negate="false"/>
          <criterion test_ref="wft-775" comment="the version of mshtml.dll is less than 5.0.3839.2200" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1679" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2006-04-12-12:55">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-04-12-05:16">DRAFT</status_change>
        <status_change date="2006-05-03-10:06">INTERIM</status_change>
      </dates>
      <description>Unspecified vulnerability in Windows Explorer in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote attackers to execute arbitrary code via attack vectors involving COM objects and "crafted files and directories," aka the "Windows Shell Vulnerability."</description>
      <reference source="CVE">CVE-2006-0012</reference>
      <status>INTERIM</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-2" comment="Windows XP is installed" negate="false"/>
          <criterion test_ref="wrt-4" comment="Win2K/XP/2003 service pack 1 is installed" negate="false"/>
          <criterion test_ref="wrt-70" comment="64-Bit version of Windows is installed" negate="true"/>
          <criterion test_ref="wft-789" comment="the version of shell32.dll is less than 6.0.2800.1816" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1682" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Outlook Express</product>
      </affected>
      <dates>
        <submitted date="2006-04-12-12:55">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-04-12-05:16">DRAFT</status_change>
        <status_change date="2006-05-03-10:06">INTERIM</status_change>
      </dates>
      <description>Buffer overflow in Microsoft Outlook Express 5.5 and 6 allows remote attackers to execute arbitrary code via a crafted Windows Address Book (WAB) file containing "certain Unicode strings" and modified length values.</description>
      <reference source="CVE">CVE-2006-0014</reference>
      <status>INTERIM</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-838" comment="Windows XP,SP1 32-bit or Win2K,SP4 is installed" negate="false"/>
          <criterion test_ref="wrt-173" comment="Outlook Express 6 SP1 is installed" negate="false"/>
          <criterion test_ref="wft-794" comment="the version of inetcomm.dll is less than 6.0.2800.1807" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1684" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>sendfilev()</product>
      </affected>
      <dates>
        <submitted date="2005-04-13-04:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-04-20-04:00">DRAFT</status_change>
        <status_change date="2005-05-11-04:00">INTERIM</status_change>
        <status_change date="2005-06-01-04:00">ACCEPTED</status_change>
        <status_change date="2005-08-25-10:03">INTERIM</status_change>
        <status_change date="2005-08-25-10:05">DRAFT</status_change>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Unknown vulnerability in the sendfilev function in Sun Solaris 8 and 9 allows local users to cause a denial of service (system panic) via unknown vectors.</description>
      <reference source="CVE">CVE-2004-1356</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" negate="false"/>
          <criterion test_ref="spt-81" comment="Patch 108528-27 or later installed" negate="true"/>
          <criterion test_ref="spt-80" comment="Patch 112233-12 or later installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1685" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Windows XP</product>
      </affected>
      <dates>
        <submitted date="2005-08-18-04:00">
          <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
        </submitted>
        <status_change date="2005-08-25-10:05">DRAFT</status_change>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Windows Server 2003 and XP SP2, with Windows Firewall turned off, allows remote attackers to cause a denial of service (CPU consumption) via a TCP packet with the SYN flag set and the same destination and source address and port, aka a reoccurrence of the "Land" vulnerability (CVE-1999-0016).</description>
      <reference source="CVE">CVE-2005-0688</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-2" comment="Windows XP is installed" negate="false"/>
          <criterion test_ref="cmp-23" comment="32-bit version of Windows or 64-bit (itanium architecture) version of Windows is installed" negate="false"/>
          <criterion test_ref="wrt-79" comment="Win2K/XP/2003 service pack 2 (or earlier) is installed" negate="false"/>
          <criterion test_ref="cmp-298" comment="A vulnerable version of tcpip.sys is installed." negate="false"/>
          <criterion test_ref="wrt-443" comment="the patch KB893066 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1688" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2006-02-17-07:36">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-02-22-08:27">DRAFT</status_change>
        <status_change date="2006-03-09-12:19">INTERIM</status_change>
        <status_change date="2006-04-06-06:30">ACCEPTED</status_change>
      </dates>
      <description>The ShellAbout API call in Korean Input Method Editor (IME) in Korean versions of Microsoft Windows XP SP1 and SP2, Windows Server 2003 up to SP1, and Office 2003, allows local users to gain privileges by launching the "shell about dialog box" and clicking the "End-User License Agreement" link, which executes Notepad with the privileges of the program that displays the about box.</description>
      <reference source="CVE">CVE-2006-0008</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wrt-4" comment="Win2K/XP/2003 service pack 1 is installed" negate="false"/>
          <criterion test_ref="wft-766" comment="the version of Imekr61.ime is less than 6.2.2551.0 (64-bit)" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1689" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Linux 9</redhat:platform>
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <redhat:platform>Red Hat Enterprise Linux 4</redhat:platform>
        <product>Sendmail</product>
      </affected>
      <dates>
        <submitted date="2006-03-27-09:51">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-04-06-06:30">DRAFT</status_change>
        <status_change date="2006-05-03-10:06">INTERIM</status_change>
      </dates>
      <description>Signal handler race condition in Sendmail 8.13.x before 8.13.6 allows remote attackers to execute arbitrary code by triggering timeouts in a way that causes the setjmp and longjmp function calls to be interrupted and modify unexpected memory locations.</description>
      <reference source="CVE">CVE-2006-0058</reference>
      <status>INTERIM</status>
      <version>0</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="rrt-11" comment="sendmail before 8.12.x is installed" negate="false"/>
          <criterion test_ref="rrt-12" comment="sendmail 8.12.x before 8.12.11 is installed" negate="false"/>
          <criterion test_ref="rrt-13" comment="sendmail 8.13.x before 8.13.6 is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1690" class="vulnerability">
      <affected family="hp-ux">
        <hpux:platform>HP-UX 11</hpux:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2006-03-29-06:11">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-04-06-06:30">DRAFT</status_change>
        <status_change date="2006-05-03-10:06">INTERIM</status_change>
      </dates>
      <description>An undisclosed vulnerability has been identified in /sbin/passwd which could be exploited to create a Denial of Service condition..</description>
      <reference source="MISC">http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00619550</reference>
      <status>INTERIM</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-682" comment="700 Series or 800 Series OS Release 11.23" negate="false"/>
          <criterion test_ref="hst-82" comment="OS-Core.UX2-CORE is installed" negate="false"/>
          <criterion test_ref="hpt-60" comment="Patch PHCO_32149 or subsequent is installed" negate="true"/>
          <criterion test_ref="hpt-61" comment="Patch PHCO_32926 or subsequent is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1695" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Microsoft Internet Explorer 6</product>
      </affected>
      <dates>
        <submitted date="2005-05-10-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2005-05-11-05:38">DRAFT</status_change>
        <status_change date="2005-06-01-03:30">INTERIM</status_change>
        <status_change date="2005-06-22-12:38">ACCEPTED</status_change>
      </dates>
      <description>Race condition in the memory management routines in the DHTML object processor in Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a malicious web page or HTML e-mail, aka "DHTML Object Memory Corruption Vulnerability".</description>
      <reference source="CVE">CVE-2005-0553</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-200" comment="Internet Explorer 6.0 Installed XP SP2" negate="false"/>
          <criterion test_ref="wft-595" comment="the version of mshtml.dll is less than 6.0.2900.2627" negate="false"/>
          <criterion test_ref="wrt-439" comment="the patch kb890923  is installed (XP SP2 Hotfix key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1696" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2006-03-15-10:53">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-03-15-07:17">DRAFT</status_change>
        <status_change date="2006-04-06-06:30">INTERIM</status_change>
        <status_change date="2006-05-03-10:06">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Windows XP SP1 and SP2 before August 2004, and possibly other operating systems and versions, uses insecure default ACLs that allow the Authenticated Users group to gain privileges by modifying critical configuration information for the (1) Simple Service Discovery Protocol (SSDP), (2) Universal Plug and Play Device Host (UPnP), (3) NetBT, (4) SCardSvr, (5) DHCP, and (6) DnsCache services, aka "Permissive Windows Services DACLs."  NOTE: the NetBT, SCardSvr, DHCP, DnsCache already require privileged access to exploit.</description>
      <reference source="CVE">CVE-2006-0023</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-2" comment="Windows XP is installed" negate="false"/>
          <criterion test_ref="wrt-4" comment="Win2K/XP/2003 service pack 1 is installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-647" comment="Patch WinXP-KB914798 is installed." negate="true"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1697" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 10</solaris:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2006-03-21-04:03">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-03-22-11:10">DRAFT</status_change>
        <status_change date="2006-04-06-06:31">INTERIM</status_change>
        <status_change date="2006-05-03-10:06">ACCEPTED</status_change>
      </dates>
      <description>X.Org server (xorg-server) 1.0.0 and later, X11R6.9.0, and X11R7.0 inadvertently treats the address of the geteuid function as if it is the return value of a call to geteuid, which allows local users to bypass intended restrictions and (1) execute arbitrary code via the -modulepath command line option or (2) overwrite arbitrary files via -logfile.</description>
      <reference source="CVE">CVE-2006-0745</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-10001" comment="Solaris 10 Installed" negate="false"/>
          <criterion test_ref="uut-10002" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="cmp-791" comment="Patch 118966-14 through 118966-16 is installed." negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1701" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Internet Explorer 6.0</product>
      </affected>
      <dates>
        <submitted date="2005-02-10-12:00">
          <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
        </submitted>
        <status_change date="2005-02-11-12:00">DRAFT</status_change>
        <status_change date="2005-03-02-12:00">INTERIM</status_change>
        <status_change date="2005-03-23-12:00">ACCEPTED</status_change>
        <modified date="2005-06-02-12:00" comment="Added product">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-06-08-03:17">INTERIM</status_change>
        <status_change date="2005-06-29-06:49">ACCEPTED</status_change>
      </dates>
      <description>The DHTML Edit Control (dhtmled.ocx) allows remote attackers to inject arbitrary web script into other domains by setting a name for a window, opening a child page whose target is the window with the given name, then injecting the script from the parent into the child using execScript, as demonstrated by "AbusiveParent" in Internet Explorer 6.0.2900.2180.</description>
      <reference source="CVE">CVE-2004-1319</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1102" comment="Windows XP 64-bit with SP1 (or earlier) installed" negate="false"/>
          <criterion test_ref="wft-383" comment="the version of wdhtmled.ocx is less than 6.1.0.9232" negate="false"/>
          <criterion test_ref="wrt-87" comment="the patch kb891781 is installed (Hotfix key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1702" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Internet Explorer</product>
      </affected>
      <dates>
        <submitted date="2006-04-12-12:55">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-04-12-05:16">DRAFT</status_change>
        <status_change date="2006-05-03-10:06">INTERIM</status_change>
      </dates>
      <description>Microsoft Internet Explorer 6 and 7 Beta 2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a certain createTextRange call on a checkbox object, which results in a dereference of an invalid table pointer.</description>
      <reference source="CVE">CVE-2006-1359</reference>
      <status>INTERIM</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-613" comment="Win2K or XP,SP1 is installed" negate="false"/>
          <criterion test_ref="wrt-652" comment="Internet Explorer 6 (any patch level) is installed" negate="false"/>
          <criterion test_ref="wft-776" comment="the version of mshtml.dll is less than 6.0.2800.1543" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1704" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Internet Explorer</product>
      </affected>
      <dates>
        <submitted date="2006-04-12-12:55">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-04-12-05:16">DRAFT</status_change>
        <status_change date="2006-05-03-10:06">INTERIM</status_change>
      </dates>
      <description>Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via by instantiating the (1) Mdt2gddr.dll, (2) Mdt2dd.dll, and (3) Mdt2gddo.dll COM objects as ActiveX controls, which leads to memory corruption.</description>
      <reference source="CVE">CVE-2006-1186</reference>
      <status>INTERIM</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wrt-4" comment="Win2K/XP/2003 service pack 1 is installed" negate="false"/>
          <criterion test_ref="wft-779" comment="the version of mshtml.dll is less than 6.0.3790.2666" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1705" class="vulnerability">
      <affected family="hp-ux">
        <hpux:platform>HP-UX 10</hpux:platform>
        <hpux:platform>HP-UX 11</hpux:platform>
        <hpux:platform>HP-UX 11i</hpux:platform>
        <product>Sendmail</product>
      </affected>
      <dates>
        <submitted date="2006-03-27-09:34">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-04-06-06:30">DRAFT</status_change>
        <status_change date="2006-05-03-10:06">INTERIM</status_change>
      </dates>
      <description>Signal handler race condition in Sendmail 8.13.x before 8.13.6 allows remote attackers to execute arbitrary code by triggering timeouts in a way that causes the setjmp and longjmp function calls to be interrupted and modify unexpected memory locations.</description>
      <reference source="CVE">CVE-2006-0058</reference>
      <status>INTERIM</status>
      <version>0</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="hwt-2" comment="sendmail before 8.12.x is installed" negate="false"/>
          <criterion test_ref="hwt-3" comment="sendmail 8.12.x before 8.12.11 is installed" negate="false"/>
          <criterion test_ref="hwt-4" comment="sendmail 8.13.x before 8.13.6 is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1707" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>Sun Enterprise Storage Manager (ESM)</product>
      </affected>
      <dates>
        <submitted date="2005-01-19-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-24-03:40">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description/>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" negate="false"/>
          <criterion test_ref="sat-1" comment="Sun Enterprise Storage Manager installed" negate="false"/>
          <criterion test_ref="spt-242" comment="Patch 117367-01 or later installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1710" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Internet Explorer</product>
      </affected>
      <dates>
        <submitted date="2006-04-12-12:55">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-04-12-05:16">DRAFT</status_change>
        <status_change date="2006-05-03-10:06">INTERIM</status_change>
      </dates>
      <description>Microsoft Internet Explorer 5.01 through 6 does not always correctly identify the domain that is associated with a browser window, which allows remote attackers to obtain sensitive cross-domain information and spoof sites by running script after the user has navigated to another site.</description>
      <reference source="CVE">CVE-2006-1191</reference>
      <status>INTERIM</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wrt-4" comment="Win2K/XP/2003 service pack 1 is installed" negate="false"/>
          <criterion test_ref="wft-779" comment="the version of mshtml.dll is less than 6.0.3790.2666" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1711" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Internet Explorer</product>
      </affected>
      <dates>
        <submitted date="2006-04-12-12:55">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-04-12-05:16">DRAFT</status_change>
        <status_change date="2006-05-03-10:06">INTERIM</status_change>
      </dates>
      <description>Unspecified vulnerability in Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via certain invalid HTML that causes memory corruption.</description>
      <reference source="CVE">CVE-2006-1185</reference>
      <status>INTERIM</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-212" comment="Windows 2000 Service Pack 4 (or later) is installed" negate="false"/>
          <criterion test_ref="wrt-651" comment="Internet Explorer 5.01 (any patch level) is installed" negate="false"/>
          <criterion test_ref="wft-775" comment="the version of mshtml.dll is less than 5.0.3839.2200" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1714" class="vulnerability">
      <affected family="hp-ux">
        <hpux:platform>HP-UX 11</hpux:platform>
        <product>Apache</product>
      </affected>
      <dates>
        <submitted date="2006-03-18-07:24">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-03-22-11:10">DRAFT</status_change>
        <status_change date="2006-04-06-06:31">INTERIM</status_change>
        <status_change date="2006-05-03-10:06">ACCEPTED</status_change>
      </dates>
      <description>Off-by-one error in the mod_ssl Certificate Revocation List (CRL) verification callback in Apache, when configured to use a CRL, allows remote attackers to cause a denial of service (child process crash) via a CRL that causes a buffer overflow of one null byte.</description>
      <reference source="CVE">CVE-2005-1268</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-672" comment="700 Series OS Release 11.04" negate="false"/>
          <criterion test_ref="hst-69" comment="VirusVault is installed" negate="false"/>
          <criterion test_ref="hpt-39" comment="Patch PHSS_34123 or later is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1718" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>VDM</product>
      </affected>
      <dates>
        <submitted date="2004-06-11-12:00">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </submitted>
        <status_change date="2004-08-04-12:00">ACCEPTED</status_change>
      </dates>
      <description>The component for the Virtual DOS Machine (VDM) subsystem in Windows NT 4.0 and Windows 2000 does not properly validate system structures, which allows local users to access protected kernel memory and execute arbitrary code.</description>
      <reference source="CVE">CVE-2004-0118</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
          <criterion test_ref="wrt-187" comment="the patch kb835732 is installed" negate="true"/>
          <criterion test_ref="cmp-1085" comment="Version check of Ntoskrnl for NT Terminal Server or NT Workstation" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1721" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Microsoft Visual Studio .NET 2003</product>
      </affected>
      <dates>
        <submitted date="2004-09-24-04:32">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </submitted>
        <status_change date="2004-09-29-02:08">DRAFT</status_change>
        <modified date="2004-09-30-11:39" comment="changed affected platforms">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <status_change date="2004-10-20-12:00">INTERIM</status_change>
        <status_change date="2004-11-03-12:00">ACCEPTED</status_change>
        <modified date="2005-12-26-09:40" comment="Removed test to check KB830348.  Added check for VS.NET Gdiplus.dll in WinSxS.">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </modified>
        <status_change date="2006-01-12-08:59">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length before a memory copy operation.</description>
      <reference source="CVE">CVE-2004-0200</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-519" comment="Microsoft Visual Studio .NET 2003 Installed" negate="false"/>
          <criterion test_ref="wft-714" comment="the version of Gdiplus.dll for Visual Studio .NET is less than 5.1.3102.1355" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1724" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Internet Explorer</product>
      </affected>
      <dates>
        <submitted date="2006-04-12-12:55">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-04-12-05:16">DRAFT</status_change>
        <status_change date="2006-05-03-10:06">INTERIM</status_change>
      </dates>
      <description>Unspecified vulnerability in Microsoft Internet Explorer 6.0 allows remote attackers to execute HTA files via unknown vectors.</description>
      <reference source="CVE">CVE-2006-1388</reference>
      <status>INTERIM</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wrt-10026" comment="Win2K/XP/2003 is patched" negate="true"/>
          <criterion test_ref="wft-778" comment="the version of mshtml.dll is less than 6.0.3790.507" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1725" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Internet Explorer</product>
      </affected>
      <dates>
        <submitted date="2006-04-12-12:55">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-04-12-05:16">DRAFT</status_change>
        <status_change date="2006-05-03-10:06">INTERIM</status_change>
      </dates>
      <description>Microsoft Internet Explorer 5.01 through 6 allows remote attackers to conduct phishing attacks by spoofing the address bar and other parts of the trust UI via unknown methods that allow "window content to persist" after the user has navigated to another site, aka the "Address Bar Spoofing Vulnerability."  NOTE: this is a different vulnerability than CVE-2006-1626.</description>
      <reference source="CVE">CVE-2006-1192</reference>
      <status>INTERIM</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wrt-4" comment="Win2K/XP/2003 service pack 1 is installed" negate="false"/>
          <criterion test_ref="wft-779" comment="the version of mshtml.dll is less than 6.0.3790.2666" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1727" class="vulnerability">
      <affected family="hp-ux">
        <hpux:platform>HP-UX 11</hpux:platform>
        <product>Apache</product>
      </affected>
      <dates>
        <submitted date="2006-03-18-07:24">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-03-22-11:10">DRAFT</status_change>
        <status_change date="2006-04-06-06:31">INTERIM</status_change>
        <status_change date="2006-05-03-10:06">ACCEPTED</status_change>
      </dates>
      <description>The byte-range filter in Apache 2.0 before 2.0.54 allows remote attackers to cause a denial of service (memory consumption) via an HTTP header with a large Range field.</description>
      <reference source="CVE">CVE-2005-2728</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-672" comment="700 Series OS Release 11.04" negate="false"/>
          <criterion test_ref="hst-70" comment="Webproxy is installed" negate="false"/>
          <criterion test_ref="hpt-40" comment="Patch PHSS_34163 or later is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1732" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>/usr/lib/print/conv_fix</product>
      </affected>
      <dates>
        <submitted date="2005-04-13-04:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-04-20-04:00">DRAFT</status_change>
        <status_change date="2005-05-11-04:00">INTERIM</status_change>
        <status_change date="2005-06-01-04:00">ACCEPTED</status_change>
        <status_change date="2005-08-25-10:03">INTERIM</status_change>
        <status_change date="2005-08-25-10:05">DRAFT</status_change>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Unknown vulnerability in conv_fix in Sun Solaris 7 through 9, when invoked by conv_lpd, allows local users to overwrite arbitrary files.</description>
      <reference source="CVE">CVE-2004-1360</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" negate="false"/>
          <criterion test_ref="sat-43" comment="SunSoft Print - Client - Usr (SUNWpcu) installed" negate="false"/>
          <criterion test_ref="spt-89" comment="Patch 107115-14 or later installed" negate="true"/>
          <criterion test_ref="spt-90" comment="Patch 109320-09 or later installed" negate="true"/>
          <criterion test_ref="spt-91" comment="Patch 113329-05 or later installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1735" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Internet Explorer</product>
      </affected>
      <dates>
        <submitted date="2006-04-12-12:55">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-04-12-05:16">DRAFT</status_change>
        <status_change date="2006-05-03-10:06">INTERIM</status_change>
      </dates>
      <description>Microsoft Internet Explorer 5.01 through 6 does not always return the correct IOleClientSite information when dynamically creating an embedded object, which could cause Internet Explorer to run the object in the wrong security context or zone, and allow remote attackers to execute arbitrary code.</description>
      <reference source="CVE">CVE-2006-1190</reference>
      <status>INTERIM</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-692" comment="Windows XP (64-bit,SP1 or 32-bit,SP2) is installed" negate="false"/>
          <criterion test_ref="wft-777" comment="the version of mshtml.dll is less than 6.0.2900.2873" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1736" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Internet Explorer 5.01 Service Pack 3</product>
      </affected>
      <dates>
        <submitted date="2005-03-17-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2005-03-23-08:09">DRAFT</status_change>
        <status_change date="2005-04-13-12:15">INTERIM</status_change>
        <status_change date="2005-05-04-12:33">ACCEPTED</status_change>
        <modified date="2005-12-26-09:40" comment="Removed test to check kb867282.">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </modified>
        <status_change date="2006-01-12-08:59">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 5.01, 5.5, and 6 allows remote attackers to spoof a less restrictive security zone and execute arbitrary code via an HTML page containing URLs that contain hostnames that have been double hex encoded, which are decoded twice to generate a malicious hostname, aka the "URL Decoding Zone Spoofing Vulnerability."</description>
      <reference source="CVE">CVE-2005-0054</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-55" comment="Internet Explorer 5.01 Service Pack 3 is installed" negate="false"/>
          <criterion test_ref="wft-406" comment="the version of mshtml.dll is less than 5.0.3528.700" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1740" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Internet Explorer</product>
      </affected>
      <dates>
        <submitted date="2006-04-12-12:55">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-04-12-05:16">DRAFT</status_change>
        <status_change date="2006-05-03-10:06">INTERIM</status_change>
      </dates>
      <description>Microsoft Internet Explorer 5.01 through 6 allows remote attackers to conduct phishing attacks by spoofing the address bar and other parts of the trust UI via unknown methods that allow "window content to persist" after the user has navigated to another site, aka the "Address Bar Spoofing Vulnerability."  NOTE: this is a different vulnerability than CVE-2006-1626.</description>
      <reference source="CVE">CVE-2006-1192</reference>
      <status>INTERIM</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-212" comment="Windows 2000 Service Pack 4 (or later) is installed" negate="false"/>
          <criterion test_ref="wrt-651" comment="Internet Explorer 5.01 (any patch level) is installed" negate="false"/>
          <criterion test_ref="wft-775" comment="the version of mshtml.dll is less than 5.0.3839.2200" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1742" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>MDAC</product>
      </affected>
      <dates>
        <submitted date="2006-04-12-12:55">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-04-12-05:16">DRAFT</status_change>
        <status_change date="2006-05-03-10:06">INTERIM</status_change>
      </dates>
      <description>Unspecified vulnerability in the RDS.Dataspace ActiveX control, which is contained in ActiveX Data Objects (ADO) and distributed in Microsoft Data Access Components (MDAC) 2.7 and 2.8, allows remote attackers to execute arbitrary code via unknown attack vectors.</description>
      <reference source="CVE">CVE-2006-0003</reference>
      <status>INTERIM</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-842" comment="Windows XP 64-bit or S03,SP1 is installed" negate="false"/>
          <criterion test_ref="wft-787" comment="the version of msadco.dll is less than 2.82.2644.0" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1743" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2006-04-12-12:55">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-04-12-05:16">DRAFT</status_change>
        <status_change date="2006-05-03-10:06">INTERIM</status_change>
      </dates>
      <description>Unspecified vulnerability in Windows Explorer in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote attackers to execute arbitrary code via attack vectors involving COM objects and "crafted files and directories," aka the "Windows Shell Vulnerability."</description>
      <reference source="CVE">CVE-2006-0012</reference>
      <status>INTERIM</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-842" comment="Windows XP 64-bit or S03,SP1 is installed" negate="false"/>
          <criterion test_ref="wft-792" comment="the version of shell32.dll is less than 6.0.3790.2662" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1744" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Windows XP</product>
      </affected>
      <dates>
        <submitted date="2005-08-18-04:00">
          <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
        </submitted>
        <status_change date="2005-08-25-10:05">DRAFT</status_change>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Windows XP SP2 and earlier, 2000 SP3 and SP4, Server 2003, and older operating systems allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted IP packets with malformed options, aka the "IP Validation Vulnerability."</description>
      <reference source="CVE">CVE-2005-0048</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-2" comment="Windows XP is installed" negate="false"/>
          <criterion test_ref="cmp-23" comment="32-bit version of Windows or 64-bit (itanium architecture) version of Windows is installed" negate="false"/>
          <criterion test_ref="wrt-79" comment="Win2K/XP/2003 service pack 2 (or earlier) is installed" negate="false"/>
          <criterion test_ref="cmp-298" comment="A vulnerable version of tcpip.sys is installed." negate="false"/>
          <criterion test_ref="wrt-443" comment="the patch KB893066 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1747" class="vulnerability">
      <affected family="hp-ux">
        <hpux:platform>HP-UX 11</hpux:platform>
        <product>Apache</product>
      </affected>
      <dates>
        <submitted date="2006-03-18-07:24">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-03-22-11:10">DRAFT</status_change>
        <status_change date="2006-04-06-06:31">INTERIM</status_change>
        <status_change date="2006-05-03-10:06">ACCEPTED</status_change>
      </dates>
      <description>Off-by-one error in the mod_ssl Certificate Revocation List (CRL) verification callback in Apache, when configured to use a CRL, allows remote attackers to cause a denial of service (child process crash) via a CRL that causes a buffer overflow of one null byte.</description>
      <reference source="CVE">CVE-2005-1268</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-672" comment="700 Series OS Release 11.04" negate="false"/>
          <criterion test_ref="hst-70" comment="Webproxy is installed" negate="false"/>
          <criterion test_ref="hpt-40" comment="Patch PHSS_34163 or later is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1748" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>FrontPage Server Extensions</product>
      </affected>
      <dates>
        <submitted date="2006-04-13-02:47">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-04-19-10:08">DRAFT</status_change>
      </dates>
      <description>Cross-site scripting (XSS) vulnerability in _vti_bin/_vti_adm/fpadmdll.dll in Microsoft FrontPage Server Extensions 2002 and SharePoint Team Services allows remote attackers to inject arbitrary web script or HTML, then leverage the attack to execute arbitrary programs or create new accounts, via the (1) operation, (2) command, and (3) name parameters.</description>
      <reference source="CVE">CVE-2006-0015</reference>
      <status>DRAFT</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-78" comment="Windows 2000, XP, or 2003 is installed" negate="false"/>
          <criterion test_ref="wft-799" comment="the version of fpadmdll.dll is less than 10.0.6790.0" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1749" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>Windows Shell</product>
      </affected>
      <dates>
        <submitted date="2004-10-14-03:38">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <status_change date="2004-10-20-02:35">DRAFT</status_change>
        <status_change date="2004-11-03-12:00">INTERIM</status_change>
        <status_change date="2004-12-09-08:46">ACCEPTED</status_change>
        <modified date="2005-09-26-01:33" comment="modified wft-517 - Changed comment to match test">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-28-01:04">INTERIM</status_change>
        <status_change date="2005-10-19-05:47">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in Microsoft Internet Explorer and Explorer on Windows XP SP1, WIndows 2000, Windows 98, and Windows Me may allow remote malicious servers to cause a denial of service (application crash) and possibly execute arbitrary code via long share names, as demonstrated using Samba.</description>
      <reference source="CVE">CVE-2004-0214</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" negate="false"/>
          <criterion test_ref="cmp-1124" comment="a vulnerable version of shell32.dll exists" negate="false"/>
          <criterion test_ref="wrt-537" comment="the patch q841356 is installed (Hotfix key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1750" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Office</product>
      </affected>
      <dates>
        <submitted date="2006-03-15-10:53">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-03-15-07:17">DRAFT</status_change>
        <status_change date="2006-04-06-06:31">INTERIM</status_change>
        <status_change date="2006-05-03-10:06">ACCEPTED</status_change>
      </dates>
      <description>Stack-based buffer overflow in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-complicit attackers to execute arbitrary code via an Excel file with a malformed record with a modified length value, which leads to memory corruption.</description>
      <reference source="CVE">CVE-2006-0031</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-650" comment="Excel 2003 is installed" negate="false"/>
          <criterion test_ref="wft-773" comment="the version of excel.exe is less than 11.0.8012.0" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1751" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>VDM</product>
      </affected>
      <dates>
        <submitted date="2004-10-13-11:27">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </submitted>
        <modified date="2004-10-13-11:42" comment="fixed OS ">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <status_change date="2004-10-13-01:15">DRAFT</status_change>
        <status_change date="2004-10-27-12:00">INTERIM</status_change>
        <status_change date="2004-11-17-10:00">ACCEPTED</status_change>
      </dates>
      <description>The Virtual DOS Machine (VDM) subsystem of Microsoft Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows local users to access kernel memory and gain privileges via a malicious program that modified some system structures in a way that is not properly validated by privileged operating system functions.</description>
      <reference source="CVE">CVE-2004-0208</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-547" comment="the patch KB840987 is installed (Hotfix key)" negate="true"/>
          <criterion test_ref="wft-508" comment="the version of win32k.sys is less than 5.2.3790.198" negate="false"/>
          <criterion test_ref="cmp-1113" comment="Windows 2003 Server or Windows XP 64-bit" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1754" class="vulnerability">
      <affected family="hp-ux">
        <hpux:platform>HP-UX 11</hpux:platform>
        <product>LDAP</product>
      </affected>
      <dates>
        <submitted date="2006-04-06-06:39">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-04-12-05:16">DRAFT</status_change>
        <status_change date="2006-05-03-10:06">INTERIM</status_change>
      </dates>
      <description>'An undisclosed vulnerability has been identified in su when used with LDAP.  The potential vulnerability could be exploited by a local authorized user to gain unauthorized access.'</description>
      <reference source="MISC">http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00637553</reference>
      <status>INTERIM</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-618" comment="700 Series or 800 Series OS Release 11.11" negate="false"/>
          <criterion test_ref="hpt-62" comment="Patch PHCO_34545 or subsequent is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1761" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Windows kernel</product>
      </affected>
      <dates>
        <submitted date="2005-05-02-12:00">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </submitted>
        <status_change date="2005-05-04-12:00">DRAFT</status_change>
        <status_change date="2005-06-01-12:00">INTERIM</status_change>
        <modified date="2005-06-02-12:00" comment="Added product">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-06-22-12:38">ACCEPTED</status_change>
      </dates>
      <description>The kernel of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via certain access requests.</description>
      <reference source="CVE">CVE-2005-0061</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wft-583" comment="The version of Ntoskrnl.exe is less than 5.2.3790.280" negate="false"/>
          <criterion test_ref="wrt-427" comment="the patch KB890859 is installed (Hotfix key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1762" class="vulnerability">
      <affected family="hp-ux">
        <hpux:platform>HP-UX 11</hpux:platform>
        <product>ftpd</product>
      </affected>
      <dates>
        <submitted date="2006-04-06-06:39">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-04-12-05:16">DRAFT</status_change>
        <status_change date="2006-05-03-10:06">INTERIM</status_change>
      </dates>
      <description>The wu_fnmatch function in wu_fnmatch.c for wu-fptd 2.6.1 and 2.6.2 allows remote attackers to cause a denial of service (CPU exhaustion by recursion) via a glob pattern with a large number of * (wildcard) characters, as demonstrated using the dir copmmand.</description>
      <reference source="CVE">CVE-2005-0256</reference>
      <status>INTERIM</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-618" comment="700 Series or 800 Series OS Release 11.11" negate="false"/>
          <criterion test_ref="cmp-824" comment="INETSVCS-RUN without patch PHNE_34544 or later, OR WUFTP-26.INETSVCS-FTP with version less than B.11.11.01.008 is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1764" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2006-04-12-12:55">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-04-12-05:16">DRAFT</status_change>
        <status_change date="2006-05-03-10:06">INTERIM</status_change>
      </dates>
      <description>Unspecified vulnerability in Windows Explorer in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote attackers to execute arbitrary code via attack vectors involving COM objects and "crafted files and directories," aka the "Windows Shell Vulnerability."</description>
      <reference source="CVE">CVE-2006-0012</reference>
      <status>INTERIM</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wrt-10026" comment="Win2K/XP/2003 is patched" negate="true"/>
          <criterion test_ref="wft-791" comment="the version of shell32.dll is less than 6.0.3790.503" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1766" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Internet Explorer</product>
      </affected>
      <dates>
        <submitted date="2006-04-12-12:55">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-04-12-05:16">DRAFT</status_change>
        <status_change date="2006-05-03-10:06">INTERIM</status_change>
      </dates>
      <description>Buffer overflow in mshtml.dll in Microsoft Internet Explorer 6.0.2900.2180, and probably other versions, allows remote attackers to execute arbitrary code via an HTML tag with a large number of script action handlers such as onload and onmouseover, as demonstrated using onclick, aka the "Multiple Event Handler Memory Corruption Vulnerability."</description>
      <reference source="CVE">CVE-2006-1245</reference>
      <status>INTERIM</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wrt-4" comment="Win2K/XP/2003 service pack 1 is installed" negate="false"/>
          <criterion test_ref="wft-779" comment="the version of mshtml.dll is less than 6.0.3790.2666" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1769" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Outlook Express</product>
      </affected>
      <dates>
        <submitted date="2006-04-12-12:55">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-04-12-05:16">DRAFT</status_change>
        <status_change date="2006-05-03-10:06">INTERIM</status_change>
      </dates>
      <description>Buffer overflow in Microsoft Outlook Express 5.5 and 6 allows remote attackers to execute arbitrary code via a crafted Windows Address Book (WAB) file containing "certain Unicode strings" and modified length values.</description>
      <reference source="CVE">CVE-2006-0014</reference>
      <status>INTERIM</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-2" comment="Windows XP is installed" negate="false"/>
          <criterion test_ref="wrt-70" comment="64-Bit version of Windows is installed" negate="false"/>
          <criterion test_ref="wrt-10004" comment="Outlook Express 6.0 is installed" negate="false"/>
          <criterion test_ref="wft-796" comment="the version of inetcomm.dll is less than 6.0.3790.2663" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1771" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Outlook Express</product>
      </affected>
      <dates>
        <submitted date="2006-04-12-12:55">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-04-12-05:16">DRAFT</status_change>
        <status_change date="2006-05-03-10:06">INTERIM</status_change>
      </dates>
      <description>Buffer overflow in Microsoft Outlook Express 5.5 and 6 allows remote attackers to execute arbitrary code via a crafted Windows Address Book (WAB) file containing "certain Unicode strings" and modified length values.</description>
      <reference source="CVE">CVE-2006-0014</reference>
      <status>INTERIM</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wrt-10026" comment="Win2K/XP/2003 is patched" negate="true"/>
          <criterion test_ref="wrt-70" comment="64-Bit version of Windows is installed" negate="false"/>
          <criterion test_ref="wrt-10004" comment="Outlook Express 6.0 is installed" negate="false"/>
          <criterion test_ref="wft-798" comment="the version of inetcomm.dll is less than 6.0.3790.504" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1773" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Internet Explorer</product>
      </affected>
      <dates>
        <submitted date="2006-04-12-12:55">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-04-12-05:16">DRAFT</status_change>
        <status_change date="2006-05-03-10:06">INTERIM</status_change>
      </dates>
      <description>Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via HTML elements with a certain crafted tag, which leads to memory corruption.</description>
      <reference source="CVE">CVE-2006-1188</reference>
      <status>INTERIM</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-692" comment="Windows XP (64-bit,SP1 or 32-bit,SP2) is installed" negate="false"/>
          <criterion test_ref="wft-777" comment="the version of mshtml.dll is less than 6.0.2900.2873" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1774" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Internet Explorer</product>
      </affected>
      <dates>
        <submitted date="2006-04-12-12:55">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-04-12-05:16">DRAFT</status_change>
        <status_change date="2006-05-03-10:06">INTERIM</status_change>
      </dates>
      <description>Unspecified vulnerability in Microsoft Internet Explorer 6.0 allows remote attackers to execute HTA files via unknown vectors.</description>
      <reference source="CVE">CVE-2006-1388</reference>
      <status>INTERIM</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-212" comment="Windows 2000 Service Pack 4 (or later) is installed" negate="false"/>
          <criterion test_ref="wrt-651" comment="Internet Explorer 5.01 (any patch level) is installed" negate="false"/>
          <criterion test_ref="wft-775" comment="the version of mshtml.dll is less than 5.0.3839.2200" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1778" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>MDAC</product>
      </affected>
      <dates>
        <submitted date="2006-04-12-12:55">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-04-12-05:16">DRAFT</status_change>
        <status_change date="2006-05-03-10:06">INTERIM</status_change>
      </dates>
      <description>Unspecified vulnerability in the RDS.Dataspace ActiveX control, which is contained in ActiveX Data Objects (ADO) and distributed in Microsoft Data Access Components (MDAC) 2.7 and 2.8, allows remote attackers to execute arbitrary code via unknown attack vectors.</description>
      <reference source="CVE">CVE-2006-0003</reference>
      <status>INTERIM</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-212" comment="Windows 2000 Service Pack 4 (or later) is installed" negate="false"/>
          <criterion test_ref="cmp-836" comment="MDAC 2.5(SP3), 2.7(SP1), 2.8, or 2.8(SP1) is installed without patches for MS06-014" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1780" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Outlook Express</product>
      </affected>
      <dates>
        <submitted date="2006-04-12-12:55">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-04-12-05:16">DRAFT</status_change>
        <status_change date="2006-05-03-10:06">INTERIM</status_change>
      </dates>
      <description>Buffer overflow in Microsoft Outlook Express 5.5 and 6 allows remote attackers to execute arbitrary code via a crafted Windows Address Book (WAB) file containing "certain Unicode strings" and modified length values.</description>
      <reference source="CVE">CVE-2006-0014</reference>
      <status>INTERIM</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-10001" comment="Outlook Express 5.5 is installed" negate="false"/>
          <criterion test_ref="wft-793" comment="the version of inetcomm.dll is less than 5.50.4963.1700" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1781" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Task Scheduler</product>
      </affected>
      <dates>
        <submitted date="2004-07-14-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <status_change date="2004-08-04-12:00">INTERIM</status_change>
        <status_change date="2004-08-25-12:00">ACCEPTED</status_change>
        <modified date="2004-09-14-10:03" comment="">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2004-09-15-12:00">INTERIM</status_change>
        <status_change date="2004-09-29-12:00">ACCEPTED</status_change>
      </dates>
      <description>Stack-based buffer overflow in the Task Scheduler for Windows 2000 and XP, and Internet Explorer 6 on Windows NT 4.0, allows local or remote attackers to execute arbitrary code via a .job file containing long parameters, as demonstrated using Internet Explorer and accessing a .job file on an anonymous share.</description>
      <reference source="CVE">CVE-2004-0212</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wft-455" comment="the version of mstask.dll is less than 5.1.2600.1555" negate="false"/>
          <criterion test_ref="wrt-483" comment="Patch Windows2000-kb841873-x86-enu.exe Installed" negate="true"/>
          <criterion test_ref="cmp-1102" comment="Windows XP 64-bit with SP1 (or earlier) installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1783" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Internet Explorer</product>
      </affected>
      <dates>
        <submitted date="2006-04-12-12:55">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-04-12-05:16">DRAFT</status_change>
        <status_change date="2006-05-03-10:06">INTERIM</status_change>
      </dates>
      <description>Microsoft Internet Explorer 5.01 through 6 does not always return the correct IOleClientSite information when dynamically creating an embedded object, which could cause Internet Explorer to run the object in the wrong security context or zone, and allow remote attackers to execute arbitrary code.</description>
      <reference source="CVE">CVE-2006-1190</reference>
      <status>INTERIM</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wrt-10026" comment="Win2K/XP/2003 is patched" negate="true"/>
          <criterion test_ref="wft-778" comment="the version of mshtml.dll is less than 6.0.3790.507" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1786" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2006-03-21-04:03">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-03-22-11:10">DRAFT</status_change>
        <status_change date="2006-04-06-06:31">INTERIM</status_change>
        <status_change date="2006-05-03-10:06">ACCEPTED</status_change>
      </dates>
      <description>Stack-based buffer overflow in xpm_extract_color (io-xpm.c) in the XPM image decoder for gtk+ 2.4.4 (gtk2) and earlier, and gdk-pixbuf before 0.22, may allow remote attackers to execute arbitrary code via a certain color string.  NOTE: this identifier is ONLY for gtk+.  It was incorrectly referenced in an advisory for a different issue (CVE-2004-0688).</description>
      <reference source="CVE">CVE-2004-0783</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-792" comment="GNOME 2.0 Solaris 8 (SPARC) meets Sun Alert ID 101776 criteria." negate="false"/>
          <criterion test_ref="cmp-793" comment="GNOME 2.0 Solaris 8 (x86) meets Sun Alert ID 101776 criteria." negate="false"/>
          <criterion test_ref="cmp-794" comment="GNOME 2.0 Solaris 9 (SPARC) meets Sun Alert ID 101776 criteria." negate="false"/>
          <criterion test_ref="cmp-795" comment="GNOME 2.0.2 Solaris 9 (SPARC) meets Sun Alert ID 101776 criteria." negate="false"/>
          <criterion test_ref="cmp-796" comment="GNOME 2.0 Solaris 9 (x86) meets Sun Alert ID 101776 criteria." negate="false"/>
          <criterion test_ref="cmp-797" comment="GNOME 2.0.2 Solaris 9 (x86) meets Sun Alert ID 101776 criteria." negate="false"/>
          <criterion test_ref="cmp-798" comment="Solaris 9 (x86) with JDS release 2 meets Sun Alert ID 101776 criteria." negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1791" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Outlook Express</product>
      </affected>
      <dates>
        <submitted date="2006-04-12-12:55">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-04-12-05:16">DRAFT</status_change>
        <status_change date="2006-05-03-10:06">INTERIM</status_change>
      </dates>
      <description>Buffer overflow in Microsoft Outlook Express 5.5 and 6 allows remote attackers to execute arbitrary code via a crafted Windows Address Book (WAB) file containing "certain Unicode strings" and modified length values.</description>
      <reference source="CVE">CVE-2006-0014</reference>
      <status>INTERIM</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wrt-4" comment="Win2K/XP/2003 service pack 1 is installed" negate="false"/>
          <criterion test_ref="wrt-10004" comment="Outlook Express 6.0 is installed" negate="false"/>
          <criterion test_ref="wft-797" comment="the version of inetcomm.dll is less than 6.0.3790.2663" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1793" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Microsoft Internet Explorer 6</product>
      </affected>
      <dates>
        <submitted date="2004-07-30-04:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <status_change date="2004-08-02-04:00">DRAFT</status_change>
        <status_change date="2004-08-25-04:00">INTERIM</status_change>
        <status_change date="2004-09-09-04:00">ACCEPTED</status_change>
        <modified date="2005-09-20-04:00" comment="modified wrt-18 - Changed value element to include pattern match">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-21-01:27">INTERIM</status_change>
        <modified date="2005-09-26-12:19" comment="modified wft-268 - Changed comment to match test">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Double-free vulnerability in mshtml.dll for certain versions of Internet Explorer 6.x allows remote attackers to cause a denial of service (application crash) via a malformed GIF image.</description>
      <reference source="CVE">CVE-2003-1048</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-18" comment="Internet Explorer 6 is installed" negate="false"/>
          <criterion test_ref="wft-268" comment="the version of mshtml.dll is less than 6.0.2743.600" negate="false"/>
          <criterion test_ref="wrt-245" comment="the patch kb832894 is installed (Installed Components key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1795" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 95</windows:platform>
        <windows:platform>Microsoft Windows 98</windows:platform>
        <windows:platform>Microsoft Windows ME</windows:platform>
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Samba</product>
      </affected>
      <dates>
        <submitted date="2005-09-15-04:00">
          <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
        </submitted>
        <status_change date="2005-09-21-01:33">DRAFT</status_change>
        <status_change date="2005-10-12-05:49">INTERIM</status_change>
        <status_change date="2005-11-16-08:02">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in Microsoft Word 2002 (10.6612.6714) SP3, and possibly other versions, allows remote attackers to cause a denial of service (application exception) and possibly execute arbitrary code in winword.exe via certain unexpected values in a .doc file, including (1) an offset that triggers an out-of-bounds memory access, (2) a certain value that causes a large memory copy as triggered by an integer conversion error, and other values.</description>
      <reference source="CVE">CVE-2004-0963</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-607" comment="Word 2003 is installed" negate="false"/>
          <criterion test_ref="wft-612" comment="the version of winword.exe is less than 11.0.6502.0" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1808" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Negotiate SSP interface</product>
      </affected>
      <dates>
        <submitted date="2004-06-14-12:00">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </submitted>
        <status_change date="2004-06-30-12:00">INTERIM</status_change>
        <status_change date="2004-07-12-12:00">ACCEPTED</status_change>
        <modified date="2005-01-13-12:00" comment="modified wft-345 - Addded a space in the registry key component of the file path">
          <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
        </modified>
        <status_change date="2005-01-20-01:26">INTERIM</status_change>
        <status_change date="2005-02-16-12:00">ACCEPTED</status_change>
      </dates>
      <description>The Negotiate Security Software Provider (SSP) interface in Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service (crash from null dereference) or execute arbitrary code via a crafted SPNEGO NegTokenInit request during authentication protocol selection.</description>
      <reference source="CVE">CVE-2004-0119</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
          <criterion test_ref="wrt-187" comment="the patch kb835732 is installed" negate="true"/>
          <criterion test_ref="wft-345" comment="The version of Ipnathlp.dll is less than 5.0.2195.6902" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wmt-206" comment="Negotiate is enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1813" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Distributed Component Object Model (DCOM) interface</product>
      </affected>
      <dates>
        <submitted date="2005-01-18-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2005-01-20-02:31">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Heap-based buffer overflow in the Distributed Component Object Model (DCOM) interface in the RPCSS Service allows remote attackers to execute arbitrary code via a malformed DCERPC DCOM object activation request packet with modified length fields, a different vulnerability than CVE-2003-0352 (Blaster/Nachi) and CVE-2003-0528.</description>
      <reference source="CVE">CVE-2003-0715</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-57" comment="Windows XP 32-bit SP1 is installed" negate="false"/>
          <criterion test_ref="wft-366" comment="the version of rpcrt4.dll is less than 5.1.2600.1254" negate="false"/>
          <criterion test_ref="wrt-281" comment="the patch kb824146 is installed (Hotfix key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-283" comment="DCOM is enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1822" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Client Server Runtime System (CSRSS)</product>
      </affected>
      <dates>
        <submitted date="2005-05-02-12:00">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </submitted>
        <status_change date="2005-05-04-12:00">DRAFT</status_change>
        <status_change date="2005-06-01-12:00">INTERIM</status_change>
        <modified date="2005-06-02-12:00" comment="Added product">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-06-22-12:38">ACCEPTED</status_change>
      </dates>
      <description>Stack-based buffer overflow in WINSRV.DLL in the Client Server Runtime System (CSRSS) process of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via a specially-designed application that provides console window information with a long FaceName value.</description>
      <reference source="CVE">CVE-2005-0551</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wft-583" comment="The version of Ntoskrnl.exe is less than 5.2.3790.280" negate="false"/>
          <criterion test_ref="wrt-427" comment="the patch KB890859 is installed (Hotfix key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1837" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Program Group Converter</product>
      </affected>
      <dates>
        <submitted date="2004-10-14-03:39">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <status_change date="2004-10-20-02:35">DRAFT</status_change>
        <status_change date="2004-11-03-12:00">INTERIM</status_change>
        <status_change date="2004-12-09-08:46">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the Windows Program Group Converter (grpconv.exe) may allow remote attackers to execute arbitrary code via a shell: URL with a long filename and a .grp extension, which is not properly handled when the shell capability launches grpconv.exe.</description>
      <reference source="CVE">CVE-2004-0572</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-2" comment="Windows XP is installed" negate="false"/>
          <criterion test_ref="wrt-70" comment="64-Bit version of Windows is installed" negate="false"/>
          <criterion test_ref="wrt-29" comment="Win2K/XP/2003 service pack 2 (or later) is installed" negate="true"/>
          <criterion test_ref="cmp-1133" comment="a vulnerable version of grpconv.exe exists" negate="false"/>
          <criterion test_ref="wrt-537" comment="the patch q841356 is installed (Hotfix key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1840" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>LDAP</product>
      </affected>
      <dates>
        <submitted date="2006-04-14-06:41">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-04-19-10:08">DRAFT</status_change>
      </dates>
      <description>Unspecified vulnerability in Solaris 8 and 9 allows local users to obtain the LDAP Directory Server root Distinguished Name (rootDN) password when a privileged user (1) runs idsconfig; or "insecurely" runs LDAP2 commands with the -w option, including (2) ldapadd, (3) ldapdelete, (4) ldapmodify, (5) ldapmodrdn, and (6) ldapsearch.</description>
      <reference source="CVE">CVE-2006-1782</reference>
      <status>DRAFT</status>
      <version>0</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-856" comment="Solaris 8 (SPARC) meets Sun Alert ID 102113 criteria." negate="false"/>
          <criterion test_ref="cmp-857" comment="Solaris 9 (SPARC) meets Sun Alert ID 102113 criteria." negate="false"/>
          <criterion test_ref="cmp-858" comment="Solaris 8 (x86) meets Sun Alert ID 102113 criteria." negate="false"/>
          <criterion test_ref="cmp-859" comment="Solaris 9 (x86) meets Sun Alert ID 102113 criteria." negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1843" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Program Group Converter</product>
      </affected>
      <dates>
        <submitted date="2004-10-14-03:39">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <status_change date="2004-10-20-02:35">DRAFT</status_change>
        <status_change date="2004-11-03-12:00">INTERIM</status_change>
        <status_change date="2004-12-09-08:46">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the Windows Program Group Converter (grpconv.exe) may allow remote attackers to execute arbitrary code via a shell: URL with a long filename and a .grp extension, which is not properly handled when the shell capability launches grpconv.exe.</description>
      <reference source="CVE">CVE-2004-0572</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-2" comment="Windows XP is installed" negate="false"/>
          <criterion test_ref="wrt-72" comment="32-Bit version of Windows is installed" negate="false"/>
          <criterion test_ref="wrt-29" comment="Win2K/XP/2003 service pack 2 (or later) is installed" negate="true"/>
          <criterion test_ref="cmp-1136" comment="a vulnerable version of grpconv.exe exists" negate="false"/>
          <criterion test_ref="wrt-537" comment="the patch q841356 is installed (Hotfix key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1844" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>NIS</product>
      </affected>
      <dates>
        <submitted date="2004-12-29-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-12-12:41">DRAFT</status_change>
        <status_change date="2005-02-02-12:00">INTERIM</status_change>
        <status_change date="2005-02-23-09:25">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in ypbind daemon in Solaris 5.4 through 8 allows remote attackers to execute arbitrary code.</description>
      <reference source="CVE">CVE-2001-1328</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-43" comment="Solaris 7 or 8 installed" negate="false"/>
          <criterion test_ref="sat-13" comment="NIS/NIS+ Utilities installed (SUNWnisu)" negate="false"/>
          <criterion test_ref="spt-8" comment="Patch 108750-02 or later installed" negate="true"/>
          <criterion test_ref="spt-9" comment="Patch 110322-01 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-3" comment="ypbind running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1847" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>SMB (Server Message Block)</product>
      </affected>
      <dates>
        <submitted date="2005-02-15-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2005-02-18-10:39">DRAFT</status_change>
        <status_change date="2005-03-09-07:56">INTERIM</status_change>
        <status_change date="2005-03-29-07:59">ACCEPTED</status_change>
      </dates>
      <description>The Server Message Block (SMB) implementation for Windows NT 4.0, 2000, XP, and Server 2003 does not properly validate certain SMB packets, which allows remote attackers to execute arbitrary code via Transaction responses containing (1) Trans or (2) Trans2 commands, aka the "Server Message Block Vulnerability," and as demonstrated using Trans2 FIND_FIRST2 responses with large file name length fields.</description>
      <reference source="CVE">CVE-2005-0045</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wft-381" comment="the version of mrxsmb.sys is less than 5.2.3790.252" negate="false"/>
          <criterion test_ref="wrt-90" comment="the patch KB885250 is installed" negate="true"/>
          <criterion test_ref="cmp-187" comment="Windows Server 2003 32-bit OR 64-bit OR Windows XP 64-bit Version 2003 is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1852" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>NetDDE</product>
      </affected>
      <dates>
        <submitted date="2004-10-13-04:09">
          <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
        </submitted>
        <status_change date="2004-10-20-02:35">DRAFT</status_change>
        <status_change date="2004-11-03-12:00">INTERIM</status_change>
        <status_change date="2004-12-09-08:46">ACCEPTED</status_change>
      </dates>
      <description>Network Dynamic Data Exchange (NetDDE) services for Microsoft Windows 98, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows attackers to remotely execute arbitrary code or locally gain privileges via a malicious message or application that involves an "unchecked buffer," possibly a buffer overflow.</description>
      <reference source="CVE">CVE-2004-0206</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-45" comment="Windows NT Server 4.0, Terminal Server Edition is installed" negate="false"/>
          <criterion test_ref="wft-520" comment="the version of nddenb32.dll is less than 4.0.1381.33565" negate="false"/>
          <criterion test_ref="wft-521" comment="the version of netdde.exe is less than 4.0.1381.33574" negate="false"/>
          <criterion test_ref="wrt-551" comment="the patch KB841533 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1872" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Enhanced Metafile (EMF)</product>
      </affected>
      <dates>
        <submitted date="2004-10-14-09:59">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </submitted>
        <status_change date="2004-10-20-02:35">DRAFT</status_change>
        <status_change date="2004-11-03-12:00">INTERIM</status_change>
        <status_change date="2004-12-09-08:46">ACCEPTED</status_change>
      </dates>
      <description>Unknown vulnerability in the Graphics Rendering Engine processes of Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code via (1) Windows Metafile (WMF) or (2) Enhanced Metafile (EMF) image formats that involve "an unchecked buffer."</description>
      <reference source="CVE">CVE-2004-0209</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-2" comment="Windows XP is installed" negate="false"/>
          <criterion test_ref="wrt-547" comment="the patch KB840987 is installed (Hotfix key)" negate="true"/>
          <criterion test_ref="wft-535" comment="the version of vdmdbg.dll is less than 5.1.2600.1560" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1880" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>dtspcd</product>
      </affected>
      <dates>
        <submitted date="2005-02-01-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-02-01-08:41">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>The CDE dtspcd daemon allows local users to execute arbitrary commands via a symlink attack.</description>
      <reference source="CVE">CVE-1999-0689</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="sat-49" comment="CDE Daemons (SUNWdtdmn) installed" negate="false"/>
          <criterion test_ref="spt-107" comment="Patch 108221-01 or later installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1886" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Windows kernel</product>
      </affected>
      <dates>
        <submitted date="2005-01-05-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2005-01-06-12:00">DRAFT</status_change>
        <status_change date="2005-02-02-12:00">INTERIM</status_change>
        <status_change date="2005-02-23-12:00">ACCEPTED</status_change>
        <modified date="2005-04-08-12:00" comment="modified wft-154 - wft-154 corrected literal string">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <status_change date="2005-04-11-08:48">INTERIM</status_change>
        <status_change date="2005-04-27-12:07">ACCEPTED</status_change>
      </dates>
      <description>The Local Procedure Call (LPC) interface of the Windows Kernel for Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 does not properly validate the lengths of messages sent to the LPC port, which allows local users to gain privileges, aka "Windows Kernel Vulnerability."</description>
      <reference source="CVE">CVE-2004-0893</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wft-154" comment="The version of Ntoskrnl.exe is less than 5.1.2600.1605" negate="false"/>
          <criterion test_ref="wrt-36" comment="the patch kb885835is installed (Hotfix key)" negate="true"/>
          <criterion test_ref="cmp-1058" comment="Windows XP 32-bit edition is installed" negate="false"/>
          <criterion test_ref="wrt-4" comment="Win2K/XP/2003 service pack 1 is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1888" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Local Security Authority Subsystem Service (LSASS)</product>
      </affected>
      <dates>
        <submitted date="2005-01-04-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2005-01-12-12:41">DRAFT</status_change>
        <status_change date="2005-02-02-12:00">INTERIM</status_change>
        <status_change date="2005-02-23-09:25">ACCEPTED</status_change>
      </dates>
      <description>LSASS (Local Security Authority Subsystem Service) of Windows 2000 Server and Windows Server 2003 does not properly validate connection information, which allows local users to gain privileges via a specially-designed program.</description>
      <reference source="CVE">CVE-2004-0894</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-34" comment="Microsoft Windows Server 2003 64-Bit Edition " negate="false"/>
          <criterion test_ref="wft-160" comment="the version of lsasrv.dll is less than 5.2.3790.220" negate="false"/>
          <criterion test_ref="wrt-36" comment="the patch kb885835is installed (Hotfix key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1889" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>SMB (Server Message Block)</product>
      </affected>
      <dates>
        <submitted date="2005-03-29-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2005-03-29-08:38">DRAFT</status_change>
        <status_change date="2005-04-13-12:15">INTERIM</status_change>
        <status_change date="2005-05-04-12:33">ACCEPTED</status_change>
      </dates>
      <description>The Server Message Block (SMB) implementation for Windows NT 4.0, 2000, XP, and Server 2003 does not properly validate certain SMB packets, which allows remote attackers to execute arbitrary code via Transaction responses containing (1) Trans or (2) Trans2 commands, aka the "Server Message Block Vulnerability," and as demonstrated using Trans2 FIND_FIRST2 responses with large file name length fields.</description>
      <reference source="CVE">CVE-2005-0045</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-61" comment="Windows XP SP1 OR Windows XP 64-bit SP1 is installed" negate="false"/>
          <criterion test_ref="wft-382" comment="the version of mrxsmb.sys is less than 5.1.2600.1620" negate="false"/>
          <criterion test_ref="wrt-90" comment="the patch KB885250 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1905" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>CDE</product>
      </affected>
      <dates>
        <submitted date="2005-02-01-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-02-01-08:41">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Heap-based buffer overflow in dtsession for Solaris 2.5.1 through Solaris 9 allows local users to gain root privileges via a long HOME environment variable.</description>
      <reference source="CVE">CVE-2003-0092</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" negate="false"/>
          <criterion test_ref="sat-47" comment="CDE Desktop Window Manager (SUNWdtwm) installed" negate="false"/>
          <criterion test_ref="spt-100" comment="Patch 107702-12 or later installed" negate="true"/>
          <criterion test_ref="spt-101" comment="Patch 109354-19 or later installed" negate="true"/>
          <criterion test_ref="spt-102" comment="Patch 114497-01 or later installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1910" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Windows XP</product>
      </affected>
      <dates>
        <submitted date="2005-08-18-04:00">
          <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
        </submitted>
        <status_change date="2005-08-25-10:05">DRAFT</status_change>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (reset TCP connections) via spoofed ICMP error messages, aka the "blind connection-reset attack."  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</description>
      <reference source="CVE">CVE-2004-0790</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-2" comment="Windows XP is installed" negate="false"/>
          <criterion test_ref="cmp-23" comment="32-bit version of Windows or 64-bit (itanium architecture) version of Windows is installed" negate="false"/>
          <criterion test_ref="wrt-79" comment="Win2K/XP/2003 service pack 2 (or earlier) is installed" negate="false"/>
          <criterion test_ref="cmp-298" comment="A vulnerable version of tcpip.sys is installed." negate="false"/>
          <criterion test_ref="wrt-443" comment="the patch KB893066 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1943" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>HTML Help Facility</product>
      </affected>
      <dates>
        <submitted date="2004-07-14-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <status_change date="2004-08-04-12:00">INTERIM</status_change>
        <status_change date="2004-08-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 5.x and 6.0 allows remote attackers to execute arbitrary programs via a modified directory traversal attack using a URL containing ".." (dot dot) sequences and a filename that ends in "::" which is treated as a .chm file even if it does not have a .chm extension.  NOTE: this bug may overlap CVE-2004-0475.</description>
      <reference source="CVE">CVE-2003-1041</reference>
      <status>ACCEPTED</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
          <criterion test_ref="wft-444" comment="the version of itss.dll is less than 5.2.3790.185" negate="false"/>
          <criterion test_ref="wrt-482" comment="the patch kb840315 is installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-491" comment="HTML Help is registered" negate="true"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1950" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Microsoft Outlook Express</product>
      </affected>
      <dates>
        <submitted date="2004-08-26-08:05">
          <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
        </submitted>
        <status_change date="2004-08-26-08:14">DRAFT</status_change>
        <status_change date="2004-09-09-12:00">INTERIM</status_change>
        <status_change date="2004-09-29-12:00">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Outlook Express 5.5 and 6 allows attackers to cause a denial of service (application crash) via a malformed e-mail header.</description>
      <reference source="CVE">CVE-2004-0215</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-173" comment="Outlook Express 6 SP1 is installed" negate="false"/>
          <criterion test_ref="wft-467" comment="the version of inetcomm.dll is less than 6.0.2800.1441" negate="false"/>
          <criterion test_ref="wrt-494" comment="the patch kb823353 is installed " negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-495" comment="all users have the preview pane disabled" negate="true"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1959" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Microsoft Word for Windows 6.0 Converter</product>
      </affected>
      <dates>
        <submitted date="2005-01-05-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2005-01-12-12:00">DRAFT</status_change>
        <status_change date="2005-02-02-12:00">INTERIM</status_change>
        <modified date="2005-03-01-12:00" comment="modified wft-123 - Changed/Corrected literal path">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-03-23-12:00">ACCEPTED</status_change>
        <modified date="2005-04-08-12:00" comment="modified wft-123 - wft-123 corrected literal string">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <status_change date="2005-04-11-08:48">INTERIM</status_change>
        <status_change date="2005-04-27-12:07">ACCEPTED</status_change>
        <modified date="2005-12-20-07:05" comment="Edited criteria. 1) dropped explicit check for Hotfix kb885836, 2) dropped version checks on mswrd wpc files.">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </modified>
        <status_change date="2006-01-04-08:04">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Word for Windows 6.0 Converter does not properly validate certain data lengths, which allows remote attackers to execute arbitrary code via a .wri, .rtf, and .doc file sent by email or malicious web site, aka "Table Conversion Vulnerability," a different vulnerability than CVE-2004-0901.</description>
      <reference source="CVE">CVE-2004-0571</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wft-123" comment="the version of wordpad.exe is less than 5.1.2600.1606" negate="false"/>
          <criterion test_ref="cmp-1058" comment="Windows XP 32-bit edition is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1962" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Negotiate Security Software Provider</product>
      </affected>
      <dates>
        <submitted date="2004-06-15-12:00">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </submitted>
        <status_change date="2004-06-30-12:00">INTERIM</status_change>
        <status_change date="2004-07-12-12:00">ACCEPTED</status_change>
        <modified date="2005-06-02-12:00" comment="Added product">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-06-08-03:17">INTERIM</status_change>
        <status_change date="2005-06-29-06:49">ACCEPTED</status_change>
      </dates>
      <description>The Negotiate Security Software Provider (SSP) interface in Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service (crash from null dereference) or execute arbitrary code via a crafted SPNEGO NegTokenInit request during authentication protocol selection.</description>
      <reference source="CVE">CVE-2004-0119</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="cmp-952" comment="The version of ipnathlp.dll is less than 5.2.3790.142 and 64-bit or 32-bit version of Windows is installed" negate="false"/>
          <criterion test_ref="wrt-187" comment="the patch kb835732 is installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wmt-206" comment="Negotiate is enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1963" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Windows XP</product>
      </affected>
      <dates>
        <submitted date="2005-03-30-12:00">
          <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
        </submitted>
        <status_change date="2005-04-12-08:26">DRAFT</status_change>
        <status_change date="2005-04-27-12:07">INTERIM</status_change>
        <status_change date="2005-06-01-03:30">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 6.0 on Windows XP SP2 allows remote attackers to execute arbitrary code by using the "Related Topics" command in the Help ActiveX Control (hhctrl.ocx) to open a Help popup window containing the PCHealth tools.htm file in the local zone and injecting Javascript to be executed, as demonstrated using "writehta.txt" and the ADODB recordset, which saves a .HTA file to the local system, aka the "HTML Help ActiveX control Cross Domain Vulnerability."</description>
      <reference source="CVE">CVE-2004-1043</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-2" comment="Windows XP is installed" negate="false"/>
          <criterion test_ref="wrt-93" comment="the patch kb890175 is installed" negate="true"/>
          <criterion test_ref="cmp-242" comment="A vulnerable version of hhctrl.ocx exists on Windows XP" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1964" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Task Scheduler</product>
      </affected>
      <dates>
        <submitted date="2004-07-13-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <modified date="2004-07-14-12:00" comment="added compound tests">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </modified>
        <status_change date="2004-08-04-12:00">INTERIM</status_change>
        <status_change date="2004-08-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Stack-based buffer overflow in the Task Scheduler for Windows 2000 and XP, and Internet Explorer 6 on Windows NT 4.0, allows local or remote attackers to execute arbitrary code via a .job file containing long parameters, as demonstrated using Internet Explorer and accessing a .job file on an anonymous share.</description>
      <reference source="CVE">CVE-2004-0212</reference>
      <status>ACCEPTED</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1058" comment="Windows XP 32-bit edition is installed" negate="false"/>
          <criterion test_ref="cmp-1070" comment="Affected mstask.dll file versions based on service pack levels" negate="false"/>
          <criterion test_ref="wrt-483" comment="Patch Windows2000-kb841873-x86-enu.exe Installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1970" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Solaris Management Console (SMC)</product>
      </affected>
      <dates>
        <submitted date="2005-04-13-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-04-20-12:13">DRAFT</status_change>
        <status_change date="2005-05-11-05:41">INTERIM</status_change>
        <status_change date="2005-06-01-03:30">ACCEPTED</status_change>
      </dates>
      <description>Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to execute arbitrary code, as demonstrated in wu-ftpd 2.5.0 through 2.6.2 via commands that cause pathnames of length MAXPATHLEN+1 to trigger a buffer overflow, including (1) STOR, (2) RETR, (3) APPE, (4) DELE, (5) MKD, (6) RMD, (7) STOU, or (8) RNTO.</description>
      <reference source="CVE">CVE-2003-0466</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-6" comment="Solaris 9 Installed" negate="false"/>
          <criterion test_ref="sat-34" comment="FTP Server - Usr (SUNWftpu) installed" negate="false"/>
          <criterion test_ref="spt-60" comment="Patch 114564-02 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-3" comment="inetd.conf contains in.ftpd" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1976" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Microsoft Word for Windows 6.0 Converter</product>
      </affected>
      <dates>
        <submitted date="2005-01-05-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2005-01-12-12:41">DRAFT</status_change>
        <status_change date="2005-02-02-12:00">INTERIM</status_change>
        <status_change date="2005-02-23-09:25">ACCEPTED</status_change>
        <modified date="2005-12-20-07:05" comment="Replaced all criteria. 1) Included all XP,64 versions, 2) dropped explicit check for Hotfix kb885836, 3) check version of wordpad.exe rather than mswrd wpc files.">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </modified>
        <status_change date="2006-01-04-08:04">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Word for Windows 6.0 Converter does not properly validate certain data lengths, which allows remote attackers to execute arbitrary code via a .wri, .rtf, and .doc file sent by email or malicious web site, aka "Table Conversion Vulnerability," a different vulnerability than CVE-2004-0901.</description>
      <reference source="CVE">CVE-2004-0571</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1112" comment="Windows XP 64-bit" negate="false"/>
          <criterion test_ref="wft-713" comment="the version of wordpad.exe is less than 5.2.3790.224" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1982" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Apache</product>
      </affected>
      <dates>
        <submitted date="2004-10-14-01:13">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <modified date="2004-10-18-03:12" comment="Changed apache test to file test">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </modified>
        <modified date="2004-10-19-11:17" comment="Changed apache test to package test">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </modified>
        <status_change date="2004-10-20-02:35">DRAFT</status_change>
        <status_change date="2004-11-03-12:00">INTERIM</status_change>
        <status_change date="2004-12-09-08:46">ACCEPTED</status_change>
      </dates>
      <description>Apache 1.4.x before 1.3.30, and 2.0.x before 2.0.49, when using multiple listening sockets on certain platforms, allows remote attackers to cause a denial of service (blocked new connections) via a "short-lived connection on a rarely-accessed listening socket."</description>
      <reference source="CVE">CVE-2004-0174</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" negate="false"/>
          <criterion test_ref="spt-253" comment="Patch 116973-01 or later installed" negate="true"/>
          <criterion test_ref="spt-254" comment="Patch 113146-05 or later installed" negate="true"/>
          <criterion test_ref="sat-5" comment="Apache (SUNWapchu) installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-10" comment="Apache running (httpd)" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1997" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Negotiate SSP interface</product>
      </affected>
      <dates>
        <submitted date="2004-06-15-12:00">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </submitted>
        <modified date="2004-07-19-12:00" comment="Modifed without comment">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <modified date="2004-07-20-12:00" comment="Modifed without comment">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <status_change date="2004-08-11-12:00">ACCEPTED</status_change>
        <modified date="2004-09-13-11:38" comment="cmp-66 added">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2004-09-15-12:00">INTERIM</status_change>
        <status_change date="2004-09-29-12:00">ACCEPTED</status_change>
      </dates>
      <description>The Negotiate Security Software Provider (SSP) interface in Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service (crash from null dereference) or execute arbitrary code via a crafted SPNEGO NegTokenInit request during authentication protocol selection.</description>
      <reference source="CVE">CVE-2004-0119</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-187" comment="the patch kb835732 is installed" negate="true"/>
          <criterion test_ref="cmp-1095" comment="Version checks on XP for Ipnathlp.dll" negate="false"/>
          <criterion test_ref="cmp-66" comment="Windows XP (sp1 or earlier) is installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wmt-206" comment="Negotiate is enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL2002" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>Solaris Enterprise Authentication Mechanism (SEAM)</product>
      </affected>
      <dates>
        <submitted date="2004-10-11-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2004-10-13-12:00">DRAFT</status_change>
        <modified date="2005-01-14-12:00" comment="Changed two unknown tests for kerberos configuration to Solaris text file contents tests ">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </modified>
        <status_change date="2005-02-02-12:00">INTERIM</status_change>
        <status_change date="2005-02-23-09:25">ACCEPTED</status_change>
      </dates>
      <description>Multiple buffer overflows in krb5_aname_to_localname for MIT Kerberos 5 (krb5) 1.3.3 and earlier allow remote attackers to execute arbitrary code as root.</description>
      <reference source="CVE">CVE-2004-0523</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uft-25" comment="Kerberos 5 installed" negate="false"/>
          <criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" negate="false"/>
          <criterion test_ref="spt-246" comment="Patch 112908-16 or later installed" negate="true"/>
          <criterion test_ref="spt-247" comment="Patch 112536-05 or later installed" negate="true"/>
          <criterion test_ref="cmp-1104" comment="Patches 112237-11 and 112390-09 or greater installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="tft-5" comment="/etc/krb5/krb5.conf is configured with a kerberos domain" negate="false"/>
          <criterion test_ref="tft-6" comment="/etc/krb5/krb5.conf is configured with explicit or rules-based mapping" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL2008" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Windows kernel</product>
      </affected>
      <dates>
        <submitted date="2005-01-05-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2005-01-06-12:00">DRAFT</status_change>
        <status_change date="2005-02-02-12:00">INTERIM</status_change>
        <status_change date="2005-02-23-12:00">ACCEPTED</status_change>
        <modified date="2005-04-08-12:00" comment="modified wft-154 - wft-154 corrected literal string">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <status_change date="2005-04-11-08:48">INTERIM</status_change>
        <status_change date="2005-04-27-12:07">ACCEPTED</status_change>
      </dates>
      <description>The Local Procedure Call (LPC) interface of the Windows Kernel for Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 does not properly validate the lengths of messages sent to the LPC port, which allows local users to gain privileges, aka "Windows Kernel Vulnerability."</description>
      <reference source="CVE">CVE-2004-0893</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wft-154" comment="The version of Ntoskrnl.exe is less than 5.1.2600.1605" negate="false"/>
          <criterion test_ref="wrt-36" comment="the patch kb885835is installed (Hotfix key)" negate="true"/>
          <criterion test_ref="wrt-4" comment="Win2K/XP/2003 service pack 1 is installed" negate="false"/>
          <criterion test_ref="cmp-1112" comment="Windows XP 64-bit" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL2011" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>Bind</product>
      </affected>
      <dates>
        <submitted date="2004-10-19-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2004-10-20-12:00">DRAFT</status_change>
        <status_change date="2004-11-03-12:00">INTERIM</status_change>
        <status_change date="2004-12-09-12:00">ACCEPTED</status_change>
        <modified date="2005-01-11-12:00" comment="modified sat-10 - Changed test to pattern match to check for 64bit version of Core Solaris">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </modified>
        <modified date="2005-01-14-12:00" comment="modified sat-10 - Changed regular expression to properly check for 64bit package">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </modified>
        <status_change date="2005-01-24-02:36">INTERIM</status_change>
        <status_change date="2005-02-16-12:00">ACCEPTED</status_change>
      </dates>
      <description>ISC BIND 8.3.x before 8.3.7, and 8.4.x before 8.4.3, allows remote attackers to poison the cache via a malicious name server that returns negative responses with a large TTL (time-to-live) value.</description>
      <reference source="CVE">CVE-2003-0914</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" negate="false"/>
          <criterion test_ref="spt-270" comment="Patch 106938-08 or later installed" negate="true"/>
          <criterion test_ref="spt-271" comment="Patch 109326-13 or later installed" negate="true"/>
          <criterion test_ref="spt-272" comment="Patch 112970-06 or later installed" negate="true"/>
          <criterion test_ref="sat-10" comment="Core Solaris (SUNWcsu/SUNWcsxu) installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-14" comment="in.named running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL2016" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>Outlook Web Access</product>
      </affected>
      <dates>
        <submitted date="2004-08-25-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2004-08-25-12:24">DRAFT</status_change>
        <status_change date="2004-09-09-12:00">INTERIM</status_change>
        <status_change date="2004-09-29-12:00">ACCEPTED</status_change>
        <modified date="2005-06-02-12:00" comment="Added product">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-06-08-03:17">INTERIM</status_change>
        <status_change date="2005-06-29-06:49">ACCEPTED</status_change>
      </dates>
      <description>Cross-site scripting (XSS) vulnerability in Outlook Web Access for Exchange Server 5.5 Service Pack 4 allows remote attackers to insert arbitrary script and spoof content in HTML email or web caches via an HTML redirect query.</description>
      <reference source="CVE">CVE-2004-0203</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-504" comment="Exchange 5.5 with SP4 Installed" negate="false"/>
          <criterion test_ref="wft-485" comment="the version of cdo.dll is less than 5.5.2558.10" negate="false"/>
          <criterion test_ref="wrt-505" comment="the  patch kb842436 is installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-506" comment="Outlook Web Access exists" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL2022" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>Windows kernel</product>
      </affected>
      <dates>
        <submitted date="2004-07-13-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2004-08-04-12:00">INTERIM</status_change>
        <status_change date="2004-08-25-12:00">ACCEPTED</status_change>
        <modified date="2005-06-02-12:00" comment="Added product">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-06-08-03:17">INTERIM</status_change>
        <status_change date="2005-06-29-06:49">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in Windows Kernel allows local users to gain privileges by causing certain error messages to be passed to a debugger.</description>
      <reference source="CVE">CVE-2003-0112</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" negate="false"/>
          <criterion test_ref="wft-436" comment="The version of Ntoskrnl.exe is less than 4.0.1381.7203" negate="false"/>
          <criterion test_ref="wrt-478" comment="the patch Q811493 is installed" negate="true"/>
          <criterion test_ref="wrt-187" comment="the patch kb835732 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL2025" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>login</product>
      </affected>
      <dates>
        <submitted date="2004-12-29-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-12-12:41">DRAFT</status_change>
        <status_change date="2005-02-02-12:00">INTERIM</status_change>
        <status_change date="2005-02-23-09:25">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in login in various System V based operating systems allows remote attackers to execute arbitrary commands via a large number of arguments through services such as telnet and rlogin.</description>
      <reference source="CVE">CVE-2001-0797</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-43" comment="Solaris 7 or 8 installed" negate="false"/>
          <criterion test_ref="spt-6" comment="Patch 112300-01 or later installed" negate="true"/>
          <criterion test_ref="spt-7" comment="Patch 111085-02 or later installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL2043" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Windows kernel</product>
      </affected>
      <dates>
        <submitted date="2005-05-02-12:00">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </submitted>
        <status_change date="2005-05-04-12:00">DRAFT</status_change>
        <status_change date="2005-06-01-12:00">INTERIM</status_change>
        <modified date="2005-06-02-12:00" comment="Added product">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-06-22-12:38">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to cause a denial of service (i.e., system crash) via a malformed request, aka "Object Management Vulnerability".</description>
      <reference source="CVE">CVE-2005-0550</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-35" comment="Windows XP 32 bit Service Pack 2" negate="false"/>
          <criterion test_ref="wft-581" comment="The version of Ntoskrnl.exe is less than 5.1.2600.2622" negate="false"/>
          <criterion test_ref="wrt-427" comment="the patch KB890859 is installed (Hotfix key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL2046" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Windows 2000</product>
      </affected>
      <dates>
        <submitted date="2005-03-31-12:00">
          <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
        </submitted>
        <status_change date="2005-04-12-08:26">DRAFT</status_change>
        <status_change date="2005-04-27-12:07">INTERIM</status_change>
        <status_change date="2005-06-01-03:30">ACCEPTED</status_change>
        <modified date="2005-12-26-09:40" comment="Removed test to check kb890047.">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </modified>
        <status_change date="2006-01-12-08:59">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via drag and drop events, aka the "Drag-and-Drop Vulnerability."</description>
      <reference source="CVE">CVE-2005-0053</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
          <criterion test_ref="wrt-538" comment="Win2K/XP/2003 service pack 4 (or earlier) is installed" negate="false"/>
          <criterion test_ref="wft-400" comment="the version of shell32.dll is less than 5.0.3900.7009" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-157" comment="Drag-and-Drop disabled when set to 3" negate="true"/>
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL2062" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Local Security Authority Subsystem Service (LSASS)</product>
      </affected>
      <dates>
        <submitted date="2005-01-04-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2005-01-12-12:41">DRAFT</status_change>
        <status_change date="2005-02-02-12:00">INTERIM</status_change>
        <status_change date="2005-02-23-09:25">ACCEPTED</status_change>
      </dates>
      <description>LSASS (Local Security Authority Subsystem Service) of Windows 2000 Server and Windows Server 2003 does not properly validate connection information, which allows local users to gain privileges via a specially-designed program.</description>
      <reference source="CVE">CVE-2004-0894</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1066" comment="Windows XP 64-bit with Service Pack 1" negate="false"/>
          <criterion test_ref="wft-349" comment="the version of lsasrv.dll is less than 5.1.2600.1597" negate="false"/>
          <criterion test_ref="wrt-36" comment="the patch kb885835is installed (Hotfix key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL2065" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>pam_krb5</product>
      </affected>
      <dates>
        <submitted date="2004-10-12-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2004-10-13-12:00">DRAFT</status_change>
        <modified date="2005-01-14-12:00" comment="Changed all unknown tests to solaris file contents tests">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </modified>
        <status_change date="2005-02-02-12:00">INTERIM</status_change>
        <status_change date="2005-02-23-09:25">ACCEPTED</status_change>
      </dates>
      <description>Solaris 9, when configured as a Kerberos client with patch 112908-12 or 115168-03 and using pam_krb5 as an "auth" module with the debug feature enabled, records passwords in plaintext, which could allow local users to gain other user's passwords by reading log files.</description>
      <reference source="CVE">CVE-2004-0653</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-6" comment="Solaris 9 Installed" negate="false"/>
          <criterion test_ref="uft-25" comment="Kerberos 5 installed" negate="false"/>
          <criterion test_ref="spt-248" comment="Patch 112908-13 or later installed" negate="true"/>
          <criterion test_ref="spt-236" comment="Patch 112908-12 installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="tft-7" comment="/etc/pam.conf is configured to use pam_krb5 as an 'auth' module and the debug feature of pam_krb5 is enabled" negate="false"/>
          <criterion test_ref="tft-5" comment="/etc/krb5/krb5.conf is configured with a kerberos domain" negate="false"/>
          <criterion test_ref="tft-8" comment="/etc/syslog.conf is configured to log &quot;debug&quot; level messages for at least daemon" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL2073" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Internet Explorer 5.01 Service Pack 3</product>
      </affected>
      <dates>
        <submitted date="2004-10-25-04:42">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2004-10-27-01:04">DRAFT</status_change>
        <status_change date="2004-11-17-10:00">INTERIM</status_change>
        <status_change date="2004-12-09-08:46">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer in Windows XP SP2, and other versions including 5.01 and 5.5, allows remote attackers to install arbitrary programs via a web page that uses certain styles and the AnchorClick behavior, popup windows, and drag-and-drop capabilities to drop the program in the local startup folder, as demonstrated by "wottapoop.html".</description>
      <reference source="CVE">CVE-2004-0839</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-55" comment="Internet Explorer 5.01 Service Pack 3 is installed" negate="false"/>
          <criterion test_ref="wft-560" comment="the version of mshtml.dll is less than 5.0.3821.2800" negate="false"/>
          <criterion test_ref="wrt-559" comment="the patch kb834707-ie501sp3 is installed (Hotfix key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL2077" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Internet Explorer 5.01 Service Pack 3</product>
      </affected>
      <dates>
        <submitted date="2005-05-10-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2005-05-11-05:38">DRAFT</status_change>
        <status_change date="2005-06-01-03:30">INTERIM</status_change>
        <status_change date="2005-06-22-12:38">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the Content Advisor in Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a crafted Content Advisor file, aka "Content Advisor Memory Corruption Vulnerability."</description>
      <reference source="CVE">CVE-2005-0555</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-55" comment="Internet Explorer 5.01 Service Pack 3 is installed" negate="false"/>
          <criterion test_ref="wft-598" comment="the version of mshtml.dll is less than 5.0.3539.2400" negate="false"/>
          <criterion test_ref="wrt-441" comment="the patch kb890923  is installed (Win2K SP3  Hotfix key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL2094" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>Bind</product>
      </affected>
      <dates>
        <submitted date="2005-01-19-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-24-03:40">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>BIND 8.x through 8.3.3 allows remote attackers to cause a denial of service (crash) via SIG RR elements with invalid expiry times, which are removed from the internal BIND database and later cause a null dereference.</description>
      <reference source="CVE">CVE-2002-1221</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" negate="false"/>
          <criterion test_ref="sat-19" comment="Internet Domain Name Server (BIND, SUNWinamd) installed" negate="false"/>
          <criterion test_ref="spt-24" comment="Patch 106938-07 or later installed" negate="true"/>
          <criterion test_ref="spt-25" comment="Patch 109326-10 or later installed" negate="true"/>
          <criterion test_ref="spt-26" comment="Patch 112970-03 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-14" comment="in.named running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL2100" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows ME</windows:platform>
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Internet Explorer 5.5 Service Pack 2</product>
      </affected>
      <dates>
        <submitted date="2004-07-30-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <status_change date="2004-08-02-12:00">DRAFT</status_change>
        <status_change date="2004-08-25-12:00">INTERIM</status_change>
        <status_change date="2004-09-09-12:00">ACCEPTED</status_change>
      </dates>
      <description>Double-free vulnerability in mshtml.dll for certain versions of Internet Explorer 6.x allows remote attackers to cause a denial of service (application crash) via a malformed GIF image.</description>
      <reference source="CVE">CVE-2003-1048</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-53" comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false"/>
          <criterion test_ref="wft-269" comment="the version of mshtml.dll is less than 5.50.4943.400" negate="false"/>
          <criterion test_ref="wrt-245" comment="the patch kb832894 is installed (Installed Components key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL2105" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 95</windows:platform>
        <windows:platform>Microsoft Windows 98</windows:platform>
        <windows:platform>Microsoft Windows ME</windows:platform>
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Word 2002</product>
      </affected>
      <dates>
        <submitted date="2005-09-15-04:00">
          <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
        </submitted>
        <status_change date="2005-09-21-01:33">DRAFT</status_change>
        <status_change date="2005-10-12-05:49">INTERIM</status_change>
        <status_change date="2005-11-16-08:02">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in Microsoft Word 2002 (10.6612.6714) SP3, and possibly other versions, allows remote attackers to cause a denial of service (application exception) and possibly execute arbitrary code in winword.exe via certain unexpected values in a .doc file, including (1) an offset that triggers an out-of-bounds memory access, (2) a certain value that causes a large memory copy as triggered by an integer conversion error, and other values.</description>
      <reference source="CVE">CVE-2004-0963</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-133" comment="Word 2002 is installed" negate="false"/>
          <criterion test_ref="wft-609" comment="the version of winword.exe is less than 10.0.6754.0" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL2108" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>Certificate Validation</product>
      </affected>
      <dates>
        <submitted date="2004-07-12-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <modified date="2004-07-13-12:00" comment="Added superceding patch info.">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <modified date="2004-07-14-12:00" comment="Changed to DRAFT">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2004-08-04-12:00">INTERIM</status_change>
        <status_change date="2004-08-25-12:00">ACCEPTED</status_change>
        <modified date="2005-06-02-12:00" comment="Added product">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-06-08-03:17">INTERIM</status_change>
        <status_change date="2005-06-29-06:49">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Windows 98 and Windows NT 4.0 do not properly verify the Basic Constraints of digital certificates, allowing remote attackers to execute code, aka "New Variant of Certificate Validation Flaw Could Enable Identity Spoofing" (CAN-2002-0862).</description>
      <reference source="CVE">CVE-2002-1183</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" negate="false"/>
          <criterion test_ref="wft-434" comment="the version of cryptdlg.dll is less then 5.0.1558.6072" negate="false"/>
          <criterion test_ref="wrt-477" comment="the patch Q329115 is installed" negate="true"/>
          <criterion test_ref="wrt-187" comment="the patch kb835732 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL2114" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Enhanced Metafile (EMF)</product>
      </affected>
      <dates>
        <submitted date="2004-10-13-11:11">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </submitted>
        <status_change date="2004-10-13-01:15">DRAFT</status_change>
        <status_change date="2004-10-27-12:00">INTERIM</status_change>
        <status_change date="2004-11-17-10:00">ACCEPTED</status_change>
      </dates>
      <description>Unknown vulnerability in the Graphics Rendering Engine processes of Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code via (1) Windows Metafile (WMF) or (2) Enhanced Metafile (EMF) image formats that involve "an unchecked buffer."</description>
      <reference source="CVE">CVE-2004-0209</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
          <criterion test_ref="wrt-547" comment="the patch KB840987 is installed (Hotfix key)" negate="true"/>
          <criterion test_ref="wft-507" comment="the version of gdi32.dll is less than 5.0.2195.6945" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL2128" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Indexing Service</product>
      </affected>
      <dates>
        <submitted date="2005-03-23-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2005-03-23-08:20">DRAFT</status_change>
        <status_change date="2005-04-13-12:15">INTERIM</status_change>
        <status_change date="2005-05-04-12:33">ACCEPTED</status_change>
      </dates>
      <description>The Indexing Service for Microsoft Windows XP and Server 2003 does not properly validate the length of a message, which allows remote attackers to execute arbitrary code via a buffer overflow attack.</description>
      <reference source="CVE">CVE-2004-0897</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-38" comment="Windows Server 2003 or Windows XP 64-Bit Edition Version 2003" negate="false"/>
          <criterion test_ref="wft-356" comment="Indexing Service ciodm.dll is less than 5.2.3790.220" negate="false"/>
          <criterion test_ref="wrt-69" comment="the patch Windows 2003 KB871250 is installed " negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL2137" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Outlook Express</product>
      </affected>
      <dates>
        <submitted date="2004-08-26-08:06">
          <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
        </submitted>
        <status_change date="2004-08-26-08:14">DRAFT</status_change>
        <status_change date="2004-09-09-12:00">INTERIM</status_change>
        <status_change date="2004-09-29-12:00">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Outlook Express 5.5 and 6 allows attackers to cause a denial of service (application crash) via a malformed e-mail header.</description>
      <reference source="CVE">CVE-2004-0215</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-170" comment="Outlook Express 5.5 SP2 is installed" negate="false"/>
          <criterion test_ref="wft-469" comment="the version of inetcomm.dll is less than 5.50.4942.400" negate="false"/>
          <criterion test_ref="wrt-494" comment="the patch kb823353 is installed " negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-495" comment="all users have the preview pane disabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL2139" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Kerberos5</product>
      </affected>
      <dates>
        <submitted date="2004-10-12-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2004-10-13-12:00">DRAFT</status_change>
        <modified date="2005-01-14-12:00" comment="Changed kerberos unknown test to solaris file contents test">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </modified>
        <status_change date="2005-02-02-12:00">INTERIM</status_change>
        <status_change date="2005-02-23-09:25">ACCEPTED</status_change>
      </dates>
      <description>The asn1buf_skiptail function in the ASN.1 decoder library for MIT Kerberos 5 (krb5) 1.2.2 through 1.3.4 allows remote attackers to cause a denial of service (infinite loop) via a certain BER encoding.</description>
      <reference source="CVE">CVE-2004-0644</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-6" comment="Solaris 9 Installed" negate="false"/>
          <criterion test_ref="uft-25" comment="Kerberos 5 installed" negate="false"/>
          <criterion test_ref="spt-250" comment="Patch 112908-15 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="tft-5" comment="/etc/krb5/krb5.conf is configured with a kerberos domain" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL2155" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>HTML Help Facility</product>
      </affected>
      <dates>
        <submitted date="2004-07-14-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <status_change date="2004-08-04-12:00">INTERIM</status_change>
        <status_change date="2004-08-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Heap-based buffer overflow in the HtmlHelp program (hh.exe) in HTML Help for Microsoft Windows 98, Me, NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary commands via a .CHM file with a large length field, a different vulnerability than CVE-2003-1041.</description>
      <reference source="CVE">CVE-2004-0201</reference>
      <status>ACCEPTED</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wft-444" comment="the version of itss.dll is less than 5.2.3790.185" negate="false"/>
          <criterion test_ref="wrt-482" comment="the patch kb840315 is installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-491" comment="HTML Help is registered" negate="true"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL2163" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Samba</product>
      </affected>
      <dates>
        <submitted date="2004-12-30-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-12-12:41">DRAFT</status_change>
        <status_change date="2005-02-02-12:00">INTERIM</status_change>
        <status_change date="2005-02-23-09:25">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x versions, and Samba-TNG before 0.3.2, allows remote attackers to execute arbitrary code.</description>
      <reference source="CVE">CVE-2003-0201</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-6" comment="Solaris 9 Installed" negate="false"/>
          <criterion test_ref="sat-15" comment="Samba (SUNWsmbar) installed" negate="false"/>
          <criterion test_ref="spt-15" comment="Patch 114684-02 or later installed" negate="true"/>
        </software>
        <configuration operation="OR">
          <criterion test_ref="cmp-56" comment="Inetd running and inetd.conf contains smbd" negate="false"/>
          <criterion test_ref="uct-15" comment="smbd running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL2166" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>POSIX</product>
      </affected>
      <dates>
        <submitted date="2004-07-13-12:00">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </submitted>
        <modified date="2004-07-14-12:00" comment="Modifed without comment">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <status_change date="2004-08-04-12:00">INTERIM</status_change>
        <status_change date="2004-08-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>The POSIX component of Microsoft Windows NT and Windows 2000 allows local users to execute arbitrary code via certain parameters, possibly by modifying message length values and causing a buffer overflow.</description>
      <reference source="CVE">CVE-2004-0210</reference>
      <status>ACCEPTED</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" negate="false"/>
          <criterion test_ref="wrt-480" comment="the patch kb841872 is installed" negate="true"/>
          <criterion test_ref="cmp-1064" comment="Version check for psxss.exe on NT Workstation, Server 4.0 and NT Terminal Server" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-479" comment="POSIX is enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL2183" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Sendmail</product>
      </affected>
      <dates>
        <submitted date="2004-12-22-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-12-12:00">DRAFT</status_change>
        <modified date="2005-01-27-12:00" comment="Removed &quot;Sendmail running&quot; configuration test.  Sendmail installs as SUID root">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </modified>
        <status_change date="2005-04-20-12:13">INTERIM</status_change>
        <status_change date="2005-05-11-05:41">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in Sendmail before 8.12.5, when configured to use a custom DNS map to query TXT records, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a malicious DNS server.</description>
      <reference source="CVE">CVE-2002-0906</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-6" comment="Solaris 9 Installed" negate="false"/>
          <criterion test_ref="sat-3" comment="Sendmail - root (SUNWsndmr) installed" negate="false"/>
          <criterion test_ref="spt-2" comment="Patch 113575-01 or later installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL2184" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Windows Shell</product>
      </affected>
      <dates>
        <submitted date="2005-05-04-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2005-05-04-12:32">DRAFT</status_change>
        <status_change date="2005-06-01-03:30">INTERIM</status_change>
        <status_change date="2005-06-22-12:38">ACCEPTED</status_change>
      </dates>
      <description>The document processing application used by the Windows Shell in Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code by modifying the CLSID stored in a file so that it is processed by HTML Application Host (MSHTA), as demonstrated using a Microsoft Word document.</description>
      <reference source="CVE">CVE-2005-0063</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1066" comment="Windows XP 64-bit with Service Pack 1" negate="false"/>
          <criterion test_ref="wft-590" comment="the version of shell32.dll is less than 6.0.2800.1643" negate="false"/>
          <criterion test_ref="wrt-435" comment="the patch  KB893086 is installed " negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-280" comment=".hta applications are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL2188" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Windows 2000</product>
      </affected>
      <dates>
        <submitted date="2005-04-22-12:00">
          <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
        </submitted>
        <status_change date="2005-04-27-12:06">DRAFT</status_change>
        <status_change date="2005-06-01-03:30">INTERIM</status_change>
        <status_change date="2005-06-22-12:38">ACCEPTED</status_change>
      </dates>
      <description>Multiple TCP/IP and ICMP implementations, when using Path MTU (PMTU) discovery (PMTUD), allow remote attackers to cause a denial of service (network throughput reduction for TCP connections) via forged ICMP ("Fragmentation Needed and Don't Fragment was Set") packets with a low next-hop MTU value, aka the "Path MTU discovery attack."  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</description>
      <reference source="CVE">CVE-2004-1060</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
          <criterion test_ref="wrt-538" comment="Win2K/XP/2003 service pack 4 (or earlier) is installed" negate="false"/>
          <criterion test_ref="wft-593" comment="the version of Tcpip.sys is less than 5.0.2195.7035" negate="false"/>
          <criterion test_ref="wrt-443" comment="the patch KB893066 is installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-380" comment="Enable Path MTU Discovery is Disabled" negate="true"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL2190" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>DirectX</product>
      </affected>
      <dates>
        <submitted date="2004-06-15-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <modified date="2004-06-16-12:00" comment="Added cmp-966 to test for vulnerable versions of DirectX">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </modified>
        <modified date="2004-06-17-12:00" comment="Re-added cmp-966">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </modified>
        <modified date="2004-07-06-12:00" comment="Added the negate attribute with a value of 'true' to the subtest elements referencing patch installations.">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </modified>
        <status_change date="2004-07-12-12:00">INTERIM</status_change>
        <status_change date="2004-07-21-12:00">ACCEPTED</status_change>
      </dates>
      <description>IDirectPlay4 Application Programming Interface (API) of Microsoft DirectPlay 7.0a thru 9.0b, as used in Windows Server 2003 and earlier allows remote attackers to cause a denial of service (application crash) via a malformed packet.</description>
      <reference source="CVE">CVE-2004-0202</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-2" comment="Windows XP is installed" negate="false"/>
          <criterion test_ref="wrt-72" comment="32-Bit version of Windows is installed" negate="false"/>
          <criterion test_ref="cmp-966" comment="DirectX without KB839643 Installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL2204" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>IIS 4.0</product>
      </affected>
      <dates>
        <submitted date="2004-07-13-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
        <status_change date="2004-08-04-12:00">INTERIM</status_change>
        <status_change date="2004-08-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in Microsoft Internet Information Server (IIS) 4.0 allows local users to execute arbitrary code via the redirect function.</description>
      <reference source="CVE">CVE-2004-0205</reference>
      <status>ACCEPTED</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" negate="false"/>
          <criterion test_ref="wrt-214" comment="IIS 4.0 Major Version" negate="false"/>
          <criterion test_ref="wrt-215" comment="IIS minor version equals 0" negate="false"/>
          <criterion test_ref="wrt-484" comment="the patch q841373 is installed (Hotfix key)" negate="true"/>
          <criterion test_ref="wft-446" comment="the version of w3svc.dll is less than 4.2.788.1" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wmt-207" comment="Permanent redirects enabled" negate="false"/>
          <criterion test_ref="wrt-485" comment="MaxClientRequestBufferData less than or equal to 16384" negate="true"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL2216" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 95</windows:platform>
        <windows:platform>Microsoft Windows 98</windows:platform>
        <windows:platform>Microsoft Windows ME</windows:platform>
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Word 2000</product>
      </affected>
      <dates>
        <submitted date="2005-09-15-04:00">
          <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
        </submitted>
        <status_change date="2005-09-21-01:33">DRAFT</status_change>
        <status_change date="2005-10-12-05:49">INTERIM</status_change>
        <status_change date="2005-11-16-08:02">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in Microsoft Word 2002 (10.6612.6714) SP3, and possibly other versions, allows remote attackers to cause a denial of service (application exception) and possibly execute arbitrary code in winword.exe via certain unexpected values in a .doc file, including (1) an offset that triggers an out-of-bounds memory access, (2) a certain value that causes a large memory copy as triggered by an integer conversion error, and other values.</description>
      <reference source="CVE">CVE-2004-0963</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-132" comment="Word 2000 is installed" negate="false"/>
          <criterion test_ref="wft-608" comment="the version of winword.exe is less than 9.0.0.8929" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL2219" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Internet Explorer 6</product>
      </affected>
      <dates>
        <submitted date="2004-10-26-04:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2004-10-27-04:00">DRAFT</status_change>
        <status_change date="2004-11-17-05:00">INTERIM</status_change>
        <status_change date="2004-12-09-05:00">ACCEPTED</status_change>
        <modified date="2005-09-20-04:00" comment="Changed IE registry test to wrt-18">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-21-01:27">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 5.01, 5.5, and 6 does not properly cache SSL content, which allows remote attackers to obtain information or spoof content via a web site with the same host name as the target web site, whose content is cached and reused when the user visits the target web site.</description>
      <reference source="CVE">CVE-2004-0845</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wft-563" comment="the version of mshtml.dll is less than 6.0.2745.2800" negate="false"/>
          <criterion test_ref="wrt-562" comment="the patch kb834707 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-18" comment="Internet Explorer 6 is installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-567" comment="Users not saving encrypted pages to disk  (DisableCachingOfSSLPages)" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL2222" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Sendmail</product>
      </affected>
      <dates>
        <submitted date="2005-04-13-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-04-20-12:13">DRAFT</status_change>
        <status_change date="2005-05-11-05:41">INTERIM</status_change>
        <status_change date="2005-06-01-03:30">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted address fields, related to sender and recipient header comments as processed by the crackaddr function of headers.c.</description>
      <reference source="CVE">CVE-2002-1337</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" negate="false"/>
          <criterion test_ref="sat-14" comment="Sendmail - user (SUNWsndmu) installed" negate="false"/>
          <criterion test_ref="spt-63" comment="Patch 107684-08 or later installed" negate="true"/>
          <criterion test_ref="spt-64" comment="Patch 110615-08 or later installed" negate="true"/>
          <criterion test_ref="spt-65" comment="Patch 113575-03 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-11" comment="Sendmail running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL2245" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2004-07-14-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2004-08-04-12:00">INTERIM</status_change>
        <status_change date="2004-08-25-12:00">ACCEPTED</status_change>
        <status_change date="2004-09-15-12:00">INTERIM</status_change>
        <status_change date="2004-09-29-12:00">ACCEPTED</status_change>
        <modified date="2005-12-20-07:05" comment="Changed criteria to drop explicit test for patch kb839645.  Inclusion resulted in false positives w/o incremental patching.">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </modified>
        <status_change date="2006-01-04-08:04">ACCEPTED</status_change>
      </dates>
      <description>The Windows Shell application in Windows 98, Windows ME, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code by spoofing the type of a file via a CLSID specifier in the filename, as demonstrated using Internet Explorer 6.0.2800.1106 on Windows XP.</description>
      <reference source="CVE">CVE-2004-0420</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wft-450" comment="the version of shell32.dll is less than 6.0.2800.1556" negate="false"/>
          <criterion test_ref="cmp-692" comment="Windows XP (64-bit,SP1 or 32-bit,SP2) is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL2248" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>libc</product>
      </affected>
      <dates>
        <submitted date="2005-04-13-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-04-20-12:13">DRAFT</status_change>
        <status_change date="2005-05-11-05:41">INTERIM</status_change>
        <status_change date="2005-06-01-03:30">ACCEPTED</status_change>
      </dates>
      <description>The Sun RPC functionality in multiple libc implementations does not provide a time-out mechanism when reading data from TCP connections, which allows remote attackers to cause a denial of service (hang).</description>
      <reference source="CVE">CVE-2002-1265</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="cmp-287" comment="All RPC w/TCP patches installed - CVE-2002-1265" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-21" comment="rpcbind running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL2253" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Internet Explorer 5.01 Service Pack 4</product>
      </affected>
      <dates>
        <submitted date="2005-05-10-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2005-05-11-05:38">DRAFT</status_change>
        <status_change date="2005-06-01-03:30">INTERIM</status_change>
        <status_change date="2005-06-22-12:38">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the URL processor of Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a URL with a long hostname, aka "URL Parsing Memory Corruption Vulnerability."</description>
      <reference source="CVE">CVE-2005-0554</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-54" comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false"/>
          <criterion test_ref="wft-599" comment="the version of mshtml.dll is less than 5.0.3826.2400" negate="false"/>
          <criterion test_ref="wrt-442" comment="the patch kb890923 is installed (Win2K SP4  Hotfix key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL2265" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>Windows kernel</product>
      </affected>
      <dates>
        <submitted date="2004-07-13-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2004-08-04-12:00">INTERIM</status_change>
        <status_change date="2004-08-25-12:00">ACCEPTED</status_change>
        <modified date="2005-06-02-12:00" comment="Added product">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-06-08-03:17">INTERIM</status_change>
        <status_change date="2005-06-29-06:49">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in Windows Kernel allows local users to gain privileges by causing certain error messages to be passed to a debugger.</description>
      <reference source="CVE">CVE-2003-0112</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-45" comment="Windows NT Server 4.0, Terminal Server Edition is installed" negate="false"/>
          <criterion test_ref="wft-437" comment="The version of Ntoskrnl.exe is less than 4.0.1381.33545" negate="false"/>
          <criterion test_ref="wrt-478" comment="the patch Q811493 is installed" negate="true"/>
          <criterion test_ref="wrt-187" comment="the patch kb835732 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL2274" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>MDAC 2.8</product>
      </affected>
      <dates>
        <submitted date="2005-03-29-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2005-03-29-08:38">DRAFT</status_change>
        <status_change date="2005-04-13-12:15">INTERIM</status_change>
        <status_change date="2005-05-04-12:33">ACCEPTED</status_change>
        <modified date="2006-03-13-02:32" comment="modified wft-410 - Literal component included \&quot;Program Files\&quot;, but the key in the registry component holds the full path to the Program Files directory (e.g. C:\\Program Files on standard installation).  Modified the literal component so full path when expanded would be correct.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2006-04-12-05:06">INTERIM</status_change>
        <status_change date="2006-05-03-10:06">ACCEPTED</status_change>
      </dates>
      <description>Multiple buffer overflows in libpng 1.2.5 and earlier, as used in multiple products, allow remote attackers to execute arbitrary code via malformed PNG images in which (1) the png_handle_tRNS function does not properly validate the length of transparency chunk (tRNS) data, or the (2) png_handle_sBIT or (3) png_handle_hIST functions do not perform sufficient bounds checking.</description>
      <reference source="CVE">CVE-2004-0597</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-179" comment="Windows Messenger 5.1 is installed" negate="true"/>
          <criterion test_ref="wft-410" comment="the version of msmsgs.exe is less than 5.1.0.639" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL2280" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>DHCP</product>
      </affected>
      <dates>
        <submitted date="2004-12-16-12:00">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </submitted>
        <status_change date="2005-01-12-12:00">DRAFT</status_change>
        <modified date="2005-01-27-12:00" comment="Corrected the patch number being checked">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <modified date="2005-02-07-12:00" comment="negated the patch check">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <status_change date="2005-02-23-09:25">INTERIM</status_change>
        <status_change date="2005-03-23-08:09">ACCEPTED</status_change>
      </dates>
      <description>The DHCP Server service for Microsoft Windows NT 4.0 Server and Terminal Server Edition, with DHCP logging enabled, does not properly validate the length of certain messages, which allows remote attackers to cause a denial of service (application crash) via a malformed DHCP message, aka "Logging Vulnerability."</description>
      <reference source="CVE">CVE-2004-0899</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-44" comment="Windows NT Server 4.0 is installed" negate="false"/>
          <criterion test_ref="wft-156" comment="the version of Dhcpssvc.dll is less than 4.0.1381.7304" negate="false"/>
          <criterion test_ref="wrt-37" comment="the patch KB885249 is installed (Hotfix key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL2292" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
      </affected>
      <dates>
        <submitted date="2005-02-10-12:00">
          <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
        </submitted>
        <status_change date="2005-02-11-12:00">DRAFT</status_change>
        <status_change date="2005-03-02-12:00">INTERIM</status_change>
        <status_change date="2005-03-23-12:00">ACCEPTED</status_change>
        <modified date="2005-05-02-12:00" comment="Added negate to the patch check. Accidentally left off.">
          <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
        </modified>
        <status_change date="2005-05-04-12:14">INTERIM</status_change>
        <status_change date="2005-06-01-03:30">ACCEPTED</status_change>
      </dates>
      <description>The Server service (srvsvc.dll) in Windows XP SP1 and SP2 allows remote attackers to obtain sensitive information (users who are accessing resources) via an anonymous logon using a named pipe, which is not properly authenticated, aka the "Named Pipe Vulnerability."</description>
      <reference source="CVE">CVE-2005-0051</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-35" comment="Windows XP 32 bit Service Pack 2" negate="false"/>
          <criterion test_ref="wft-373" comment="the version of srvsvc.dll is less than 5.1.2600.2577" negate="false"/>
          <criterion test_ref="wrt-81" comment="the patch kb888302 is installed (Hotfix key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL2300" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>SMTP</product>
      </affected>
      <dates>
        <submitted date="2004-10-19-10:33">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2004-10-20-02:35">DRAFT</status_change>
        <modified date="2004-10-26-09:17" comment="">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2004-11-17-10:00">INTERIM</status_change>
        <status_change date="2004-12-09-08:46">ACCEPTED</status_change>
      </dates>
      <description>The SMTP (Simple Mail Transfer Protocol) component of Microsoft Windows XP 64-bit Edition, Windows Server 2003, Windows Server 2003 64-bit Edition, and the Exchange Routing Engine component of Exchange Server 2003, allows remote attackers to execute arbitrary code via a malicious DNS response message containing length values that are not properly validated.</description>
      <reference source="CVE">CVE-2004-0840</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wft-502" comment="The version of smtpsvc.dll is less than 6.0.3790.211" negate="false"/>
          <criterion test_ref="wrt-542" comment="the patch WindowsServer2003-KB885881-x86-enu.exe is installed" negate="false"/>
          <criterion test_ref="cmp-1153" comment="Exchange Server 2003 is installed on Windows Server 2003" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-240" comment="SMTP Enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL2343" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Distributed Component Object Model (DCOM) interface</product>
      </affected>
      <dates>
        <submitted date="2005-04-28-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2005-05-04-12:32">DRAFT</status_change>
        <status_change date="2005-06-01-03:30">INTERIM</status_change>
        <status_change date="2005-06-22-12:38">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in a certain DCOM interface for RPC in Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary code via a malformed message, as exploited by the Blaster/MSblast/LovSAN and Nachi/Welchia worms.</description>
      <reference source="CVE">CVE-2003-0352</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <notes>
        <note>This bulletin has been superceded by MS03-039.  Definition reflects updated information.</note>
      </notes>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-310" comment="Windows XP 32-bit OR Windows XP 64-bit is installed" negate="false"/>
          <criterion test_ref="cmp-312" comment="A vulnerable version of rpcrt4.dll exists depending on service pack level" negate="false"/>
          <criterion test_ref="wrt-281" comment="the patch kb824146 is installed (Hotfix key)" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-283" comment="DCOM is enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL2348" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 98</windows:platform>
        <windows:platform>Microsoft Windows ME</windows:platform>
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Microsoft Project Professional 2002</product>
      </affected>
      <dates>
        <submitted date="2005-03-29-12:00">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </submitted>
        <status_change date="2005-03-29-08:38">DRAFT</status_change>
        <status_change date="2005-04-13-12:15">INTERIM</status_change>
        <status_change date="2005-05-04-12:33">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in Microsoft Office XP allows remote attackers to execute arbitrary code via a link with a URL file location containing long inputs after (1) "%00 (null byte) in .doc filenames or (2) "%0a" (carriage return) in .rtf filenames.</description>
      <reference source="CVE">CVE-2004-0848</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-523" comment="Windows Project Professional 2002 Service Pack 1 is installed" negate="false"/>
          <criterion test_ref="wft-377" comment="the version of mso.dll is less than 10.0.6735.0" negate="false"/>
          <criterion test_ref="wrt-94" comment="Patch KB873355 installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL2351" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>COM Internet Services</product>
      </affected>
      <dates>
        <submitted date="2005-02-15-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2005-02-18-10:39">DRAFT</status_change>
        <status_change date="2005-03-09-07:56">INTERIM</status_change>
        <status_change date="2005-03-29-07:59">ACCEPTED</status_change>
      </dates>
      <description>Windows 2000, XP, and Server 2003 does not properly "validate the use of memory regions" for COM structured storage files, which allows attackers to execute arbitrary code, aka the "COM Structured Storage Vulnerability."</description>
      <reference source="CVE">CVE-2005-0047</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-35" comment="Windows XP 32 bit Service Pack 2" negate="false"/>
          <criterion test_ref="wft-388" comment="the version of ole32.dll is less than 5.1.2600.2595" negate="false"/>
          <criterion test_ref="wrt-91" comment="the patch KB873333 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL2378" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>libpng</product>
      </affected>
      <dates>
        <submitted date="2004-12-12-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-24-12:04">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Multiple buffer overflows in libpng 1.2.5 and earlier, as used in multiple products, allow remote attackers to execute arbitrary code via malformed PNG images in which (1) the png_handle_tRNS function does not properly validate the length of transparency chunk (tRNS) data, or the (2) png_handle_sBIT or (3) png_handle_hIST functions do not perform sufficient bounds checking.</description>
      <reference source="CVE">CVE-2004-0597</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" negate="false"/>
          <criterion test_ref="sat-11" comment="Netscape installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL2379" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Windows Media Player 9</product>
      </affected>
      <dates>
        <submitted date="2005-02-22-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <modified date="2005-02-22-12:13" comment="modified wrt-169 - fixed version">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <modified date="2005-02-22-12:14" comment="modified wrt-169 - fixed pattern match">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <modified date="2005-02-22-12:14" comment="modified wrt-174 - modified name">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <modified date="2005-02-22-12:14" comment="modified wrt-175 - modified name">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <modified date="2005-02-22-12:15" comment="modified wrt-176 - modified name">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <modified date="2005-02-22-12:16" comment="modified wrt-177 - modified name">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <modified date="2005-02-22-12:17" comment="modified wrt-178 - modified name ">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-02-23-08:48">DRAFT</status_change>
        <status_change date="2005-03-23-08:09">INTERIM</status_change>
        <status_change date="2005-04-13-12:15">ACCEPTED</status_change>
      </dates>
      <description>Windows Media Player 9 allows remote attackers to execute arbitrary code via a PNG file containing large (1) width or (2) height values, aka the "PNG Processing Vulnerability."</description>
      <reference source="CVE">CVE-2004-1244</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-82" comment="Windows Media Player 9.0 installed" negate="false"/>
          <criterion test_ref="wft-374" comment="the version of wmp.dll is les than 9.0.0.3250" negate="false"/>
          <criterion test_ref="wrt-85" comment="The patch KB885492 is installed on Windows 2000" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-188" comment="The files .asx, .wax, .wvx, .wpl, .wmx, .wms, .wmz EXIST" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL2381" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2004-07-14-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2004-08-04-12:00">INTERIM</status_change>
        <status_change date="2004-08-25-12:00">ACCEPTED</status_change>
        <modified date="2005-12-20-07:05" comment="Changed criteria to drop explicit test for patch kb839645.  Inclusion resulted in false positives w/o incremental patching.">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </modified>
        <status_change date="2006-01-04-08:04">ACCEPTED</status_change>
      </dates>
      <description>The Windows Shell application in Windows 98, Windows ME, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code by spoofing the type of a file via a CLSID specifier in the filename, as demonstrated using Internet Explorer 6.0.2800.1106 on Windows XP.</description>
      <reference source="CVE">CVE-2004-0420</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wft-3" comment="the version of helpctr.exe is less than 5.1.2600.1515" negate="true"/>
          <criterion test_ref="wft-448" comment="the version of shell32.dll is less than 6.0.3790.168" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL2385" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Internet Explorer 5.01 Service Pack 3</product>
      </affected>
      <dates>
        <submitted date="2005-03-17-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2005-03-23-08:09">DRAFT</status_change>
        <status_change date="2005-04-13-12:15">INTERIM</status_change>
        <status_change date="2005-05-04-12:33">ACCEPTED</status_change>
        <modified date="2005-12-26-09:40" comment="Removed test to check kb867282.">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </modified>
        <status_change date="2006-01-12-08:59">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 5.01, 5.5, and 6 does not properly validate certain URLs in Channel Definition Format (CDF) files, which allows remote attackers to obtain sensitive information or execute arbitrary code, aka the "Channel Definition Format (CDF) Cross Domain Vulnerability."</description>
      <reference source="CVE">CVE-2005-0056</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-55" comment="Internet Explorer 5.01 Service Pack 3 is installed" negate="false"/>
          <criterion test_ref="wft-406" comment="the version of mshtml.dll is less than 5.0.3528.700" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL2394" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>NetDDE</product>
      </affected>
      <dates>
        <submitted date="2004-10-13-04:09">
          <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
        </submitted>
        <status_change date="2004-10-20-02:35">DRAFT</status_change>
        <status_change date="2004-11-03-12:00">INTERIM</status_change>
        <status_change date="2004-12-09-08:46">ACCEPTED</status_change>
      </dates>
      <description>Network Dynamic Data Exchange (NetDDE) services for Microsoft Windows 98, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows attackers to remotely execute arbitrary code or locally gain privileges via a malicious message or application that involves an "unchecked buffer," possibly a buffer overflow.</description>
      <reference source="CVE">CVE-2004-0206</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-44" comment="Windows NT Server 4.0 is installed" negate="false"/>
          <criterion test_ref="wft-518" comment="the version of nddenb32.dll is less than 4.0.1381.7268" negate="false"/>
          <criterion test_ref="wft-522" comment="the version of netdde.exe is less than 4.0.1381.7280" negate="false"/>
          <criterion test_ref="wrt-551" comment="the patch KB841533 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL2413" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>DirectX</product>
      </affected>
      <dates>
        <submitted date="2004-06-15-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <modified date="2004-06-16-12:00" comment="Changed Status to Draft; Added cmp-967">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </modified>
        <modified date="2004-07-06-12:00" comment="Added the negate attribute with a value of 'true' to the subtest elements referencing patch installations.">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </modified>
        <status_change date="2004-07-12-12:00">INTERIM</status_change>
        <status_change date="2004-07-21-12:00">ACCEPTED</status_change>
        <modified date="2004-09-13-12:00" comment="Modifed without comment">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <modified date="2004-09-14-10:07" comment="">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <modified date="2004-09-14-10:07" comment="">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2004-09-15-12:00">INTERIM</status_change>
        <status_change date="2004-09-29-12:00">ACCEPTED</status_change>
      </dates>
      <description>IDirectPlay4 Application Programming Interface (API) of Microsoft DirectPlay 7.0a thru 9.0b, as used in Windows Server 2003 and earlier allows remote attackers to cause a denial of service (application crash) via a malformed packet.</description>
      <reference source="CVE">CVE-2004-0202</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-967" comment="DirectX 8.1 without kb839643 installed" negate="false"/>
          <criterion test_ref="cmp-1102" comment="Windows XP 64-bit with SP1 (or earlier) installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL2415" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 95</windows:platform>
        <windows:platform>Microsoft Windows 98</windows:platform>
        <windows:platform>Microsoft Windows ME</windows:platform>
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Word 2002</product>
      </affected>
      <dates>
        <submitted date="2005-09-15-04:00">
          <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
        </submitted>
        <status_change date="2005-09-21-01:33">DRAFT</status_change>
        <status_change date="2005-10-12-05:49">INTERIM</status_change>
        <status_change date="2005-11-16-08:02">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in Microsoft Word 2000, Word 2002, and Word 2003 allows remote attackers to execute arbitrary code via a crafted document.</description>
      <reference source="CVE">CVE-2005-0558</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-133" comment="Word 2002 is installed" negate="false"/>
          <criterion test_ref="wft-609" comment="the version of winword.exe is less than 10.0.6754.0" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL2418" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>mozilla</product>
      </affected>
      <dates>
        <submitted date="2005-01-19-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-24-03:40">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, allow remote web sites to hijack the user interface via the "chrome" flag and XML User Interface Language (XUL) files.</description>
      <reference source="CVE">CVE-2004-0764</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" negate="false"/>
          <criterion test_ref="cmp-72" comment="Mozilla components (any SUNWmoznav/SUNWmozmail) installed" negate="false"/>
          <criterion test_ref="spt-46" comment="Patch 117765-02 or later installed" negate="true"/>
          <criterion test_ref="spt-47" comment="Patch 117767-02 or later installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL2423" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>NIS</product>
      </affected>
      <dates>
        <submitted date="2005-01-19-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-24-03:40">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>The getdbm procedure in ypxfrd allows local users to read arbitrary files, and remote attackers to read databases outside /var/yp, via a directory traversal and symlink attack on the domain and map arguments.</description>
      <reference source="CVE">CVE-2002-1199</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" negate="false"/>
          <criterion test_ref="sat-20" comment="NIS Server - User (SUNWypu) installed" negate="false"/>
          <criterion test_ref="spt-33" comment="Patch 106541-24 or later installed" negate="true"/>
          <criterion test_ref="spt-34" comment="Patch 109328-03 or later installed" negate="true"/>
          <criterion test_ref="spt-35" comment="Patch 113579-01 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-17" comment="ypxfrd running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL2426" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Basic Security Module</product>
      </affected>
      <dates>
        <submitted date="2004-10-12-09:40">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2004-10-13-01:15">DRAFT</status_change>
      </dates>
      <description>Unknown vulnerability in the Basic Security Module (BSM), when configured to audit either the Administrative (ad) or the System-Wide Administration (as) audit class in Solaris 7, 8, and 9, allows local users to cause a denial of service (kernel panic).</description>
      <reference source="CVE">CVE-2004-0654</reference>
      <status>DRAFT</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="spt-233" comment="Patch 106541-33 or later installed" negate="true"/>
          <criterion test_ref="spt-234" comment="Patch 109007-18 or later installed" negate="true"/>
          <criterion test_ref="spt-235" comment="Patch 114332-12 or later installed" negate="true"/>
          <criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="ukn-26" comment="Basic Security Module enabled" negate="false"/>
          <criterion test_ref="ukn-27" comment="Auditing Administrative or System-Wide Administrative audit classes" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL2428" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Enhanced Metafile (EMF)</product>
      </affected>
      <dates>
        <submitted date="2004-10-13-11:29">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </submitted>
        <modified date="2004-10-13-11:43" comment="changed OS">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <status_change date="2004-10-13-01:15">DRAFT</status_change>
        <status_change date="2004-10-27-12:00">INTERIM</status_change>
        <status_change date="2004-11-17-10:00">ACCEPTED</status_change>
      </dates>
      <description>Unknown vulnerability in the Graphics Rendering Engine processes of Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code via (1) Windows Metafile (WMF) or (2) Enhanced Metafile (EMF) image formats that involve "an unchecked buffer."</description>
      <reference source="CVE">CVE-2004-0209</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wft-508" comment="the version of win32k.sys is less than 5.2.3790.198" negate="false"/>
          <criterion test_ref="wrt-547" comment="the patch KB840987 is installed (Hotfix key)" negate="true"/>
          <criterion test_ref="cmp-1113" comment="Windows 2003 Server or Windows XP 64-bit" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL2447" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Indexing Service</product>
      </affected>
      <dates>
        <submitted date="2005-03-23-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2005-03-23-08:20">DRAFT</status_change>
        <status_change date="2005-04-13-12:15">INTERIM</status_change>
        <status_change date="2005-05-04-12:33">ACCEPTED</status_change>
      </dates>
      <description>The Indexing Service for Microsoft Windows XP and Server 2003 does not properly validate the length of a message, which allows remote attackers to execute arbitrary code via a buffer overflow attack.</description>
      <reference source="CVE">CVE-2004-0897</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-66" comment="Windows XP (sp1 or earlier) is installed" negate="false"/>
          <criterion test_ref="wft-357" comment="Indexing Service ciodm.dll is less than 5.1.2600.1596" negate="false"/>
          <criterion test_ref="wrt-74" comment="the patch Windows XP KB871250 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL2448" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Internet Explorer 6 Service Pack 1 for Windows Server 2003</product>
      </affected>
      <dates>
        <submitted date="2005-01-18-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2005-01-20-12:00">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-12:00">ACCEPTED</status_change>
        <modified date="2005-05-10-12:00" comment="modified wrt-51 - Comment updated to indicate IE 6.">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </modified>
        <status_change date="2005-05-11-05:33">INTERIM</status_change>
        <status_change date="2005-06-01-03:30">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 6 on Double Byte Character Set (DBCS) systems allows remote attackers to alter displayed address bars and spoof web pages via a URL containing special characters, facilitating phishing attacks, aka the "Address Bar Spoofing on Double Byte Character Set Systems Vulnerability."</description>
      <reference source="CVE">CVE-2004-0844</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-51" comment="Internet Explorer 6  for Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wft-558" comment="the version of mshtml.dll is less than 6.0.3790.219" negate="false"/>
          <criterion test_ref="wrt-557" comment="the patch kb834707 is installed (Hotfix key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL2487" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Microsoft Internet Explorer 6</product>
      </affected>
      <dates>
        <submitted date="2004-10-25-04:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2004-10-27-04:00">DRAFT</status_change>
        <status_change date="2004-11-17-05:00">INTERIM</status_change>
        <status_change date="2004-12-09-05:00">ACCEPTED</status_change>
        <modified date="2005-09-20-04:00" comment="Changed IE registry test to wrt-18">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-21-01:27">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 5.5 and 6 does not properly handle plug-in navigation, which allows remote attackers to alter displayed address bars and thereby spoof web pages, facilitating phishing attacks, aka the "Plug-in Navigation Address Bar Spoofing Vulnerability."</description>
      <reference source="CVE">CVE-2004-0843</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wft-563" comment="the version of mshtml.dll is less than 6.0.2745.2800" negate="false"/>
          <criterion test_ref="wrt-562" comment="the patch kb834707 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-18" comment="Internet Explorer 6 is installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL2495" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Utility Manager</product>
      </affected>
      <dates>
        <submitted date="2004-07-13-12:00">
          <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
        </submitted>
        <status_change date="2004-08-04-12:00">INTERIM</status_change>
        <status_change date="2004-08-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Utility Manager in Windows 2000 launches winhlp32.exe while Utility Manager is running with raised privileges, which allows local users to gain system privileges via a "Shatter" style attack that sends a Windows message to cause Utility Manager to launch winhlp32 by directly accessing the context sensitive help and bypassing the GUI, then sending another message to winhlp32 in order to open a user-selected file, a different vulnerability than CVE-2003-0908.</description>
      <reference source="CVE">CVE-2004-0213</reference>
      <status>ACCEPTED</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
          <criterion test_ref="wft-439" comment="the version of Sp3res.dll is less than 5.0.2195.6928" negate="false"/>
          <criterion test_ref="wft-442" comment="the version of Umandlg.dll is less than 1.0.0.5" negate="false"/>
          <criterion test_ref="wrt-481" comment="the patch kb842526 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL2505" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>Remote Procedure Call (RPC)</product>
      </affected>
      <dates>
        <submitted date="2004-10-18-11:46">
          <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
        </submitted>
        <status_change date="2004-10-20-02:35">DRAFT</status_change>
        <status_change date="2004-11-03-12:00">INTERIM</status_change>
        <status_change date="2004-12-09-08:46">ACCEPTED</status_change>
      </dates>
      <description>The RPC Runtime Library for Microsoft Windows NT 4.0 allows remote attackers to read active memory or cause a denial of service (system crash) via a malicious message, possibly related to improper length values.</description>
      <reference source="CVE">CVE-2004-0569</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" negate="false"/>
          <criterion test_ref="wft-552" comment="the version of rpcrt4.dll is less than 4.0.1381.7299" negate="false"/>
          <criterion test_ref="wrt-558" comment="Patch KB873350 Installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL2516" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>DirectX</product>
      </affected>
      <dates>
        <submitted date="2004-06-15-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <modified date="2004-06-16-12:00" comment="Changed Status to Draft; Added cmp-969">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </modified>
        <modified date="2004-07-06-12:00" comment="Added the negate attribute with a value of 'true' to the subtest elements referencing patch installations.">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </modified>
        <status_change date="2004-07-12-12:00">INTERIM</status_change>
        <status_change date="2004-07-21-12:00">ACCEPTED</status_change>
      </dates>
      <description>IDirectPlay4 Application Programming Interface (API) of Microsoft DirectPlay 7.0a thru 9.0b, as used in Windows Server 2003 and earlier allows remote attackers to cause a denial of service (application crash) via a malformed packet.</description>
      <reference source="CVE">CVE-2004-0202</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wrt-72" comment="32-Bit version of Windows is installed" negate="false"/>
          <criterion test_ref="cmp-969" comment="DirectX without KB839643 Installed on Windows Server 2003" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL2536" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>Kerberos5</product>
      </affected>
      <dates>
        <submitted date="2005-01-19-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-24-03:40">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>The Key Distribution Center (KDC) in Kerberos 5 (krb5) 1.2.7 and earlier allows remote, authenticated attackers to cause a denial of service (crash) on KDCs within the same realm using a certain protocol request that causes the KDC to corrupt its heap (aka "buffer underrun").</description>
      <reference source="CVE">CVE-2003-0082</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <notes>
        <note>Vulnerability exists in standard Solaris kerberos and SEAM.  This definition only covers Solaris kerberos</note>
      </notes>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" negate="false"/>
          <criterion test_ref="cmp-74" comment="Kerberos v5 (any SUNWkrbr/SUNWkrbu/SUNWkrbux) installed" negate="false"/>
          <criterion test_ref="cmp-79" comment="Patches 112237-09 and 112390-08 or later installed" negate="true"/>
          <criterion test_ref="cmp-81" comment="Patches 112925-03,112923-03,112921-02, and 112908-10 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="tft-5" comment="/etc/krb5/krb5.conf is configured with a kerberos domain" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL2537" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Internet Explorer 5.01 Service Pack 4</product>
      </affected>
      <dates>
        <submitted date="2004-10-25-05:29">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2004-10-27-01:04">DRAFT</status_change>
        <status_change date="2004-11-17-10:00">INTERIM</status_change>
        <status_change date="2004-12-09-08:46">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 5.5 and 6 does not properly handle plug-in navigation, which allows remote attackers to alter displayed address bars and thereby spoof web pages, facilitating phishing attacks, aka the "Plug-in Navigation Address Bar Spoofing Vulnerability."</description>
      <reference source="CVE">CVE-2004-0843</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-54" comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false"/>
          <criterion test_ref="wft-561" comment="the version of mshtml.dll is less than 5.0.3534.2800" negate="false"/>
          <criterion test_ref="wrt-560" comment="the patch kb834707-ie501sp4 is installed (Hotfix key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL2539" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>Bind</product>
      </affected>
      <dates>
        <submitted date="2005-01-19-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-24-03:40">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in named in BIND 4 versions 4.9.10 and earlier, and 8 versions 8.3.3 and earlier, allows remote attackers to execute arbitrary code via a certain DNS server response containing SIG resource records (RR).</description>
      <reference source="CVE">CVE-2002-1219</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" negate="false"/>
          <criterion test_ref="sat-19" comment="Internet Domain Name Server (BIND, SUNWinamd) installed" negate="false"/>
          <criterion test_ref="spt-24" comment="Patch 106938-07 or later installed" negate="true"/>
          <criterion test_ref="spt-25" comment="Patch 109326-10 or later installed" negate="true"/>
          <criterion test_ref="spt-26" comment="Patch 112970-03 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-14" comment="in.named running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL2541" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Windows 2000</product>
      </affected>
      <dates>
        <submitted date="2005-01-03-12:00">
          <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
        </submitted>
        <status_change date="2005-01-12-12:41">DRAFT</status_change>
        <status_change date="2005-02-02-12:00">INTERIM</status_change>
        <status_change date="2005-02-23-09:25">ACCEPTED</status_change>
      </dates>
      <description>The WINS service (wins.exe) on Microsoft Windows NT Server 4.0, Windows 2000 Server, and Windows Server 2003 allows remote attackers to write to arbitrary memory locations and possibly execute arbitrary code via a modified memory pointer in a WINS replication packet to TCP port 42, aka the "Association Context Vulnerability."</description>
      <reference source="CVE">CVE-2004-1080</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-60" comment="Windows 2000 Server is installed" negate="false"/>
          <criterion test_ref="wrt-538" comment="Win2K/XP/2003 service pack 4 (or earlier) is installed" negate="false"/>
          <criterion test_ref="wft-163" comment="the version of wins.exe is less than 5.0.2195.7005" negate="false"/>
          <criterion test_ref="wrt-38" comment="the patch KB870763 is installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-98" comment="the wins service is enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL2545" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>HyperTerminal</product>
      </affected>
      <dates>
        <submitted date="2004-12-17-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2005-01-18-12:00">DRAFT</status_change>
        <status_change date="2005-02-02-12:00">INTERIM</status_change>
        <modified date="2005-03-02-12:00" comment="modified wft-176 - access DLL via HKLM">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </modified>
        <status_change date="2005-03-23-12:00">ACCEPTED</status_change>
        <modified date="2005-03-29-12:00" comment="modified wrt-45 - deleted an extra space after Filelist">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <modified date="2005-04-22-12:00" comment="modified wrt-45 - Removed extra space between 'Windows XP' in the key field">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </modified>
        <status_change date="2005-04-27-12:05">INTERIM</status_change>
        <status_change date="2005-06-01-03:30">ACCEPTED</status_change>
      </dates>
      <description>HyperTerminal application for Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 does not properly validate the length of a value that is saved in a session file, which allows remote attackers to execute arbitrary code via a malicious HyperTerminal session file (.ht), web site, or Telnet URL contained in an e-mail message, triggering a buffer overflow.</description>
      <reference source="CVE">CVE-2004-0568</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-2" comment="Windows XP is installed" negate="false"/>
          <criterion test_ref="wrt-250" comment="Win2K/XP/2003 service pack 2 is installed" negate="false"/>
          <criterion test_ref="wft-176" comment="the version of hypertrm.dll is less than 5.1.2600.2563" negate="false"/>
          <criterion test_ref="wrt-45" comment="the patch WindowsXP-KB87339-x86-ENU.exe is installed " negate="true"/>
        </software>
        <configuration operation="OR">
          <criterion test_ref="wrt-39" comment="If key present hyperterminal will automatically open session files" negate="false"/>
          <criterion test_ref="wrt-67" comment="If the Hyperterminal client is registered as the default telnet client" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL2559" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Internet Explorer 6</product>
      </affected>
      <dates>
        <submitted date="2005-05-10-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2005-05-11-05:38">DRAFT</status_change>
        <status_change date="2005-06-01-03:30">INTERIM</status_change>
        <status_change date="2005-06-22-12:38">ACCEPTED</status_change>
        <modified date="2005-09-26-12:44" comment="modified wft-594 - Changed comment to match test">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-28-01:04">INTERIM</status_change>
        <status_change date="2005-10-19-05:47">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the URL processor of Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a URL with a long hostname, aka "URL Parsing Memory Corruption Vulnerability."</description>
      <reference source="CVE">CVE-2005-0554</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-51" comment="Internet Explorer 6  for Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wft-594" comment="the version of mshtml.dll is less than 6.0.3790.279" negate="false"/>
          <criterion test_ref="wrt-438" comment="the patch kb890923 is installed (Hotfix key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL2562" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Windows kernel</product>
      </affected>
      <dates>
        <submitted date="2005-05-02-12:00">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </submitted>
        <status_change date="2005-05-04-12:00">DRAFT</status_change>
        <status_change date="2005-06-01-12:00">INTERIM</status_change>
        <modified date="2005-06-02-12:00" comment="Added product">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <modified date="2005-06-17-12:00" comment="modified cmp-1106 - Replaced the test that checks for the service pack level, instead of checking for sp4 or ealier (did not check for GOLD edition) it is now negating the test that checks for sp5 for later.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <status_change date="2005-07-27-10:37">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the font processing component of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via a specially-designed application.</description>
      <reference source="CVE">CVE-2005-0060</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1106" comment="Windows 2000 (sp4 or earlier) is installed" negate="false"/>
          <criterion test_ref="wft-579" comment="The version of Ntoskrnl.exe is less than 5.0.2195.7035" negate="false"/>
          <criterion test_ref="wrt-427" comment="the patch KB890859 is installed (Hotfix key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL2568" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>MDAC 2.8</product>
      </affected>
      <dates>
        <submitted date="2005-03-29-12:00">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </submitted>
        <status_change date="2005-03-29-08:38">DRAFT</status_change>
        <status_change date="2005-04-13-12:15">INTERIM</status_change>
        <status_change date="2005-05-04-12:33">ACCEPTED</status_change>
      </dates>
      <description>The License Logging service for Windows NT Server, Windows 2000 Server, and Windows Server 2003 does not properly validate the length of messages, which leads to an "unchecked buffer" and allows remote attackers to cause a denial of service (crash) and possibly execute arbtirary code, aka the "License Logging Service Vulnerability."</description>
      <reference source="CVE">CVE-2005-0050</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-60" comment="Windows 2000 Server is installed" negate="false"/>
          <criterion test_ref="wrt-96" comment="the patch kb885834 is installed (Hotfix key)" negate="true"/>
          <criterion test_ref="wft-394" comment="the version of Llssrv.exe is less than 5.0.2195.7021" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-344" comment="license logging service is enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL2570" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Hyperlink Object Library</product>
      </affected>
      <dates>
        <submitted date="2005-02-24-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <status_change date="2005-03-02-09:00">DRAFT</status_change>
        <status_change date="2005-03-23-08:09">INTERIM</status_change>
        <status_change date="2005-04-13-12:15">ACCEPTED</status_change>
      </dates>
      <description>The Hyperlink Object Library for Windows 98, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary code via a crafted link that triggers an "unchecked buffer" in the library, possibly due to a buffer overflow.</description>
      <reference source="CVE">CVE-2005-0057</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-2" comment="Windows XP is installed" negate="false"/>
          <criterion test_ref="wft-369" comment="the version of hlink.dll is less than 5.2.3790.227" negate="false"/>
          <criterion test_ref="wrt-78" comment="the patch kb888113 is installed (Hotfix key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL2572" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>libpng</product>
      </affected>
      <dates>
        <submitted date="2004-12-12-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-24-12:04">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>The png_handle_iCCP function in libpng 1.2.5 and earlier allows remote attackers to cause a denial of service (application crash) via a certain PNG image that triggers a null dereference.</description>
      <reference source="CVE">CVE-2004-0598</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" negate="false"/>
          <criterion test_ref="sat-11" comment="Netscape installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL2580" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Windows Animated Cursor</product>
      </affected>
      <dates>
        <submitted date="2005-01-14-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2005-01-20-02:31">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>The Windows Animated Cursor (ANI) capability in Windows NT, Windows 2000 through SP4, Windows XP through SP1, and Windows 2003 allow remote attackers to cause a denial of service via (1) the frame number set to zero, which causes an invalid memory address to be used and leads to a kernel crash, or (2) the rate number set to zero, which leads to resource exhaustion and hang.</description>
      <reference source="CVE">CVE-2004-1305</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-62" comment="Windows Server 2003 or Windows Server 2003 64-bit Edition is installed" negate="false"/>
          <criterion test_ref="wft-355" comment="the version of user32.dll is less than 5.2.3790.245" negate="false"/>
          <criterion test_ref="wrt-68" comment="the patch kb891711 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL2590" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Sun Cluster</product>
      </affected>
      <dates>
        <submitted date="2004-10-19-03:11">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2004-10-20-02:35">DRAFT</status_change>
        <status_change date="2004-11-03-12:00">INTERIM</status_change>
        <status_change date="2004-12-09-08:46">ACCEPTED</status_change>
      </dates>
      <description>Double-free vulnerability in OpenSSL 0.9.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an SSL client certificate with a certain invalid ASN.1 encoding.</description>
      <reference source="CVE">CVE-2003-0545</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" negate="false"/>
          <criterion test_ref="spt-266" comment="Patch 113505-02 or later installed" negate="true"/>
          <criterion test_ref="spt-267" comment="Patch 113508-02 or later installed" negate="true"/>
          <criterion test_ref="spt-268" comment="Patch 115054-01 or later installed" negate="true"/>
          <criterion test_ref="spt-269" comment="Patch 115055-01 or later installed" negate="true"/>
          <criterion test_ref="sat-8" comment="SunCluster Component SUNWscvw installed" negate="false"/>
          <criterion test_ref="sat-5" comment="Apache (SUNWapchu) installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-13" comment="Apache running with SunPlex Manager config" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL2592" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>kcms_server</product>
      </affected>
      <dates>
        <submitted date="2005-01-19-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-24-03:40">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Directory traversal vulnerability in Sun Kodak Color Management System (KCMS) library service daemon (kcms_server) allows remote attackers to read arbitrary files via the KCS_OPEN_PROFILE procedure.</description>
      <reference source="CVE">CVE-2003-0027</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" negate="false"/>
          <criterion test_ref="sat-18" comment="Kodak Color Managment Server (KCMS) Runtime Environment (SUNWkcsrt/SUNWkcsrx) installed" negate="false"/>
          <criterion test_ref="spt-20" comment="Patch 114636-01 or later installed" negate="true"/>
          <criterion test_ref="spt-21" comment="Patch 107337-03 or later installed" negate="true"/>
          <criterion test_ref="spt-22" comment="Patch 111400-02 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-206" comment="inetd.conf contains kcms_server" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL2611" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Internet Explorer 6</product>
      </affected>
      <dates>
        <submitted date="2004-10-25-04:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2004-10-27-04:00">DRAFT</status_change>
        <status_change date="2004-11-17-05:00">INTERIM</status_change>
        <status_change date="2004-12-09-05:00">ACCEPTED</status_change>
        <modified date="2005-09-20-04:00" comment="Changed IE registry test to wrt-18">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-21-01:27">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 6.x allows remote attackers to install arbitrary programs via mousedown events that call the Popup.show method and use drag-and-drop actions in a popup window, aka "HijackClick 3" and the "Script in Image Tag File Download Vulnerability."</description>
      <reference source="CVE">CVE-2004-0841</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wft-563" comment="the version of mshtml.dll is less than 6.0.2745.2800" negate="false"/>
          <criterion test_ref="wrt-562" comment="the patch kb834707 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-18" comment="Internet Explorer 6 is installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL2621" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>Sun Crypto Accelerator 4000</product>
      </affected>
      <dates>
        <submitted date="2004-10-12-09:44">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2004-10-13-01:15">DRAFT</status_change>
        <status_change date="2004-10-27-12:00">INTERIM</status_change>
        <status_change date="2004-11-17-10:00">ACCEPTED</status_change>
      </dates>
      <description>The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that triggers a null dereference.</description>
      <reference source="CVE">CVE-2004-0079</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" negate="false"/>
          <criterion test_ref="spt-243" comment="Patch 114796-04 or later installed" negate="true"/>
          <criterion test_ref="sat-2" comment="Sun Crypto Accelerator 4000 software installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-10" comment="Apache running (httpd)" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL2638" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 98</windows:platform>
        <product>Windows Shell</product>
      </affected>
      <dates>
        <submitted date="2004-10-14-03:37">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <status_change date="2004-10-20-02:35">DRAFT</status_change>
        <status_change date="2004-11-03-12:00">INTERIM</status_change>
        <status_change date="2004-12-09-08:46">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in Microsoft Internet Explorer and Explorer on Windows XP SP1, WIndows 2000, Windows 98, and Windows Me may allow remote malicious servers to cause a denial of service (application crash) and possibly execute arbitrary code via long share names, as demonstrated using Samba.</description>
      <reference source="CVE">CVE-2004-0214</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-391" comment="Windows 98 Installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL2657" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Outlook Express</product>
      </affected>
      <dates>
        <submitted date="2004-08-26-12:00">
          <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
        </submitted>
        <status_change date="2004-08-26-10:32">DRAFT</status_change>
        <status_change date="2004-09-09-12:00">INTERIM</status_change>
        <status_change date="2004-09-29-12:00">ACCEPTED</status_change>
        <modified date="2005-06-02-12:00" comment="Added product">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-06-08-03:17">INTERIM</status_change>
        <status_change date="2005-06-29-06:49">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Outlook Express 5.5 and 6 allows attackers to cause a denial of service (application crash) via a malformed e-mail header.</description>
      <reference source="CVE">CVE-2004-0215</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wrt-172" comment="Outlook Express 6 for Windows 2003 is installed" negate="false"/>
          <criterion test_ref="wrt-494" comment="the patch kb823353 is installed " negate="true"/>
          <criterion test_ref="cmp-1098" comment="a vulnerable version of inetcomm.dll exisits" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-495" comment="all users have the preview pane disabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL2665" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>Sun Am7990 Ethernet Driver</product>
      </affected>
      <dates>
        <submitted date="2004-12-30-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-12-12:41">DRAFT</status_change>
      </dates>
      <description>Multiple ethernet Network Interface Card (NIC) device drivers do not pad frames with null bytes, which allows remote attackers to obtain information from previous packets or kernel memory by using malformed packets, as demonstrated by Etherleak.</description>
      <reference source="CVE">CVE-2003-0001</reference>
      <status>DRAFT</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" negate="false"/>
          <criterion test_ref="spt-16" comment="Patch 112604-02 or later installed" negate="true"/>
          <criterion test_ref="spt-17" comment="Patch 112609-02 or later installed" negate="true"/>
          <criterion test_ref="spt-18" comment="Patch 115172-01 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uft-30" comment="Lance Ethernet (le) interface configured to start" negate="false"/>
          <criterion test_ref="ukn-2" comment="Lance Ethernet interface in use" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL2670" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Office 2000 SP3</product>
      </affected>
      <dates>
        <submitted date="2004-09-28-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2004-09-29-12:00">DRAFT</status_change>
        <status_change date="2004-10-20-12:00">INTERIM</status_change>
        <status_change date="2004-11-03-12:00">ACCEPTED</status_change>
        <modified date="2005-02-10-12:00" comment="modified wft-489 - corrected registry path check for .dll file">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <status_change date="2005-02-11-09:31">INTERIM</status_change>
        <status_change date="2005-03-02-09:01">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the converter for Microsoft WordPerfect 5.x on Office 2000, Office XP, Office 2003, and Works Suites 2001 through 2004 allows remote attackers to execute arbitrary code via a malicious document or website.</description>
      <reference source="CVE">CVE-2004-0573</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wft-489" comment="the version of msconv97.dll is less than 2003.1100.6252.0 " negate="false"/>
          <criterion test_ref="wrt-530" comment="the patch kb873380 for Office 2000 SP3 is installed " negate="true"/>
          <criterion test_ref="cmp-1103" comment="Microsoft Office 2000 (Premium or Professional) Service Pack 3 is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL2671" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Certificate Validation</product>
      </affected>
      <dates>
        <submitted date="2004-07-11-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <modified date="2004-07-12-12:00" comment="negated patch info.">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <modified date="2004-07-13-12:00" comment="Added superceding patch info.">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <modified date="2004-07-14-12:00" comment="Changed to DRAFT">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2004-08-04-12:00">INTERIM</status_change>
        <status_change date="2004-08-25-12:00">ACCEPTED</status_change>
        <modified date="2005-06-02-12:00" comment="Added product">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-06-08-03:17">INTERIM</status_change>
        <status_change date="2005-06-29-06:49">ACCEPTED</status_change>
      </dates>
      <description>The (1) CertGetCertificateChain, (2) CertVerifyCertificateChainPolicy, and (3) WinVerifyTrust APIs within the CryptoAPI for Microsoft products including Microsoft Windows 98 through XP, Office for Mac, Internet Explorer for Mac, and Outlook Express for Mac, do not properly verify the Basic Constraints of intermediate CA-signed X.509 certificates, which allows remote attackers to spoof the certificates of trusted sites via a man-in-the-middle attack for SSL sessions, as originally reported for Internet Explorer and IIS.</description>
      <reference source="CVE">CVE-2002-0862</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-65" comment="Windows 2000 (sp3 or earlier) is installed" negate="false"/>
          <criterion test_ref="wft-434" comment="the version of cryptdlg.dll is less then 5.0.1558.6072" negate="false"/>
          <criterion test_ref="wrt-477" comment="the patch Q329115 is installed" negate="true"/>
          <criterion test_ref="wrt-187" comment="the patch kb835732 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL2673" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 95</windows:platform>
        <windows:platform>Microsoft Windows 98</windows:platform>
        <windows:platform>Microsoft Windows ME</windows:platform>
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Excel 2000</product>
      </affected>
      <dates>
        <submitted date="2004-10-18-12:07">
          <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
        </submitted>
        <status_change date="2004-10-20-02:35">DRAFT</status_change>
        <status_change date="2004-11-03-12:00">INTERIM</status_change>
        <status_change date="2004-12-09-08:46">ACCEPTED</status_change>
      </dates>
      <description>Unknown vulnerability in Microsoft Excel 2000, 2002, 2001 for Mac, and v.X for Mac allows remote attackers to execute arbitrary code via a malicious file containing certain parameters that are not properly validated.</description>
      <reference source="CVE">CVE-2004-0846</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-535" comment="Microsoft Office 2000 Professional Service Pack 3 is installed" negate="false"/>
          <criterion test_ref="wrt-137" comment="Excel 2000 is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL2685" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 95</windows:platform>
        <windows:platform>Microsoft Windows 98</windows:platform>
        <windows:platform>Microsoft Windows ME</windows:platform>
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Word 2000</product>
      </affected>
      <dates>
        <submitted date="2005-09-15-04:00">
          <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
        </submitted>
        <status_change date="2005-09-21-01:33">DRAFT</status_change>
        <status_change date="2005-10-12-05:49">INTERIM</status_change>
        <status_change date="2005-11-16-08:02">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in Microsoft Word 2000, Word 2002, and Word 2003 allows remote attackers to execute arbitrary code via a crafted document.</description>
      <reference source="CVE">CVE-2005-0558</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-132" comment="Word 2000 is installed" negate="false"/>
          <criterion test_ref="wft-608" comment="the version of winword.exe is less than 9.0.0.8929" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL2689" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Word 2003</product>
      </affected>
      <dates>
        <submitted date="2005-08-18-04:00">
          <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
        </submitted>
        <status_change date="2005-08-25-10:05">DRAFT</status_change>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial of service (connection loss) to persistent TCP connections by repeatedly injecting a TCP RST packet, especially in protocols that use long-lived connections, such as BGP.</description>
      <reference source="CVE">CVE-2004-0230</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="cmp-23" comment="32-bit version of Windows or 64-bit (itanium architecture) version of Windows is installed" negate="false"/>
          <criterion test_ref="wrt-3" comment="a Win2K/XP/2003 service pack is installed" negate="true"/>
          <criterion test_ref="wft-600" comment="the version of Tcpip.sys is less than 5.2.3790.336" negate="false"/>
          <criterion test_ref="wrt-443" comment="the patch KB893066 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL2692" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Internet Explorer 5.01 Service Pack 3</product>
      </affected>
      <dates>
        <submitted date="2005-03-17-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2005-03-23-08:09">DRAFT</status_change>
        <status_change date="2005-04-13-12:15">INTERIM</status_change>
        <status_change date="2005-05-04-12:33">ACCEPTED</status_change>
        <modified date="2005-12-26-09:40" comment="Removed test to check kb867282.">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </modified>
        <status_change date="2006-01-12-08:59">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 5.01, 5.5, and 6 does not properly validate buffers when handling certain DHTML methods including the createControlRange Javascript function, which allows remote attackers to execute arbitrary code, aka the "DHTML Method Heap Memory Corruption Vulnerability."</description>
      <reference source="CVE">CVE-2005-0055</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-55" comment="Internet Explorer 5.01 Service Pack 3 is installed" negate="false"/>
          <criterion test_ref="wft-406" comment="the version of mshtml.dll is less than 5.0.3528.700" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL2705" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>DirectX</product>
      </affected>
      <dates>
        <submitted date="2004-06-15-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <modified date="2004-06-16-12:00" comment="Changed Status to Draft; Added cmp-970">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </modified>
        <modified date="2004-07-06-12:00" comment="Added the negate attribute with a value of 'true' to the subtest elements referencing patch installations.">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </modified>
        <status_change date="2004-07-12-12:00">INTERIM</status_change>
        <status_change date="2004-07-21-12:00">ACCEPTED</status_change>
      </dates>
      <description>IDirectPlay4 Application Programming Interface (API) of Microsoft DirectPlay 7.0a thru 9.0b, as used in Windows Server 2003 and earlier allows remote attackers to cause a denial of service (application crash) via a malformed packet.</description>
      <reference source="CVE">CVE-2004-0202</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-413" comment="Windows XP or Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wrt-70" comment="64-Bit version of Windows is installed" negate="false"/>
          <criterion test_ref="cmp-967" comment="DirectX 8.1 without kb839643 installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL2706" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Microsoft Office 2003</product>
      </affected>
      <dates>
        <submitted date="2004-09-24-12:00">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </submitted>
        <modified date="2004-09-27-12:00" comment="changed affected product from GDI+ and office2003 to just office 2003">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <status_change date="2004-09-29-12:00">DRAFT</status_change>
        <status_change date="2004-10-13-12:00">INTERIM</status_change>
        <status_change date="2004-10-27-12:00">ACCEPTED</status_change>
        <modified date="2005-02-10-12:00" comment="modified wft-495 - corrected registry path check for .dll file">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <status_change date="2005-02-11-09:31">INTERIM</status_change>
        <status_change date="2005-03-02-09:01">ACCEPTED</status_change>
        <modified date="2005-12-26-09:40" comment="Changed criteria to remove test for KB838905.  Changed criteria to use a new test for gdiplus.dll version, which uses a registry key specific to MS Office to determine the file's path.">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </modified>
        <status_change date="2006-01-12-08:59">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length before a memory copy operation.</description>
      <reference source="CVE">CVE-2004-0200</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-515" comment="Microsoft Office 2003 is installed" negate="false"/>
          <criterion test_ref="wft-715" comment="the version of Gdiplus.dll for Microsoft Office is less than 6.0.3264.0" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL2719" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>OpenSSH</product>
      </affected>
      <dates>
        <submitted date="2004-12-30-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-12-12:41">DRAFT</status_change>
        <status_change date="2005-02-02-12:00">INTERIM</status_change>
        <status_change date="2005-02-23-09:25">ACCEPTED</status_change>
      </dates>
      <description>A "buffer management error" in buffer_append_space of buffer.c for OpenSSH before 3.7 may allow remote attackers to execute arbitrary code by causing an incorrect amount of memory to be freed and corrupting the heap, a different vulnerability than CVE-2003-0695.</description>
      <reference source="CVE">CVE-2003-0693</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-6" comment="Solaris 9 Installed" negate="false"/>
          <criterion test_ref="spt-19" comment="Patch 113273-04 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-16" comment="sshd running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL2730" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 95</windows:platform>
        <windows:platform>Microsoft Windows 98</windows:platform>
        <windows:platform>Microsoft Windows ME</windows:platform>
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>MDAC 2.5</product>
      </affected>
      <dates>
        <submitted date="2004-08-24-12:00">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </submitted>
        <status_change date="2004-08-25-12:00">DRAFT</status_change>
        <status_change date="2004-09-09-12:00">INTERIM</status_change>
        <status_change date="2004-09-29-12:00">ACCEPTED</status_change>
        <modified date="2005-02-28-12:00" comment="removed the test for windows NT and added a test for MDAC 2.5 since this definition is dependent on the MDAC version and not the platform">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <status_change date="2005-03-02-08:52">INTERIM</status_change>
        <status_change date="2005-03-23-08:09">ACCEPTED</status_change>
      </dates>
      <description>Heap-based buffer overflow in the Remote Data Services (RDS) component of Microsoft Data Access Components (MDAC) 2.1 through 2.6, and Internet Explorer 5.01 through 6.0, allows remote attackers to execute code via a malformed HTTP request to the Data Stub.</description>
      <reference source="CVE">CVE-2002-1142</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-100" comment="MDAC 2.5 is installed" negate="false"/>
          <criterion test_ref="wft-482" comment="the version of msadco.dll is less than 2.53.6202.0" negate="false"/>
          <criterion test_ref="wrt-503" comment="Patch Q329414 Installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL2731" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Windows kernel</product>
      </affected>
      <dates>
        <submitted date="2005-05-02-12:00">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </submitted>
        <status_change date="2005-05-04-12:00">DRAFT</status_change>
        <status_change date="2005-06-01-12:00">INTERIM</status_change>
        <modified date="2005-06-02-12:00" comment="Added product">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-06-22-12:38">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the font processing component of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via a specially-designed application.</description>
      <reference source="CVE">CVE-2005-0060</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wft-583" comment="The version of Ntoskrnl.exe is less than 5.2.3790.280" negate="false"/>
          <criterion test_ref="wrt-427" comment="the patch KB890859 is installed (Hotfix key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL2734" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>Windows Internet Naming Service (WINS)</product>
      </affected>
      <dates>
        <submitted date="2004-12-17-12:00">
          <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
        </submitted>
        <status_change date="2005-01-12-12:00">DRAFT</status_change>
        <status_change date="2005-02-02-12:00">INTERIM</status_change>
        <status_change date="2005-02-23-12:00">ACCEPTED</status_change>
        <modified date="2005-06-02-12:00" comment="Added product">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-06-08-03:17">INTERIM</status_change>
        <status_change date="2005-06-29-06:49">ACCEPTED</status_change>
      </dates>
      <description>The WINS service (wins.exe) on Microsoft Windows NT Server 4.0, Windows 2000 Server, and Windows Server 2003 allows remote attackers to write to arbitrary memory locations and possibly execute arbitrary code via a modified memory pointer in a WINS replication packet to TCP port 42, aka the "Association Context Vulnerability."</description>
      <reference source="CVE">CVE-2004-1080</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-43" comment="this is an NT Terminal Server" negate="false"/>
          <criterion test_ref="wft-165" comment="the version of wins.exe is less than 4.0.1381.33618" negate="false"/>
          <criterion test_ref="wrt-38" comment="the patch KB870763 is installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-98" comment="the wins service is enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL2738" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 98</windows:platform>
        <windows:platform>Microsoft Windows ME</windows:platform>
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Microsoft Visio Professional 2002</product>
      </affected>
      <dates>
        <submitted date="2005-03-29-12:00">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </submitted>
        <status_change date="2005-03-29-08:38">DRAFT</status_change>
        <status_change date="2005-04-13-12:15">INTERIM</status_change>
        <status_change date="2005-05-04-12:33">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in Microsoft Office XP allows remote attackers to execute arbitrary code via a link with a URL file location containing long inputs after (1) "%00 (null byte) in .doc filenames or (2) "%0a" (carriage return) in .rtf filenames.</description>
      <reference source="CVE">CVE-2004-0848</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-525" comment="Visio Professional 2002 with service pack 2" negate="false"/>
          <criterion test_ref="wrt-89" comment="Patch KB873354 installed" negate="true"/>
          <criterion test_ref="wft-377" comment="the version of mso.dll is less than 10.0.6735.0" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL2753" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Program Group Converter</product>
      </affected>
      <dates>
        <submitted date="2004-10-14-03:39">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <status_change date="2004-10-20-02:35">DRAFT</status_change>
        <status_change date="2004-11-03-12:00">INTERIM</status_change>
        <status_change date="2004-12-09-08:46">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the Windows Program Group Converter (grpconv.exe) may allow remote attackers to execute arbitrary code via a shell: URL with a long filename and a .grp extension, which is not properly handled when the shell capability launches grpconv.exe.</description>
      <reference source="CVE">CVE-2004-0572</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
          <criterion test_ref="wft-519" comment="the version of grpconv.exe (system32) is less than 5.0.2195.6966" negate="false"/>
          <criterion test_ref="wrt-537" comment="the patch q841356 is installed (Hotfix key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL2770" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>CDE</product>
      </affected>
      <dates>
        <submitted date="2004-10-15-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2004-10-20-12:00">DRAFT</status_change>
        <status_change date="2004-11-03-12:00">INTERIM</status_change>
        <status_change date="2004-12-09-12:00">ACCEPTED</status_change>
        <modified date="2005-01-11-12:00" comment="modified sat-6 - Changed test to pattern match and added check for 64bit version">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </modified>
        <modified date="2005-01-14-12:00" comment="modified sat-6 - Changed regular expression test to properly check for 64bit package">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </modified>
        <status_change date="2005-01-24-02:39">INTERIM</status_change>
        <status_change date="2005-02-16-12:00">ACCEPTED</status_change>
      </dates>
      <description>CDE ToolTalk database server (ttdbserver) allows local users to overwrite arbitrary files via a symlink attack on the transaction log file used by the _TT_TRANSACTION RPC procedure.</description>
      <reference source="CVE">CVE-2002-0678</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-6" comment="Solaris 9 Installed" negate="false"/>
          <criterion test_ref="sat-6" comment="Toolktalk (SUNWtltk/SUNWtltkx) installed" negate="false"/>
          <criterion test_ref="spt-255" comment="Patch 112808-02 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
          <criterion test_ref="sit-202" comment="inetd.conf contains rpc.ttdbserverd" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL2786" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Internet Explorer 5.01 Service Pack 4</product>
      </affected>
      <dates>
        <submitted date="2005-05-10-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2005-05-11-05:38">DRAFT</status_change>
        <status_change date="2005-06-01-03:30">INTERIM</status_change>
        <status_change date="2005-06-22-12:38">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the Content Advisor in Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a crafted Content Advisor file, aka "Content Advisor Memory Corruption Vulnerability."</description>
      <reference source="CVE">CVE-2005-0555</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-54" comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false"/>
          <criterion test_ref="wft-599" comment="the version of mshtml.dll is less than 5.0.3826.2400" negate="false"/>
          <criterion test_ref="wrt-442" comment="the patch kb890923 is installed (Win2K SP4  Hotfix key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL2816" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>fs.auto, xfs</product>
      </affected>
      <dates>
        <submitted date="2005-01-19-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-24-03:40">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in Dispatch() routine for XFS font server (fs.auto) on Solaris 2.5.1 through 9 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a certain XFS query.</description>
      <reference source="CVE">CVE-2002-1317</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-6" comment="Solaris 9 Installed" negate="false"/>
          <criterion test_ref="sat-21" comment="X Window System Font Server (SUNWxwfs) installed" negate="false"/>
          <criterion test_ref="spt-42" comment="Patch 113923-02 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-207" comment="inetd.conf contains fs.auto" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL2817" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Internet Explorer 6.0 for Windows Server 2003</product>
      </affected>
      <dates>
        <submitted date="2005-03-17-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2005-03-23-12:00">DRAFT</status_change>
        <status_change date="2005-04-13-12:00">INTERIM</status_change>
        <modified date="2005-04-21-03:53" comment="modified wrt-158 - removed note">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </modified>
        <modified date="2005-04-21-12:00" comment="modified wrt-158 - removed value to check against">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </modified>
        <modified date="2005-05-10-12:00" comment="modified wrt-51 - Comment updated to indicate IE 6.">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </modified>
        <status_change date="2005-06-01-03:30">ACCEPTED</status_change>
        <modified date="2005-12-26-09:40" comment="Removed test to check kb867282.">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </modified>
        <status_change date="2006-01-12-08:59">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 5.01, 5.5, and 6 does not properly validate certain URLs in Channel Definition Format (CDF) files, which allows remote attackers to obtain sensitive information or execute arbitrary code, aka the "Channel Definition Format (CDF) Cross Domain Vulnerability."</description>
      <reference source="CVE">CVE-2005-0056</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-51" comment="Internet Explorer 6  for Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wft-405" comment="the version of mshtml.dll is less than 6.0.3790.259" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL2819" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>Linux kernel</product>
      </affected>
      <dates>
        <submitted date="2004-09-01-11:51">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-09-08-10:41">DRAFT</status_change>
        <status_change date="2004-09-22-12:00">INTERIM</status_change>
        <status_change date="2004-10-06-12:00">ACCEPTED</status_change>
      </dates>
      <description>The do_fork function in Linux 2.4.x before 2.4.26, and 2.6.x before 2.6.6, does not properly decrement the mm_count counter when an error occurs after the mm_struct for a child process has been activated, which triggers a memory leak that allows local users to cause a denial of service (memory exhaustion) via the clone (CLONE_VM) system call.</description>
      <reference source="CVE">CVE-2004-0427</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1100" comment="kernel, kernel-hugemem or kernel-smp rpm older than 2.4.21-15.0.2EL Epoch 0" negate="false"/>
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL2830" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Windows 2000</product>
      </affected>
      <dates>
        <submitted date="2005-02-10-12:00">
          <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
        </submitted>
        <status_change date="2005-02-11-12:00">DRAFT</status_change>
        <modified date="2005-03-01-12:00" comment="Removed software test to check for Windows service Packs">
          <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
        </modified>
        <modified date="2005-03-24-12:00" comment="Added a configuration test to see if ActiveX controls are enabled.">
          <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
        </modified>
        <status_change date="2005-04-13-12:15">INTERIM</status_change>
        <status_change date="2005-05-04-12:33">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 6.0 on Windows XP SP2 allows remote attackers to execute arbitrary code by using the "Related Topics" command in the Help ActiveX Control (hhctrl.ocx) to open a Help popup window containing the PCHealth tools.htm file in the local zone and injecting Javascript to be executed, as demonstrated using "writehta.txt" and the ADODB recordset, which saves a .HTA file to the local system, aka the "HTML Help ActiveX control Cross Domain Vulnerability."</description>
      <reference source="CVE">CVE-2004-1043</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
          <criterion test_ref="wft-390" comment="the version of hhctrl.ocx is less than 5.2.3790.233" negate="false"/>
          <criterion test_ref="wrt-93" comment="the patch kb890175 is installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL2847" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>POSIX</product>
      </affected>
      <dates>
        <submitted date="2004-07-13-12:00">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </submitted>
        <status_change date="2004-08-04-12:00">INTERIM</status_change>
        <status_change date="2004-08-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>The POSIX component of Microsoft Windows NT and Windows 2000 allows local users to execute arbitrary code via certain parameters, possibly by modifying message length values and causing a buffer overflow.</description>
      <reference source="CVE">CVE-2004-0210</reference>
      <status>ACCEPTED</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-480" comment="the patch kb841872 is installed" negate="true"/>
          <criterion test_ref="wft-441" comment="the version of psxss.exe is less than 5.0.2195.6929" negate="false"/>
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-479" comment="POSIX is enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL2884" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Distributed Component Object Model (DCOM) interface</product>
      </affected>
      <dates>
        <submitted date="2005-01-18-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2005-01-20-02:31">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Heap-based buffer overflow in the Distributed Component Object Model (DCOM) interface in the RPCSS Service allows remote attackers to execute arbitrary code via a malformed RPC request with a long filename parameter, a different vulnerability than CVE-2003-0352 (Blaster/Nachi) and CVE-2003-0715.</description>
      <reference source="CVE">CVE-2003-0528</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-57" comment="Windows XP 32-bit SP1 is installed" negate="false"/>
          <criterion test_ref="wft-366" comment="the version of rpcrt4.dll is less than 5.1.2600.1254" negate="false"/>
          <criterion test_ref="wrt-281" comment="the patch kb824146 is installed (Hotfix key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-283" comment="DCOM is enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL2892" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>COM Internet Services</product>
      </affected>
      <dates>
        <submitted date="2005-03-29-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2005-03-29-08:38">DRAFT</status_change>
        <status_change date="2005-04-13-12:15">INTERIM</status_change>
        <status_change date="2005-05-04-12:33">ACCEPTED</status_change>
      </dates>
      <description>Windows 2000, XP, and Server 2003 does not properly "validate the use of memory regions" for COM structured storage files, which allows attackers to execute arbitrary code, aka the "COM Structured Storage Vulnerability."</description>
      <reference source="CVE">CVE-2005-0047</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-61" comment="Windows XP SP1 OR Windows XP 64-bit SP1 is installed" negate="false"/>
          <criterion test_ref="wft-387" comment="the version of ole32.dll is less than 5.1.2600.1619" negate="false"/>
          <criterion test_ref="wrt-91" comment="the patch KB873333 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL2894" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2004-07-14-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2004-08-04-12:00">INTERIM</status_change>
        <status_change date="2004-08-25-12:00">ACCEPTED</status_change>
        <modified date="2005-12-20-07:05" comment="Changed criteria to drop explicit test for patch kb839645.  Inclusion resulted in false positives w/o incremental patching.">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </modified>
        <status_change date="2006-01-04-08:04">ACCEPTED</status_change>
      </dates>
      <description>The Windows Shell application in Windows 98, Windows ME, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code by spoofing the type of a file via a CLSID specifier in the filename, as demonstrated using Internet Explorer 6.0.2800.1106 on Windows XP.</description>
      <reference source="CVE">CVE-2004-0420</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1112" comment="Windows XP 64-bit" negate="false"/>
          <criterion test_ref="wft-3" comment="the version of helpctr.exe is less than 5.1.2600.1515" negate="true"/>
          <criterion test_ref="wft-448" comment="the version of shell32.dll is less than 6.0.3790.168" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL2906" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Internet Explorer 5.01 Service Pack 4</product>
      </affected>
      <dates>
        <submitted date="2004-10-19-04:45">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2004-10-20-02:35">DRAFT</status_change>
        <status_change date="2004-11-03-12:00">INTERIM</status_change>
        <status_change date="2004-12-09-08:46">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 6.0 SP1 and earlier, and possibly other versions, allows remote attackers to cause a denial of service (application crash from "memory corruption") via certain malformed Cascading Style Sheet (CSS) elements that trigger heap-based buffer overflows, as demonstrated using the "&lt;STYLE>@;/*" string, possibly due to a missing comment terminator that may cause an invalid length to trigger a large memory copy operation, aka the "CSS Heap Memory Corruption Vulnerability."</description>
      <reference source="CVE">CVE-2004-0842</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-54" comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false"/>
          <criterion test_ref="wft-561" comment="the version of mshtml.dll is less than 5.0.3534.2800" negate="false"/>
          <criterion test_ref="wrt-560" comment="the patch kb834707-ie501sp4 is installed (Hotfix key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL2915" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>Linux kernel</product>
      </affected>
      <dates>
        <submitted date="2004-09-02-12:10">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-09-08-10:41">DRAFT</status_change>
        <status_change date="2004-09-22-12:00">INTERIM</status_change>
        <status_change date="2004-10-06-12:00">ACCEPTED</status_change>
      </dates>
      <description>Linux kernel 2.4.x and 2.6.x for x86 allows local users to cause a denial of service (system crash), possibly via an infinite loop that triggers a signal handler with a certain sequence of fsave and frstor instructions, as originally demonstrated using a "crash.c" program.</description>
      <reference source="CVE">CVE-2004-0554</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="cmp-1100" comment="kernel, kernel-hugemem or kernel-smp rpm older than 2.4.21-15.0.2EL Epoch 0" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL2917" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Windows Media Player 9</product>
      </affected>
      <dates>
        <submitted date="2005-02-15-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2005-02-18-12:00">DRAFT</status_change>
        <status_change date="2005-03-09-12:00">INTERIM</status_change>
        <status_change date="2005-03-29-12:00">ACCEPTED</status_change>
        <modified date="2005-06-17-12:00" comment="modified cmp-1106 - Replaced the test that checks for the service pack level, instead of checking for sp4 or ealier (did not check for GOLD edition) it is now negating the test that checks for sp5 for later.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <status_change date="2005-06-22-12:35">INTERIM</status_change>
        <status_change date="2005-07-27-10:37">ACCEPTED</status_change>
      </dates>
      <description>The OLE component in Windows 98, 2000, XP, and Server 2003, and Exchange Server 5.0 through 2003, does not properly validate the lengths of messages for certain OLE data, which allows remote attackers to execute arbitrary code, aka the "Input Validation Vulnerability."</description>
      <reference source="CVE">CVE-2005-0044</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1106" comment="Windows 2000 (sp4 or earlier) is installed" negate="false"/>
          <criterion test_ref="wft-386" comment="the version of ole32.dll is less than 5.0.2195.7021" negate="false"/>
          <criterion test_ref="wrt-91" comment="the patch KB873333 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL2919" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 98</windows:platform>
        <windows:platform>Microsoft Windows ME</windows:platform>
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Adobe Acrobat Reader</product>
      </affected>
      <dates>
        <submitted date="2005-04-26-12:00">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </submitted>
        <status_change date="2005-04-27-12:06">DRAFT</status_change>
        <status_change date="2005-06-01-03:30">INTERIM</status_change>
        <status_change date="2005-06-22-12:38">ACCEPTED</status_change>
      </dates>
      <description>Format string vulnerability in Adobe Acrobat Reader 6.0.0 through 6.0.2 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via an .ETD document containing format string specifiers in (1) title or (2) baseurl fields.</description>
      <reference source="CVE">CVE-2004-1153</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <notes>
        <note>iDEFENSE reports that deleting eBook.api from the plug_ins directory is a workaround.  See http://www.idefense.com/application/poi/display?id=163&amp;type=vulnerabilities</note>
      </notes>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-301" comment="the software Adobe Acrobat Reader major version 6, minor version less than 3 is installed" negate="false"/>
          <criterion test_ref="wft-603" comment="Adobe Acrobat Reader eBook.api plug-in software installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL2953" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Microsoft Internet Explorer 6</product>
      </affected>
      <dates>
        <submitted date="2005-03-17-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2005-03-23-12:00">DRAFT</status_change>
        <status_change date="2005-04-13-12:00">INTERIM</status_change>
        <modified date="2005-04-21-12:00" comment="modified wrt-159 - unchecked value">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </modified>
        <status_change date="2005-05-11-05:41">ACCEPTED</status_change>
        <modified date="2005-12-26-09:40" comment="Removed test to check kb867282.">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </modified>
        <status_change date="2006-01-12-08:59">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via drag and drop events, aka the "Drag-and-Drop Vulnerability."</description>
      <reference source="CVE">CVE-2005-0053</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-200" comment="Internet Explorer 6.0 Installed XP SP2" negate="false"/>
          <criterion test_ref="wft-500" comment="the version of mshtml.dll is less than 6.0.2900.2604" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-258" comment="Check for Drag&amp;Drop enabled and the patch kb834707(wildcard*)  missing" negate="false"/>
          <criterion test_ref="cmp-99" comment="local machine settings are being used and ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL2956" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Cursor and Icon Formatting</product>
      </affected>
      <dates>
        <submitted date="2005-01-14-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2005-01-20-02:31">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Integer overflow in the LoadImage API of the USER32 Lib for Microsoft Windows allows remote attackers to execute arbitrary code via a .bmp, .cur, .ico or .ani file with a large image size field, which leads to a buffer overflow, aka the "Cursor and Icon Format Handling Vulnerability."</description>
      <reference source="CVE">CVE-2004-1049</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-61" comment="Windows XP SP1 OR Windows XP 64-bit SP1 is installed" negate="false"/>
          <criterion test_ref="wft-354" comment="the version of user32.dll is less than 5.1.2600.1617" negate="false"/>
          <criterion test_ref="wrt-68" comment="the patch kb891711 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL2961" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>Linux kernel</product>
      </affected>
      <dates>
        <submitted date="2004-09-02-12:06">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-09-08-10:41">DRAFT</status_change>
        <status_change date="2004-09-22-12:00">INTERIM</status_change>
        <status_change date="2004-10-06-12:00">ACCEPTED</status_change>
      </dates>
      <description>Multiple unknown vulnerabilities in Linux kernel 2.4 and 2.6 allow local users to gain privileges or access kernel memory, as found by the Sparse source code checking tool.</description>
      <reference source="CVE">CVE-2004-0495</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="cmp-1100" comment="kernel, kernel-hugemem or kernel-smp rpm older than 2.4.21-15.0.2EL Epoch 0" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL2968" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Distributed Component Object Model (DCOM) interface</product>
      </affected>
      <dates>
        <submitted date="2005-01-18-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2005-01-20-02:31">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Heap-based buffer overflow in the Distributed Component Object Model (DCOM) interface in the RPCSS Service allows remote attackers to execute arbitrary code via a malformed RPC request with a long filename parameter, a different vulnerability than CVE-2003-0352 (Blaster/Nachi) and CVE-2003-0715.</description>
      <reference source="CVE">CVE-2003-0528</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1058" comment="Windows XP 32-bit edition is installed" negate="false"/>
          <criterion test_ref="wft-359" comment="the version of rpcrt4.dll is less than 5.1.2600.109" negate="false"/>
          <criterion test_ref="wrt-281" comment="the patch kb824146 is installed (Hotfix key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-283" comment="DCOM is enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL2972" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>TCP/IP</product>
      </affected>
      <dates>
        <submitted date="2005-04-13-04:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-04-20-04:00">DRAFT</status_change>
        <status_change date="2005-05-11-04:00">INTERIM</status_change>
        <status_change date="2005-06-01-04:00">ACCEPTED</status_change>
        <status_change date="2005-08-25-10:03">INTERIM</status_change>
        <status_change date="2005-08-25-10:05">DRAFT</status_change>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Unknown vulnerability in the TCP/IP stack for Sun Solaris 8 and 9 allows local users to cause a denial of service (system panic) via unknown vectors.</description>
      <reference source="CVE">CVE-2004-1355</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" negate="false"/>
          <criterion test_ref="spt-78" comment="Patch 116895-01 or later installed" negate="true"/>
          <criterion test_ref="spt-79" comment="Patch 117000-03 or later installed" negate="true"/>
          <criterion test_ref="spt-80" comment="Patch 112233-12 or later installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL2975" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>Sendmail</product>
      </affected>
      <dates>
        <submitted date="2004-12-29-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-12-12:41">DRAFT</status_change>
        <status_change date="2005-02-02-12:00">INTERIM</status_change>
        <status_change date="2005-02-23-09:25">ACCEPTED</status_change>
      </dates>
      <description>The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using the parseaddr function in parseaddr.c.</description>
      <reference source="CVE">CVE-2003-0694</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" negate="false"/>
          <criterion test_ref="sat-14" comment="Sendmail - user (SUNWsndmu) installed" negate="false"/>
          <criterion test_ref="spt-13" comment="Patch 107684-10 or later installed" negate="true"/>
          <criterion test_ref="spt-14" comment="Patch 110615-10 or later installed" negate="true"/>
          <criterion test_ref="spt-240" comment="Patch 113575-05 or later installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL3006" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Internet Explorer 5.01 Service Pack 3</product>
      </affected>
      <dates>
        <submitted date="2005-03-17-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2005-03-23-08:09">DRAFT</status_change>
        <status_change date="2005-04-13-12:15">INTERIM</status_change>
        <status_change date="2005-05-04-12:33">ACCEPTED</status_change>
        <modified date="2005-12-26-09:40" comment="Removed test to check kb867282.">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </modified>
        <status_change date="2006-01-12-08:59">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via drag and drop events, aka the "Drag-and-Drop Vulnerability."</description>
      <reference source="CVE">CVE-2005-0053</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-55" comment="Internet Explorer 5.01 Service Pack 3 is installed" negate="false"/>
          <criterion test_ref="wft-406" comment="the version of mshtml.dll is less than 5.0.3528.700" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-258" comment="Check for Drag&amp;Drop enabled and the patch kb834707(wildcard*)  missing" negate="false"/>
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL3038" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Microsoft Project Professional 2002</product>
      </affected>
      <dates>
        <submitted date="2004-09-27-12:00">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </submitted>
        <status_change date="2004-09-29-12:00">DRAFT</status_change>
        <modified date="2004-09-30-12:00" comment="Changed affected platforms">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <status_change date="2004-10-20-12:00">INTERIM</status_change>
        <status_change date="2004-11-03-12:00">ACCEPTED</status_change>
        <modified date="2005-02-10-12:00" comment="modified wft-496 - corrected registry path check">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <status_change date="2005-02-11-09:31">INTERIM</status_change>
        <status_change date="2005-03-02-09:01">ACCEPTED</status_change>
        <modified date="2005-12-26-09:40" comment="Changed criteria to remove test for KB831931.">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </modified>
        <status_change date="2006-01-12-08:59">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length before a memory copy operation.</description>
      <reference source="CVE">CVE-2004-0200</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-523" comment="Windows Project Professional 2002 Service Pack 1 is installed" negate="false"/>
          <criterion test_ref="wft-496" comment="the version of mso.dll is less than 10.0.6714.0" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL3055" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
      </affected>
      <dates>
        <submitted date="2005-02-10-12:00">
          <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
        </submitted>
        <status_change date="2005-02-11-09:34">DRAFT</status_change>
        <status_change date="2005-03-02-09:01">INTERIM</status_change>
        <status_change date="2005-03-23-08:09">ACCEPTED</status_change>
      </dates>
      <description>The Server service (srvsvc.dll) in Windows XP SP1 and SP2 allows remote attackers to obtain sensitive information (users who are accessing resources) via an anonymous logon using a named pipe, which is not properly authenticated, aka the "Named Pipe Vulnerability."</description>
      <reference source="CVE">CVE-2005-0051</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-61" comment="Windows XP SP1 OR Windows XP 64-bit SP1 is installed" negate="false"/>
          <criterion test_ref="wft-372" comment="the version of srvsvc.dll is less than 5.1.2600.1613" negate="false"/>
          <criterion test_ref="wrt-81" comment="the patch kb888302 is installed (Hotfix key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL3060" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Internet Explorer 6 Service Pack 1 for Windows Server 2003</product>
      </affected>
      <dates>
        <submitted date="2005-03-17-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2005-03-23-12:00">DRAFT</status_change>
        <status_change date="2005-04-13-12:00">INTERIM</status_change>
        <modified date="2005-04-21-08:52" comment="modified wrt-158 - removed note">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </modified>
        <modified date="2005-04-21-12:00" comment="modified wrt-158 - removed value to check against">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </modified>
        <modified date="2005-05-10-12:00" comment="modified wrt-51 - Comment updated to indicate IE 6.">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </modified>
        <status_change date="2005-06-01-03:30">ACCEPTED</status_change>
        <modified date="2005-12-26-09:40" comment="Removed test to check kb867282.">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </modified>
        <status_change date="2006-01-12-08:59">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 5.01, 5.5, and 6 allows remote attackers to spoof a less restrictive security zone and execute arbitrary code via an HTML page containing URLs that contain hostnames that have been double hex encoded, which are decoded twice to generate a malicious hostname, aka the "URL Decoding Zone Spoofing Vulnerability."</description>
      <reference source="CVE">CVE-2005-0054</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-51" comment="Internet Explorer 6  for Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wft-405" comment="the version of mshtml.dll is less than 6.0.3790.259" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL3071" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>Program Group Converter</product>
      </affected>
      <dates>
        <submitted date="2004-10-14-03:39">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <status_change date="2004-10-20-02:35">DRAFT</status_change>
        <status_change date="2004-11-03-12:00">INTERIM</status_change>
        <status_change date="2004-12-09-08:46">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the Windows Program Group Converter (grpconv.exe) may allow remote attackers to execute arbitrary code via a shell: URL with a long filename and a .grp extension, which is not properly handled when the shell capability launches grpconv.exe.</description>
      <reference source="CVE">CVE-2004-0572</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" negate="false"/>
          <criterion test_ref="cmp-1128" comment="a vulnerable version of grpconv.exe exists on NT" negate="false"/>
          <criterion test_ref="wrt-537" comment="the patch q841356 is installed (Hotfix key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL3078" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>CDE</product>
      </affected>
      <dates>
        <submitted date="2005-02-01-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-02-01-08:41">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the AddSuLog function of the CDE dtaction utility allows local users to gain root privileges via a long user name.</description>
      <reference source="CVE">CVE-1999-0691</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="sat-32" comment="CDE application basic runtime environment (SUNWdtbas/SUNWdtbax) installed" negate="false"/>
          <criterion test_ref="spt-106" comment="Patch 108219-01 or later installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL3082" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Microsoft Visio Professional 2002</product>
      </affected>
      <dates>
        <submitted date="2004-09-27-12:00">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </submitted>
        <status_change date="2004-09-29-12:00">DRAFT</status_change>
        <modified date="2004-09-30-12:00" comment="Changed affected platforms">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <status_change date="2004-10-20-12:00">INTERIM</status_change>
        <status_change date="2004-11-03-12:00">ACCEPTED</status_change>
        <modified date="2005-02-10-12:00" comment="modified wft-496 - corrected registry path check">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <status_change date="2005-02-11-09:31">INTERIM</status_change>
        <status_change date="2005-03-02-09:01">ACCEPTED</status_change>
        <modified date="2005-12-26-09:40" comment="Changed criteria to remove test for KB831932.">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </modified>
        <status_change date="2006-01-12-08:59">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length before a memory copy operation.</description>
      <reference source="CVE">CVE-2004-0200</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-525" comment="Visio Professional 2002 with service pack 2" negate="false"/>
          <criterion test_ref="wft-496" comment="the version of mso.dll is less than 10.0.6714.0" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL3095" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Explorer.exe</product>
      </affected>
      <dates>
        <submitted date="2004-07-14-12:00">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </submitted>
        <modified date="2004-07-19-12:00" comment="Modifed without comment">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <status_change date="2004-08-04-12:00">INTERIM</status_change>
        <status_change date="2004-08-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in EXPLORER.EXE on Windows XP allows attackers to execute arbitrary code as the XP user via a desktop.ini file with a long .ShellClassInfo parameter.</description>
      <reference source="CVE">CVE-2003-0306</reference>
      <status>ACCEPTED</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-493" comment="Patch KB821557 Installed" negate="true"/>
          <criterion test_ref="wrt-2" comment="Windows XP is installed" negate="false"/>
          <criterion test_ref="cmp-1074" comment="Version check for XP SP1 and XP no service pack for shell32.dll" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL3097" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>Cursor and Icon Formatting</product>
      </affected>
      <dates>
        <submitted date="2005-01-14-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2005-01-20-02:31">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Integer overflow in the LoadImage API of the USER32 Lib for Microsoft Windows allows remote attackers to execute arbitrary code via a .bmp, .cur, .ico or .ani file with a large image size field, which leads to a buffer overflow, aka the "Cursor and Icon Format Handling Vulnerability."</description>
      <reference source="CVE">CVE-2004-1049</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-45" comment="Windows NT Server 4.0, Terminal Server Edition is installed" negate="false"/>
          <criterion test_ref="wft-352" comment="the version of user32.dll is less than 4.0.1381.33630" negate="false"/>
          <criterion test_ref="wrt-68" comment="the patch kb891711 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL3100" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Internet Explorer 6</product>
      </affected>
      <dates>
        <submitted date="2005-05-10-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2005-05-11-05:38">DRAFT</status_change>
        <status_change date="2005-06-01-03:30">INTERIM</status_change>
        <status_change date="2005-06-22-12:38">ACCEPTED</status_change>
        <modified date="2005-09-26-12:44" comment="modified wft-594 - Changed comment to match test">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-28-01:04">INTERIM</status_change>
        <status_change date="2005-10-19-05:47">ACCEPTED</status_change>
      </dates>
      <description>Race condition in the memory management routines in the DHTML object processor in Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a malicious web page or HTML e-mail, aka "DHTML Object Memory Corruption Vulnerability".</description>
      <reference source="CVE">CVE-2005-0553</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-51" comment="Internet Explorer 6  for Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wft-594" comment="the version of mshtml.dll is less than 6.0.3790.279" negate="false"/>
          <criterion test_ref="wrt-438" comment="the patch kb890923 is installed (Hotfix key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL3120" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>NetDDE</product>
      </affected>
      <dates>
        <submitted date="2004-10-13-04:17">
          <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
        </submitted>
        <status_change date="2004-10-20-02:35">DRAFT</status_change>
        <status_change date="2004-11-03-12:00">INTERIM</status_change>
        <status_change date="2004-12-09-08:46">ACCEPTED</status_change>
      </dates>
      <description>Network Dynamic Data Exchange (NetDDE) services for Microsoft Windows 98, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows attackers to remotely execute arbitrary code or locally gain privileges via a malicious message or application that involves an "unchecked buffer," possibly a buffer overflow.</description>
      <reference source="CVE">CVE-2004-0206</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1107" comment="Windows 2000 (sp5 or earlier) is installed" negate="false"/>
          <criterion test_ref="wft-527" comment="the version of netdde.exe is less than 5.0.2195.6952" negate="false"/>
          <criterion test_ref="wft-528" comment="the version of nddenb32.dll is less than 5.0.2195.6922" negate="false"/>
          <criterion test_ref="wrt-551" comment="the patch KB841533 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL3134" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>mozilla</product>
      </affected>
      <dates>
        <submitted date="2005-01-19-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-24-03:40">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Mozilla 1.5 through 1.7 allows a CA certificate to be imported even when their DN is the same as that of the built-in CA root certificate, which allows remote attackers to cause a denial of service to SSL pages because the malicious certificate is treated as invalid.</description>
      <reference source="CVE">CVE-2004-0758</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" negate="false"/>
          <criterion test_ref="cmp-72" comment="Mozilla components (any SUNWmoznav/SUNWmozmail) installed" negate="false"/>
          <criterion test_ref="spt-46" comment="Patch 117765-02 or later installed" negate="true"/>
          <criterion test_ref="spt-47" comment="Patch 117767-02 or later installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL3137" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Internet Explorer 6.0 for Windows Server 2003</product>
      </affected>
      <dates>
        <submitted date="2005-03-17-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2005-03-23-12:00">DRAFT</status_change>
        <status_change date="2005-04-13-12:00">INTERIM</status_change>
        <modified date="2005-04-21-08:33" comment="modified wrt-158 - removed note">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </modified>
        <modified date="2005-04-21-12:00" comment="modified wrt-158 - removed value to check against">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </modified>
        <modified date="2005-05-10-12:00" comment="modified wrt-51 - Comment updated to indicate IE 6.">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </modified>
        <status_change date="2005-06-01-03:30">ACCEPTED</status_change>
        <modified date="2005-12-26-09:40" comment="Removed test to check kb867282.">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </modified>
        <status_change date="2006-01-12-08:59">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 5.01, 5.5, and 6 does not properly validate buffers when handling certain DHTML methods including the createControlRange Javascript function, which allows remote attackers to execute arbitrary code, aka the "DHTML Method Heap Memory Corruption Vulnerability."</description>
      <reference source="CVE">CVE-2005-0055</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-51" comment="Internet Explorer 6  for Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wft-405" comment="the version of mshtml.dll is less than 6.0.3790.259" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL3138" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>HyperTerminal</product>
      </affected>
      <dates>
        <submitted date="2005-01-07-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2005-01-24-12:00">DRAFT</status_change>
        <modified date="2005-01-27-12:00" comment="modified wrt-44 -  ">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </modified>
        <modified date="2005-03-02-12:00" comment="modified wft-169 - Change to access dll via HKLM">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </modified>
        <status_change date="2005-03-23-08:09">INTERIM</status_change>
        <status_change date="2005-04-13-12:15">ACCEPTED</status_change>
      </dates>
      <description>HyperTerminal application for Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 does not properly validate the length of a value that is saved in a session file, which allows remote attackers to execute arbitrary code via a malicious HyperTerminal session file (.ht), web site, or Telnet URL contained in an e-mail message, triggering a buffer overflow.</description>
      <reference source="CVE">CVE-2004-0568</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wrt-44" comment="the patch Windows 2003 kb873339 is installed " negate="true"/>
          <criterion test_ref="wft-169" comment="the version of hypertrm.dll is less than 5.2.3790.233" negate="false"/>
        </software>
        <configuration operation="OR">
          <criterion test_ref="wrt-39" comment="If key present hyperterminal will automatically open session files" negate="false"/>
          <criterion test_ref="wrt-67" comment="If the Hyperterminal client is registered as the default telnet client" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL3145" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Windows kernel</product>
      </affected>
      <dates>
        <submitted date="2004-07-13-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <modified date="2004-07-14-12:00" comment="Changed to DRAFT">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2004-08-04-12:00">INTERIM</status_change>
        <status_change date="2004-08-25-12:00">ACCEPTED</status_change>
        <modified date="2005-06-02-12:00" comment="Added product">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-06-08-03:17">INTERIM</status_change>
        <status_change date="2005-06-29-06:49">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in Windows Kernel allows local users to gain privileges by causing certain error messages to be passed to a debugger.</description>
      <reference source="CVE">CVE-2003-0112</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
          <criterion test_ref="wft-435" comment="The version of Ntoskrnl.exe is less than 5.0.2195.6159" negate="false"/>
          <criterion test_ref="wrt-478" comment="the patch Q811493 is installed" negate="true"/>
          <criterion test_ref="wrt-187" comment="the patch kb835732 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL3157" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Microsoft Internet Explorer 6</product>
      </affected>
      <dates>
        <submitted date="2005-05-10-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2005-05-11-05:38">DRAFT</status_change>
        <status_change date="2005-06-01-03:30">INTERIM</status_change>
        <status_change date="2005-06-22-12:38">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the Content Advisor in Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a crafted Content Advisor file, aka "Content Advisor Memory Corruption Vulnerability."</description>
      <reference source="CVE">CVE-2005-0555</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-200" comment="Internet Explorer 6.0 Installed XP SP2" negate="false"/>
          <criterion test_ref="wft-595" comment="the version of mshtml.dll is less than 6.0.2900.2627" negate="false"/>
          <criterion test_ref="wrt-439" comment="the patch kb890923  is installed (XP SP2 Hotfix key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL3161" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>VDM</product>
      </affected>
      <dates>
        <submitted date="2004-10-14-09:58">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </submitted>
        <status_change date="2004-10-20-02:35">DRAFT</status_change>
        <status_change date="2004-11-03-12:00">INTERIM</status_change>
        <status_change date="2004-12-09-08:46">ACCEPTED</status_change>
      </dates>
      <description>The Virtual DOS Machine (VDM) subsystem of Microsoft Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows local users to access kernel memory and gain privileges via a malicious program that modified some system structures in a way that is not properly validated by privileged operating system functions.</description>
      <reference source="CVE">CVE-2004-0208</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-2" comment="Windows XP is installed" negate="false"/>
          <criterion test_ref="wrt-547" comment="the patch KB840987 is installed (Hotfix key)" negate="true"/>
          <criterion test_ref="wft-535" comment="the version of vdmdbg.dll is less than 5.1.2600.1560" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL3179" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>HTML Help Facility</product>
      </affected>
      <dates>
        <submitted date="2004-07-14-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <status_change date="2004-08-04-12:00">INTERIM</status_change>
        <status_change date="2004-08-25-12:00">ACCEPTED</status_change>
        <modified date="2005-05-10-12:00" comment="modified wrt-51 - Comment updated to indicate IE 6.">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </modified>
        <status_change date="2005-05-11-05:33">INTERIM</status_change>
        <status_change date="2005-06-01-03:30">ACCEPTED</status_change>
      </dates>
      <description>Heap-based buffer overflow in the HtmlHelp program (hh.exe) in HTML Help for Microsoft Windows 98, Me, NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary commands via a .CHM file with a large length field, a different vulnerability than CVE-2003-1041.</description>
      <reference source="CVE">CVE-2004-0201</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" negate="false"/>
          <criterion test_ref="cmp-1071" comment="Internet Explorer 5.5 SP2 or Internet Explorer 6.0 SP1 is installed" negate="false"/>
          <criterion test_ref="wft-444" comment="the version of itss.dll is less than 5.2.3790.185" negate="false"/>
          <criterion test_ref="wrt-482" comment="the patch kb840315 is installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-491" comment="HTML Help is registered" negate="true"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL3196" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Microsoft Internet Explorer 6</product>
      </affected>
      <dates>
        <submitted date="2005-03-17-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2005-03-23-12:00">DRAFT</status_change>
        <status_change date="2005-04-13-12:00">INTERIM</status_change>
        <modified date="2005-04-21-12:00" comment="modified wrt-159 - unchecked value">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </modified>
        <status_change date="2005-05-11-05:41">ACCEPTED</status_change>
        <modified date="2005-12-26-09:40" comment="Removed test to check kb867282.">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </modified>
        <status_change date="2006-01-12-08:59">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 5.01, 5.5, and 6 allows remote attackers to spoof a less restrictive security zone and execute arbitrary code via an HTML page containing URLs that contain hostnames that have been double hex encoded, which are decoded twice to generate a malicious hostname, aka the "URL Decoding Zone Spoofing Vulnerability."</description>
      <reference source="CVE">CVE-2005-0054</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-200" comment="Internet Explorer 6.0 Installed XP SP2" negate="false"/>
          <criterion test_ref="wft-500" comment="the version of mshtml.dll is less than 6.0.2900.2604" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL3203" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Hyperlink Object Library</product>
      </affected>
      <dates>
        <submitted date="2005-02-10-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2005-02-11-09:34">DRAFT</status_change>
        <status_change date="2005-03-02-09:01">INTERIM</status_change>
        <status_change date="2005-03-23-08:09">ACCEPTED</status_change>
      </dates>
      <description>The Hyperlink Object Library for Windows 98, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary code via a crafted link that triggers an "unchecked buffer" in the library, possibly due to a buffer overflow.</description>
      <reference source="CVE">CVE-2005-0057</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="cmp-177" comment="a vulnerable version of hlink.dll exists on Server 2003" negate="false"/>
          <criterion test_ref="wrt-78" comment="the patch kb888113 is installed (Hotfix key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL3216" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Windows Animated Cursor</product>
      </affected>
      <dates>
        <submitted date="2005-01-14-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2005-01-20-12:00">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-12:00">ACCEPTED</status_change>
        <modified date="2005-06-17-12:00" comment="modified cmp-1106 - Replaced the test that checks for the service pack level, instead of checking for sp4 or ealier (did not check for GOLD edition) it is now negating the test that checks for sp5 for later.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <status_change date="2005-06-22-12:35">INTERIM</status_change>
        <status_change date="2005-07-27-10:37">ACCEPTED</status_change>
      </dates>
      <description>The Windows Animated Cursor (ANI) capability in Windows NT, Windows 2000 through SP4, Windows XP through SP1, and Windows 2003 allow remote attackers to cause a denial of service via (1) the frame number set to zero, which causes an invalid memory address to be used and leads to a kernel crash, or (2) the rate number set to zero, which leads to resource exhaustion and hang.</description>
      <reference source="CVE">CVE-2004-1305</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1106" comment="Windows 2000 (sp4 or earlier) is installed" negate="false"/>
          <criterion test_ref="wft-353" comment="the version of user32.dll is less than 5.0.2195.7017" negate="false"/>
          <criterion test_ref="wrt-68" comment="the patch kb891711 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL3220" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Cursor and Icon Formatting</product>
      </affected>
      <dates>
        <submitted date="2005-01-14-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2005-01-20-02:31">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Integer overflow in the LoadImage API of the USER32 Lib for Microsoft Windows allows remote attackers to execute arbitrary code via a .bmp, .cur, .ico or .ani file with a large image size field, which leads to a buffer overflow, aka the "Cursor and Icon Format Handling Vulnerability."</description>
      <reference source="CVE">CVE-2004-1049</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wft-355" comment="the version of user32.dll is less than 5.2.3790.245" negate="false"/>
          <criterion test_ref="wrt-68" comment="the patch kb891711 is installed" negate="true"/>
          <criterion test_ref="cmp-62" comment="Windows Server 2003 or Windows Server 2003 64-bit Edition is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL3242" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>NetDDE</product>
      </affected>
      <dates>
        <submitted date="2004-10-15-08:03">
          <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
        </submitted>
        <status_change date="2004-10-20-02:35">DRAFT</status_change>
        <status_change date="2004-11-03-12:00">INTERIM</status_change>
        <status_change date="2004-12-09-08:46">ACCEPTED</status_change>
      </dates>
      <description>Network Dynamic Data Exchange (NetDDE) services for Microsoft Windows 98, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows attackers to remotely execute arbitrary code or locally gain privileges via a malicious message or application that involves an "unchecked buffer," possibly a buffer overflow.</description>
      <reference source="CVE">CVE-2004-0206</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-2" comment="Windows XP is installed" negate="false"/>
          <criterion test_ref="wrt-70" comment="64-Bit version of Windows is installed" negate="false"/>
          <criterion test_ref="wrt-29" comment="Win2K/XP/2003 service pack 2 (or later) is installed" negate="true"/>
          <criterion test_ref="cmp-1152" comment="a vulnerable version of netdde.exe exists" negate="false"/>
          <criterion test_ref="cmp-1151" comment="a vulnerable version of nddenb32.dll exists" negate="false"/>
          <criterion test_ref="wrt-551" comment="the patch KB841533 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL3250" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>mozilla</product>
      </affected>
      <dates>
        <submitted date="2005-01-19-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-24-03:40">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Heap-based buffer overflow in the SendUidl in the POP3 capability for Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, may allow remote POP3 mail servers to execute arbitrary code.</description>
      <reference source="CVE">CVE-2004-0757</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" negate="false"/>
          <criterion test_ref="cmp-72" comment="Mozilla components (any SUNWmoznav/SUNWmozmail) installed" negate="false"/>
          <criterion test_ref="spt-46" comment="Patch 117765-02 or later installed" negate="true"/>
          <criterion test_ref="spt-47" comment="Patch 117767-02 or later installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL3310" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>Microsoft Word for Windows 6.0 Converter</product>
      </affected>
      <dates>
        <submitted date="2005-01-05-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2005-01-06-09:32">DRAFT</status_change>
        <status_change date="2005-02-02-12:00">INTERIM</status_change>
        <status_change date="2005-02-23-09:25">ACCEPTED</status_change>
        <modified date="2005-12-20-07:05" comment="Edited criteria. 1) dropped explicit check for Hotfix kb885836, 2) check version of wordpad.exe rather than mswrd wpc files.">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </modified>
        <status_change date="2006-01-04-08:04">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Word for Windows 6.0 Converter (MSWRD632.WPC), as used in WordPad, does not properly validate certain data lengths, which allows remote attackers to execute arbitrary code via a .wri, .rtf, and .doc file sent by email or malicious web site, aka "Font Conversion Vulnerability," a different vulnerability than CVE-2004-0571.</description>
      <reference source="CVE">CVE-2004-0901</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-44" comment="Windows NT Server 4.0 is installed" negate="false"/>
          <criterion test_ref="wft-710" comment="the version of wordpad.exe is less than 4.0.1381.7312" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL3311" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Microsoft Office 2003</product>
      </affected>
      <dates>
        <submitted date="2004-09-23-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2004-09-29-12:00">DRAFT</status_change>
        <status_change date="2004-10-13-12:00">INTERIM</status_change>
        <status_change date="2004-10-27-12:00">ACCEPTED</status_change>
        <modified date="2005-02-10-12:00" comment="modified wft-489 - corrected registry path check for .dll file">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <status_change date="2005-02-11-12:00">INTERIM</status_change>
        <status_change date="2005-03-02-12:00">ACCEPTED</status_change>
        <modified date="2005-04-08-12:00" comment="modified wrt-516 - wrt-516 corrected literal string">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <status_change date="2005-04-11-08:48">INTERIM</status_change>
        <status_change date="2005-04-27-12:07">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the converter for Microsoft WordPerfect 5.x on Office 2000, Office XP, Office 2003, and Works Suites 2001 through 2004 allows remote attackers to execute arbitrary code via a malicious document or website.</description>
      <reference source="CVE">CVE-2004-0573</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-515" comment="Microsoft Office 2003 is installed" negate="false"/>
          <criterion test_ref="wft-489" comment="the version of msconv97.dll is less than 2003.1100.6252.0 " negate="false"/>
          <criterion test_ref="wrt-516" comment="Patch KB873378 is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL3312" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Local Security Authority Subsystem Service (LSASS)</product>
      </affected>
      <dates>
        <submitted date="2005-01-05-12:00">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </submitted>
        <status_change date="2005-01-12-12:41">DRAFT</status_change>
        <status_change date="2005-02-02-12:00">INTERIM</status_change>
        <status_change date="2005-02-23-09:25">ACCEPTED</status_change>
      </dates>
      <description>LSASS (Local Security Authority Subsystem Service) of Windows 2000 Server and Windows Server 2003 does not properly validate connection information, which allows local users to gain privileges via a specially-designed program.</description>
      <reference source="CVE">CVE-2004-0894</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-38" comment="Windows Server 2003 or Windows XP 64-Bit Edition Version 2003" negate="false"/>
          <criterion test_ref="wft-160" comment="the version of lsasrv.dll is less than 5.2.3790.220" negate="false"/>
          <criterion test_ref="wrt-36" comment="the patch kb885835is installed (Hotfix key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL3318" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Microsoft Internet Explorer 6 Service Pack 1</product>
      </affected>
      <dates>
        <submitted date="2005-03-17-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2005-03-23-08:09">DRAFT</status_change>
        <status_change date="2005-04-13-12:15">INTERIM</status_change>
        <status_change date="2005-05-04-12:33">ACCEPTED</status_change>
        <modified date="2005-12-26-09:40" comment="Removed test to check kb867282.">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </modified>
        <status_change date="2006-01-12-08:59">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 5.01, 5.5, and 6 does not properly validate certain URLs in Channel Definition Format (CDF) files, which allows remote attackers to obtain sensitive information or execute arbitrary code, aka the "Channel Definition Format (CDF) Cross Domain Vulnerability."</description>
      <reference source="CVE">CVE-2005-0056</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-50" comment="Internet Explorer 6 Service Pack 1 is installed" negate="false"/>
          <criterion test_ref="cmp-257" comment="a vulnerable version of mshtml.dll exisits GDR/QFE" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL3320" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Microsoft Visio Professional 2003</product>
      </affected>
      <dates>
        <submitted date="2004-09-27-12:00">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </submitted>
        <status_change date="2004-09-29-12:00">DRAFT</status_change>
        <modified date="2004-09-30-12:00" comment="Changed affected platforms">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <status_change date="2004-10-20-12:00">INTERIM</status_change>
        <status_change date="2004-11-03-12:00">ACCEPTED</status_change>
        <modified date="2005-02-10-12:00" comment="modified wft-495 - corrected registry path check for .dll file">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <status_change date="2005-02-11-09:31">INTERIM</status_change>
        <status_change date="2005-03-02-09:01">ACCEPTED</status_change>
        <modified date="2005-12-26-09:40" comment="Changed criteria to remove test for KB838345.">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </modified>
        <status_change date="2006-01-12-08:59">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length before a memory copy operation.</description>
      <reference source="CVE">CVE-2004-0200</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-527" comment="Visio Professional 2003 is Installed" negate="false"/>
          <criterion test_ref="wft-495" comment="the version of gdiplus.dll is less than 6.0.3264.0" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL3322" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Kerberos5</product>
      </affected>
      <dates>
        <submitted date="2004-10-12-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2004-10-13-12:00">DRAFT</status_change>
        <modified date="2005-01-14-12:00" comment="Changed kerberos unknown test to solaris file contents test">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </modified>
        <status_change date="2005-02-02-12:00">INTERIM</status_change>
        <status_change date="2005-02-23-09:25">ACCEPTED</status_change>
      </dates>
      <description>Double-free vulnerability in the krb5_rd_cred function for MIT Kerberos 5 (krb5) 1.3.1 and earlier may allow local users to execute arbitrary code.</description>
      <reference source="CVE">CVE-2004-0643</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-6" comment="Solaris 9 Installed" negate="false"/>
          <criterion test_ref="uft-25" comment="Kerberos 5 installed" negate="false"/>
          <criterion test_ref="spt-250" comment="Patch 112908-15 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="tft-5" comment="/etc/krb5/krb5.conf is configured with a kerberos domain" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL3325" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Local Security Authority Subsystem Service (LSASS)</product>
      </affected>
      <dates>
        <submitted date="2004-12-28-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2005-01-12-12:41">DRAFT</status_change>
        <status_change date="2005-02-02-12:00">INTERIM</status_change>
        <status_change date="2005-02-23-09:25">ACCEPTED</status_change>
      </dates>
      <description>LSASS (Local Security Authority Subsystem Service) of Windows 2000 Server and Windows Server 2003 does not properly validate connection information, which allows local users to gain privileges via a specially-designed program.</description>
      <reference source="CVE">CVE-2004-0894</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1058" comment="Windows XP 32-bit edition is installed" negate="false"/>
          <criterion test_ref="wrt-4" comment="Win2K/XP/2003 service pack 1 is installed" negate="false"/>
          <criterion test_ref="wft-349" comment="the version of lsasrv.dll is less than 5.1.2600.1597" negate="false"/>
          <criterion test_ref="wrt-36" comment="the patch kb885835is installed (Hotfix key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL3333" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Microsoft Office XP SP3</product>
      </affected>
      <dates>
        <submitted date="2004-09-22-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2004-09-23-12:00">DRAFT</status_change>
        <status_change date="2004-10-06-12:00">INTERIM</status_change>
        <status_change date="2004-10-20-12:00">ACCEPTED</status_change>
        <modified date="2005-02-10-12:00" comment="modified wft-489 - corrected registry path check for .dll file">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <status_change date="2005-02-11-09:31">INTERIM</status_change>
        <status_change date="2005-03-02-09:01">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the converter for Microsoft WordPerfect 5.x on Office 2000, Office XP, Office 2003, and Works Suites 2001 through 2004 allows remote attackers to execute arbitrary code via a malicious document or website.</description>
      <reference source="CVE">CVE-2004-0573</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-199" comment="Microsoft Office XP Service Pack 3 is installed" negate="false"/>
          <criterion test_ref="wft-489" comment="the version of msconv97.dll is less than 2003.1100.6252.0 " negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL3355" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>Cursor and Icon Formatting</product>
      </affected>
      <dates>
        <submitted date="2005-01-14-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2005-01-20-02:31">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Integer overflow in the LoadImage API of the USER32 Lib for Microsoft Windows allows remote attackers to execute arbitrary code via a .bmp, .cur, .ico or .ani file with a large image size field, which leads to a buffer overflow, aka the "Cursor and Icon Format Handling Vulnerability."</description>
      <reference source="CVE">CVE-2004-1049</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-44" comment="Windows NT Server 4.0 is installed" negate="false"/>
          <criterion test_ref="wft-351" comment="the version of user32.dll is less than 4.0.1381.7342" negate="false"/>
          <criterion test_ref="wrt-68" comment="the patch kb891711 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL3372" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Internet Explorer 6 Service Pack 1 for Windows Server 2003</product>
      </affected>
      <dates>
        <submitted date="2004-10-19-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2004-10-20-12:00">DRAFT</status_change>
        <status_change date="2004-11-03-12:00">INTERIM</status_change>
        <status_change date="2004-12-09-12:00">ACCEPTED</status_change>
        <modified date="2005-05-10-12:00" comment="modified wrt-51 - Comment updated to indicate IE 6.">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </modified>
        <status_change date="2005-05-11-05:33">INTERIM</status_change>
        <status_change date="2005-06-01-03:30">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 6.0 SP1 and earlier, and possibly other versions, allows remote attackers to cause a denial of service (application crash from "memory corruption") via certain malformed Cascading Style Sheet (CSS) elements that trigger heap-based buffer overflows, as demonstrated using the "&lt;STYLE>@;/*" string, possibly due to a missing comment terminator that may cause an invalid length to trigger a large memory copy operation, aka the "CSS Heap Memory Corruption Vulnerability."</description>
      <reference source="CVE">CVE-2004-0842</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-51" comment="Internet Explorer 6  for Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wft-558" comment="the version of mshtml.dll is less than 6.0.3790.219" negate="false"/>
          <criterion test_ref="wrt-557" comment="the patch kb834707 is installed (Hotfix key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL3376" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Microsoft Outlook Express</product>
      </affected>
      <dates>
        <submitted date="2004-08-26-08:07">
          <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
        </submitted>
        <status_change date="2004-08-26-08:14">DRAFT</status_change>
        <status_change date="2004-09-09-12:00">INTERIM</status_change>
        <modified date="2004-09-13-11:40" comment="cmp-66 added">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2004-09-29-12:00">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Outlook Express 5.5 and 6 allows attackers to cause a denial of service (application crash) via a malformed e-mail header.</description>
      <reference source="CVE">CVE-2004-0215</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-171" comment="Outlook Express 6 is installed" negate="false"/>
          <criterion test_ref="wft-461" comment="the version of inetcomm.dll is less than 6.0.2742.200" negate="false"/>
          <criterion test_ref="wrt-494" comment="the patch kb823353 is installed " negate="true"/>
          <criterion test_ref="cmp-66" comment="Windows XP (sp1 or earlier) is installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-495" comment="all users have the preview pane disabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL3386" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2004-10-04-01:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2004-10-06-12:57">DRAFT</status_change>
        <status_change date="2004-10-20-12:00">INTERIM</status_change>
        <status_change date="2004-11-03-12:00">ACCEPTED</status_change>
        <modified date="2005-12-20-07:05" comment="Changed criteria to drop explicit test for patch kb839645.  Inclusion resulted in false positives w/o incremental patching.">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </modified>
        <status_change date="2006-01-04-08:04">ACCEPTED</status_change>
      </dates>
      <description>The Windows Shell application in Windows 98, Windows ME, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code by spoofing the type of a file via a CLSID specifier in the filename, as demonstrated using Internet Explorer 6.0.2800.1106 on Windows XP.</description>
      <reference source="CVE">CVE-2004-0420</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
          <criterion test_ref="wft-447" comment="the version of shell32.dll is less than 5.0.3900.6922" negate="false"/>
          <criterion test_ref="wrt-29" comment="Win2K/XP/2003 service pack 2 (or later) is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL3391" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>SMB (Server Message Block)</product>
      </affected>
      <dates>
        <submitted date="2004-07-19-12:00">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </submitted>
        <status_change date="2004-08-04-12:00">INTERIM</status_change>
        <status_change date="2004-08-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the SMB capability for Microsoft Windows XP, 2000, and NT allows remote attackers to cause a denial of service and possibly execute arbitrary code via an SMB packet that specifies a smaller buffer length than is required.</description>
      <reference source="CVE">CVE-2003-0345</reference>
      <status>ACCEPTED</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-2" comment="Windows XP is installed" negate="false"/>
          <criterion test_ref="wrt-277" comment="Patch Windows2000-KB817606-x86-ENU.exe Installed" negate="true"/>
          <criterion test_ref="cmp-1094" comment="XP SP1 or pre SP1 with version check on Srv.sys" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL3400" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Licence Logging Service</product>
      </affected>
      <dates>
        <submitted date="2005-04-13-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-04-20-12:13">DRAFT</status_change>
        <status_change date="2005-05-11-05:41">INTERIM</status_change>
        <status_change date="2005-06-01-03:30">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the ping daemon of Sun Solaris 7 through 9 may allow local users to execute arbitrary code.</description>
      <reference source="CVE">CVE-2004-1352</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-96" comment="Solaris 7 or 8 OR Solaris 9 and Solaris Basic IP Commands (SUNWbip) installed" negate="false"/>
          <criterion test_ref="spt-71" comment="Patch 118313-01 or later installed" negate="true"/>
          <criterion test_ref="spt-72" comment="Patch 116986-02 or later installed" negate="true"/>
          <criterion test_ref="spt-73" comment="Patch 116774-03 or later installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL3416" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Word for Windows 6.0 Converter</product>
      </affected>
      <dates>
        <submitted date="2005-01-05-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2005-01-12-12:00">DRAFT</status_change>
        <status_change date="2005-02-02-12:00">INTERIM</status_change>
        <status_change date="2005-02-23-12:00">ACCEPTED</status_change>
        <modified date="2005-06-17-12:00" comment="modified cmp-1106 - Replaced the test that checks for the service pack level, instead of checking for sp4 or ealier (did not check for GOLD edition) it is now negating the test that checks for sp5 for later.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <status_change date="2005-06-22-12:35">INTERIM</status_change>
        <status_change date="2005-07-27-10:37">ACCEPTED</status_change>
        <modified date="2005-12-20-07:05" comment="Replaced all criteria. 1) Included all Win2k versions, 2) dropped explicit check for Hotfix kb885836, 3) check version of wordpad.exe rather than mswrd wpc files.">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </modified>
        <status_change date="2006-01-04-08:04">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Word for Windows 6.0 Converter does not properly validate certain data lengths, which allows remote attackers to execute arbitrary code via a .wri, .rtf, and .doc file sent by email or malicious web site, aka "Table Conversion Vulnerability," a different vulnerability than CVE-2004-0901.</description>
      <reference source="CVE">CVE-2004-0571</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
          <criterion test_ref="wft-712" comment="the version of wordpad.exe is less than 5.0.2195.6991" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL3428" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Task Scheduler</product>
      </affected>
      <dates>
        <submitted date="2004-07-14-12:00">
          <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
        </submitted>
        <status_change date="2004-08-04-12:00">INTERIM</status_change>
        <status_change date="2004-08-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Stack-based buffer overflow in the Task Scheduler for Windows 2000 and XP, and Internet Explorer 6 on Windows NT 4.0, allows local or remote attackers to execute arbitrary code via a .job file containing long parameters, as demonstrated using Internet Explorer and accessing a .job file on an anonymous share.</description>
      <reference source="CVE">CVE-2004-0212</reference>
      <status>ACCEPTED</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
          <criterion test_ref="wft-445" comment="the version of mstask.dll is less than 4.71.2195.6920" negate="false"/>
          <criterion test_ref="wrt-483" comment="Patch Windows2000-kb841873-x86-enu.exe Installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL3456" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Windows Shell</product>
      </affected>
      <dates>
        <submitted date="2005-05-04-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2005-05-04-12:32">DRAFT</status_change>
        <status_change date="2005-06-01-03:30">INTERIM</status_change>
        <status_change date="2005-06-22-12:38">ACCEPTED</status_change>
      </dates>
      <description>The document processing application used by the Windows Shell in Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code by modifying the CLSID stored in a file so that it is processed by HTML Application Host (MSHTA), as demonstrated using a Microsoft Word document.</description>
      <reference source="CVE">CVE-2005-0063</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-57" comment="Windows XP 32-bit SP1 is installed" negate="false"/>
          <criterion test_ref="wft-590" comment="the version of shell32.dll is less than 6.0.2800.1643" negate="false"/>
          <criterion test_ref="wrt-434" comment="the patch  KB893086 is installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-280" comment=".hta applications are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL3458" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Windows 2000</product>
      </affected>
      <dates>
        <submitted date="2005-04-22-12:00">
          <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
        </submitted>
        <status_change date="2005-04-27-12:06">DRAFT</status_change>
        <status_change date="2005-06-01-03:30">INTERIM</status_change>
        <status_change date="2005-06-22-12:38">ACCEPTED</status_change>
      </dates>
      <description>Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (reset TCP connections) via spoofed ICMP error messages, aka the "blind connection-reset attack."  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</description>
      <reference source="CVE">CVE-2004-0790</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
          <criterion test_ref="wrt-538" comment="Win2K/XP/2003 service pack 4 (or earlier) is installed" negate="false"/>
          <criterion test_ref="wft-593" comment="the version of Tcpip.sys is less than 5.0.2195.7035" negate="false"/>
          <criterion test_ref="wrt-443" comment="the patch KB893066 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL3460" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>SMTP</product>
      </affected>
      <dates>
        <submitted date="2004-10-13-10:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2004-10-13-01:15">DRAFT</status_change>
        <status_change date="2004-10-27-12:00">INTERIM</status_change>
        <status_change date="2004-11-17-10:00">ACCEPTED</status_change>
      </dates>
      <description>The SMTP (Simple Mail Transfer Protocol) component of Microsoft Windows XP 64-bit Edition, Windows Server 2003, Windows Server 2003 64-bit Edition, and the Exchange Routing Engine component of Exchange Server 2003, allows remote attackers to execute arbitrary code via a malicious DNS response message containing length values that are not properly validated.</description>
      <reference source="CVE">CVE-2004-0840</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wrt-70" comment="64-Bit version of Windows is installed" negate="false"/>
          <criterion test_ref="wft-502" comment="The version of smtpsvc.dll is less than 6.0.3790.211" negate="false"/>
          <criterion test_ref="wrt-544" comment="the patch WindowsServer2003-KB885881-ia64-enu.exe is installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-240" comment="SMTP Enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL3464" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Internet Explorer 6.0</product>
      </affected>
      <dates>
        <submitted date="2005-02-10-12:00">
          <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
        </submitted>
        <status_change date="2005-02-11-12:00">DRAFT</status_change>
        <status_change date="2005-03-02-12:00">INTERIM</status_change>
        <status_change date="2005-03-23-12:00">ACCEPTED</status_change>
        <modified date="2005-06-02-12:00" comment="Added product">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-06-08-03:17">INTERIM</status_change>
        <status_change date="2005-06-29-06:49">ACCEPTED</status_change>
      </dates>
      <description>The DHTML Edit Control (dhtmled.ocx) allows remote attackers to inject arbitrary web script into other domains by setting a name for a window, opening a child page whose target is the window with the given name, then injecting the script from the parent into the child using execScript, as demonstrated by "AbusiveParent" in Internet Explorer 6.0.2900.2180.</description>
      <reference source="CVE">CVE-2004-1319</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-180" comment="Windows XP 32-bit edition is installed  with service pack 2 (or earlier)" negate="false"/>
          <criterion test_ref="wft-375" comment="the version of dhtmled.ocx is less than 6.1.0.9232" negate="false"/>
          <criterion test_ref="wrt-87" comment="the patch kb891781 is installed (Hotfix key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL3465" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Solaris Volume Manager (SVM)</product>
      </affected>
      <dates>
        <submitted date="2005-01-19-05:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-24-05:00">DRAFT</status_change>
        <status_change date="2005-02-16-05:00">INTERIM</status_change>
        <status_change date="2005-03-09-05:00">ACCEPTED</status_change>
        <status_change date="2005-08-25-10:03">INTERIM</status_change>
        <status_change date="2005-08-25-10:05">DRAFT</status_change>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>The Sun Solaris Volume Manager (SVM) on Solaris 9 allows local users to cause a denial of service (kernel panic) via a malformed probe request to the SVM.</description>
      <reference source="CVE">CVE-2004-1346</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-6" comment="Solaris 9 Installed" negate="false"/>
          <criterion test_ref="spt-241" comment="Patch 113073-13 or later installed" negate="true"/>
          <criterion test_ref="sat-4" comment="Solaris Volume Manager package installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uft-24" comment="svm.init init script exists" negate="false"/>
          <criterion test_ref="tft-9" comment="/etc/vfstab is configured with SVM devices" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL3483" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>NetBT Name Service</product>
      </affected>
      <dates>
        <submitted date="2004-07-01-12:00">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </submitted>
        <modified date="2004-07-19-12:00" comment="Modifed without comment">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <modified date="2004-07-20-12:00" comment="Modifed without comment">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <status_change date="2004-08-04-12:00">INTERIM</status_change>
        <status_change date="2004-08-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>The NetBT Name Service (NBNS) for NetBIOS in Windows NT 4.0, 2000, XP, and Server 2003 may include random memory in a response to a NBNS query, which could allow remote attackers to obtain sensitive information.</description>
      <reference source="CVE">CVE-2003-0661</reference>
      <status>ACCEPTED</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-2" comment="Windows XP is installed" negate="false"/>
          <criterion test_ref="cmp-1051" comment="Patch WindowsXP-KB824105-x86-ENU.exe installed on XP or XP SP1" negate="true"/>
          <criterion test_ref="cmp-1097" comment="XP SP1 or Pre SP1 with correct netbt.sys version" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL3496" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>HTML Help ActiveX Control</product>
      </affected>
      <dates>
        <submitted date="2005-03-30-12:00">
          <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
        </submitted>
        <status_change date="2005-04-12-08:26">DRAFT</status_change>
        <status_change date="2005-04-27-12:07">INTERIM</status_change>
        <status_change date="2005-06-01-03:30">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 6.0 on Windows XP SP2 allows remote attackers to execute arbitrary code by using the "Related Topics" command in the Help ActiveX Control (hhctrl.ocx) to open a Help popup window containing the PCHealth tools.htm file in the local zone and injecting Javascript to be executed, as demonstrated using "writehta.txt" and the ADODB recordset, which saves a .HTA file to the local system, aka the "HTML Help ActiveX control Cross Domain Vulnerability."</description>
      <reference source="CVE">CVE-2004-1043</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-44" comment="Windows NT Server 4.0 is installed" negate="false"/>
          <criterion test_ref="wft-390" comment="the version of hhctrl.ocx is less than 5.2.3790.233" negate="false"/>
          <criterion test_ref="wrt-184" comment="the patch Q890175 is installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL3505" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>sshd</product>
      </affected>
      <dates>
        <submitted date="2005-04-13-04:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-04-20-04:00">DRAFT</status_change>
        <status_change date="2005-05-11-04:00">INTERIM</status_change>
        <status_change date="2005-06-01-04:00">ACCEPTED</status_change>
        <status_change date="2005-08-25-10:03">INTERIM</status_change>
        <status_change date="2005-08-25-10:05">DRAFT</status_change>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>The Secure Shell (SSH) Daemon (SSHD) in Sun Solaris 9 does not properly log IP addresses when SSHD is configured with the ListenAddress as 0.0.0.0, which makes it easier for remote attackers to hide the source of their activities.</description>
      <reference source="CVE">CVE-2004-1357</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-6" comment="Solaris 9 Installed" negate="false"/>
          <criterion test_ref="sat-41" comment="Secure Shell Server - Usr (SUNWsshdu) installed" negate="false"/>
          <criterion test_ref="spt-83" comment="Patch 113273-05 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="tft-2" comment="/etc/ssh/sshd_config has 0.0.0.0 as ListenAddress" negate="false"/>
          <criterion test_ref="uct-16" comment="sshd running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL3508" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Windows XP</product>
      </affected>
      <dates>
        <submitted date="2005-08-18-04:00">
          <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
        </submitted>
        <status_change date="2005-08-25-10:05">DRAFT</status_change>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial of service (connection loss) to persistent TCP connections by repeatedly injecting a TCP RST packet, especially in protocols that use long-lived connections, such as BGP.</description>
      <reference source="CVE">CVE-2004-0230</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-2" comment="Windows XP is installed" negate="false"/>
          <criterion test_ref="cmp-23" comment="32-bit version of Windows or 64-bit (itanium architecture) version of Windows is installed" negate="false"/>
          <criterion test_ref="wrt-79" comment="Win2K/XP/2003 service pack 2 (or earlier) is installed" negate="false"/>
          <criterion test_ref="cmp-298" comment="A vulnerable version of tcpip.sys is installed." negate="false"/>
          <criterion test_ref="wrt-443" comment="the patch KB893066 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL3514" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>HTML Help Facility</product>
      </affected>
      <dates>
        <submitted date="2004-07-14-12:00">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <status_change date="2004-08-04-12:00">INTERIM</status_change>
        <status_change date="2004-08-25-12:00">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 5.x and 6.0 allows remote attackers to execute arbitrary programs via a modified directory traversal attack using a URL containing ".." (dot dot) sequences and a filename that ends in "::" which is treated as a .chm file even if it does not have a .chm extension.  NOTE: this bug may overlap CVE-2004-0475.</description>
      <reference source="CVE">CVE-2003-1041</reference>
      <status>ACCEPTED</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wft-444" comment="the version of itss.dll is less than 5.2.3790.185" negate="false"/>
          <criterion test_ref="wrt-482" comment="the patch kb840315 is installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-491" comment="HTML Help is registered" negate="true"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL3533" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2004-07-14-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2004-08-04-12:00">INTERIM</status_change>
        <status_change date="2004-08-25-12:00">ACCEPTED</status_change>
        <modified date="2005-12-20-07:05" comment="Changed criteria to drop explicit test for patch kb839645. Inclusion resulted in false positives w/o incremental patching.">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </modified>
        <status_change date="2006-01-04-08:04">ACCEPTED</status_change>
        <status_change date="2006-05-03-10:06">INTERIM</status_change>
      </dates>
      <description>The Windows Shell application in Windows 98, Windows ME, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code by spoofing the type of a file via a CLSID specifier in the filename, as demonstrated using Internet Explorer 6.0.2800.1106 on Windows XP.</description>
      <reference source="CVE">CVE-2004-0420</reference>
      <status>INTERIM</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-66" comment="Windows XP (sp1 or earlier) is installed" negate="false"/>
          <criterion test_ref="wrt-72" comment="32-Bit version of Windows is installed" negate="false"/>
          <criterion test_ref="wft-449" comment="the version of shell32.dll is less than 6.0.2600.151" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL3544" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Client Server Runtime System (CSRSS)</product>
      </affected>
      <dates>
        <submitted date="2005-05-02-12:00">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </submitted>
        <status_change date="2005-05-04-12:00">DRAFT</status_change>
        <status_change date="2005-06-01-12:00">INTERIM</status_change>
        <modified date="2005-06-02-12:00" comment="Added product">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-06-22-12:38">ACCEPTED</status_change>
      </dates>
      <description>Stack-based buffer overflow in WINSRV.DLL in the Client Server Runtime System (CSRSS) process of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via a specially-designed application that provides console window information with a long FaceName value.</description>
      <reference source="CVE">CVE-2005-0551</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-2" comment="Windows XP is installed" negate="false"/>
          <criterion test_ref="wrt-427" comment="the patch KB890859 is installed (Hotfix key)" negate="true"/>
          <criterion test_ref="cmp-328" comment="Windows No Service Pack or Service Pack 1 and Ntoskrnl.exe version less than 5.1.2600.1634" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL3556" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>MDAC 2.7</product>
      </affected>
      <dates>
        <submitted date="2005-03-31-12:00">
          <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
        </submitted>
        <status_change date="2005-04-12-08:26">DRAFT</status_change>
        <status_change date="2005-04-27-12:07">INTERIM</status_change>
        <status_change date="2005-06-01-03:30">ACCEPTED</status_change>
      </dates>
      <description>The Microsoft .NET forms authentication capability for ASP.NET allows remote attackers to bypass authentication for .aspx files in restricted directories via a request containing a (1) "\" (backslash) or (2) "%5C" (encoded backslash), aka "Path Validation Vulnerability."</description>
      <reference source="CVE">CVE-2004-0847</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-117" comment="Is the .NET Framework 1.1 installed" negate="false"/>
          <criterion test_ref="cmp-253" comment="A vulnerable version of .NET Framework v1.1 is installed." negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL3567" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Basic Security Module</product>
      </affected>
      <dates>
        <submitted date="2005-04-13-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-04-20-12:13">DRAFT</status_change>
        <status_change date="2005-05-11-05:41">INTERIM</status_change>
        <status_change date="2005-06-01-03:30">ACCEPTED</status_change>
      </dates>
      <description>The patches (1) 114332-08 and (2) 114929-06 for Sun Solaris 9 disable the auditing functionality of the Basic Security Module (BSM), which allows attackers to avoid having their activity logged.</description>
      <reference source="CVE">CVE-2004-1358</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-6" comment="Solaris 9 Installed" negate="false"/>
          <criterion test_ref="spt-84" comment="Patch 114332-08 installed" negate="false"/>
          <criterion test_ref="spt-85" comment="Patch 114332-10 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="tft-3" comment="/etc/system has BSM enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL3568" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>OLE</product>
      </affected>
      <dates>
        <submitted date="2005-02-15-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <modified date="2005-02-16-12:00" comment="Added registry check to include three platforms">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-02-18-10:39">DRAFT</status_change>
        <status_change date="2005-03-09-07:56">INTERIM</status_change>
        <status_change date="2005-03-29-07:59">ACCEPTED</status_change>
      </dates>
      <description>The OLE component in Windows 98, 2000, XP, and Server 2003, and Exchange Server 5.0 through 2003, does not properly validate the lengths of messages for certain OLE data, which allows remote attackers to execute arbitrary code, aka the "Input Validation Vulnerability."</description>
      <reference source="CVE">CVE-2005-0044</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wft-389" comment="the version of ole32.dll is less than 5.2.3790.250" negate="false"/>
          <criterion test_ref="wrt-91" comment="the patch KB873333 is installed" negate="true"/>
          <criterion test_ref="cmp-187" comment="Windows Server 2003 32-bit OR 64-bit OR Windows XP 64-bit Version 2003 is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL3573" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 95</windows:platform>
        <windows:platform>Microsoft Windows 98</windows:platform>
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>MDAC 2.1</product>
      </affected>
      <dates>
        <submitted date="2004-08-24-12:00">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </submitted>
        <status_change date="2004-08-25-12:00">DRAFT</status_change>
        <status_change date="2004-09-09-12:00">INTERIM</status_change>
        <status_change date="2004-09-29-12:00">ACCEPTED</status_change>
        <modified date="2005-02-28-12:00" comment="removed the test for windows NT and added a test for MDAC 2.1 since this definition is dependent on the MDAC version and not the platform">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <status_change date="2005-03-02-08:52">INTERIM</status_change>
        <status_change date="2005-03-23-08:09">ACCEPTED</status_change>
      </dates>
      <description>Heap-based buffer overflow in the Remote Data Services (RDS) component of Microsoft Data Access Components (MDAC) 2.1 through 2.6, and Internet Explorer 5.01 through 6.0, allows remote attackers to execute code via a malformed HTTP request to the Data Stub.</description>
      <reference source="CVE">CVE-2002-1142</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-183" comment="MDAC 2.1 is installed" negate="false"/>
          <criterion test_ref="wft-483" comment="the version of msadco.dll is less than 2.12.5118.0" negate="false"/>
          <criterion test_ref="wrt-503" comment="Patch Q329414 Installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL3577" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>DHCP</product>
      </affected>
      <dates>
        <submitted date="2005-01-27-12:00">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </submitted>
        <status_change date="2005-01-28-09:32">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>The DHCP Server service for Microsoft Windows NT 4.0 Server and Terminal Server Edition does not properly validate the length of certain messages, which allows remote attackers to execute arbitrary code via a malformed DHCP message, aka the "DHCP Request Vulnerability."</description>
      <reference source="CVE">CVE-2004-0900</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-44" comment="Windows NT Server 4.0 is installed" negate="false"/>
          <criterion test_ref="wft-156" comment="the version of Dhcpssvc.dll is less than 4.0.1381.7304" negate="false"/>
          <criterion test_ref="wrt-37" comment="the patch KB885249 is installed (Hotfix key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL3582" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>MDAC 2.8</product>
      </affected>
      <dates>
        <submitted date="2005-03-29-12:00">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </submitted>
        <status_change date="2005-03-29-11:25">DRAFT</status_change>
        <status_change date="2005-04-13-12:00">INTERIM</status_change>
        <status_change date="2005-05-04-12:00">ACCEPTED</status_change>
        <modified date="2005-06-02-12:00" comment="Corrected Windows Server 2003 test logic">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <status_change date="2005-06-08-03:17">INTERIM</status_change>
        <status_change date="2005-06-29-06:49">ACCEPTED</status_change>
      </dates>
      <description>The License Logging service for Windows NT Server, Windows 2000 Server, and Windows Server 2003 does not properly validate the length of messages, which leads to an "unchecked buffer" and allows remote attackers to cause a denial of service (crash) and possibly execute arbtirary code, aka the "License Logging Service Vulnerability."</description>
      <reference source="CVE">CVE-2005-0050</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wrt-96" comment="the patch kb885834 is installed (Hotfix key)" negate="true"/>
          <criterion test_ref="wft-395" comment="the version of Llssrv.exe is less than 5.2.3790.242" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-344" comment="license logging service is enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL3585" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Windows Explorer</product>
      </affected>
      <dates>
        <submitted date="2005-05-13-12:00">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </submitted>
        <status_change date="2005-06-01-12:00">DRAFT</status_change>
        <modified date="2005-06-17-12:00" comment="modified cmp-1106 - Replaced the test that checks for the service pack level, instead of checking for sp4 or ealier (did not check for GOLD edition) it is now negating the test that checks for sp5 for later.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <status_change date="2005-07-27-10:37">INTERIM</status_change>
        <status_change date="2005-08-18-07:37">ACCEPTED</status_change>
      </dates>
      <description>The Web View DLL (webvw.dll), as used in Windows Explorer on Windows 2000 systems, does not properly filter an apostrophe ("'") in the author name in a document, which allows attackers to execute arbitrary script via extra attributes when Web View constructs a mailto: link for the preview pane when the user selects the file.</description>
      <reference source="CVE">CVE-2005-1191</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1106" comment="Windows 2000 (sp4 or earlier) is installed" negate="false"/>
          <criterion test_ref="wft-613" comment="the version of webvw.dll is less than 5.0.3900.7036" negate="false"/>
          <criterion test_ref="wrt-608" comment="the patch KB894320 is installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-609" comment="Webview is  Enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL3586" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Internet Explorer 6 SP1</product>
      </affected>
      <dates>
        <submitted date="2005-03-17-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2005-03-23-08:09">DRAFT</status_change>
        <status_change date="2005-04-13-12:15">INTERIM</status_change>
        <status_change date="2005-05-04-12:33">ACCEPTED</status_change>
        <modified date="2005-12-26-09:40" comment="Removed test to check kb867282.">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </modified>
        <status_change date="2006-01-12-08:59">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 5.01, 5.5, and 6 allows remote attackers to spoof a less restrictive security zone and execute arbitrary code via an HTML page containing URLs that contain hostnames that have been double hex encoded, which are decoded twice to generate a malicious hostname, aka the "URL Decoding Zone Spoofing Vulnerability."</description>
      <reference source="CVE">CVE-2005-0054</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-50" comment="Internet Explorer 6 Service Pack 1 is installed" negate="false"/>
          <criterion test_ref="cmp-257" comment="a vulnerable version of mshtml.dll exisits GDR/QFE" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL3601" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>Solaris Runtime Linker</product>
      </affected>
      <dates>
        <submitted date="2004-12-29-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-12-12:41">DRAFT</status_change>
        <status_change date="2005-02-02-12:00">INTERIM</status_change>
        <status_change date="2005-02-23-09:25">ACCEPTED</status_change>
      </dates>
      <description>Stack-based buffer overflow in the runtime linker, ld.so.1, on Solaris 2.6 through 9 allows local users to gain root privileges via a long LD_PRELOAD environment variable.</description>
      <reference source="CVE">CVE-2003-0609</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" negate="false"/>
          <criterion test_ref="cmp-54" comment="Solaris 9 OR Patch 106950-14+ OR Patch 109147-07+ installed" negate="false"/>
          <criterion test_ref="spt-10" comment="Patch 106950-14 or later installed" negate="true"/>
          <criterion test_ref="spt-11" comment="Patch 109147-07 or later installed" negate="true"/>
          <criterion test_ref="spt-12" comment="Patch 112963-09 or later installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL3603" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>mozilla</product>
      </affected>
      <dates>
        <submitted date="2005-01-19-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-24-03:40">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, allow remote attackers to use certain redirect sequences to spoof the security lock icon that makes a web page appear to be encrypted.</description>
      <reference source="CVE">CVE-2004-0761</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" negate="false"/>
          <criterion test_ref="cmp-72" comment="Mozilla components (any SUNWmoznav/SUNWmozmail) installed" negate="false"/>
          <criterion test_ref="spt-46" comment="Patch 117765-02 or later installed" negate="true"/>
          <criterion test_ref="spt-47" comment="Patch 117767-02 or later installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL3604" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>Internet Explorer 6</product>
      </affected>
      <dates>
        <submitted date="2004-10-04-01:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2004-10-06-12:57">DRAFT</status_change>
        <status_change date="2004-10-20-12:00">INTERIM</status_change>
        <status_change date="2004-11-03-12:00">ACCEPTED</status_change>
        <modified date="2005-12-20-07:05" comment="Changed criteria to drop explicit test for patch kb839645.  Inclusion resulted in false positives w/o incremental patching.">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </modified>
        <status_change date="2006-01-04-08:04">ACCEPTED</status_change>
      </dates>
      <description>The Windows Shell application in Windows 98, Windows ME, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code by spoofing the type of a file via a CLSID specifier in the filename, as demonstrated using Internet Explorer 6.0.2800.1106 on Windows XP.</description>
      <reference source="CVE">CVE-2004-0420</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1067" comment="Windows NT 4.0 with Active Desktop Installed" negate="false"/>
          <criterion test_ref="wft-452" comment="the version of shell32.dll is less than 4.72.3841.1100" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL3606" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Sendmail</product>
      </affected>
      <dates>
        <submitted date="2004-10-12-12:26">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2004-10-13-01:15">DRAFT</status_change>
      </dates>
      <description>A "potential buffer overflow in ruleset parsing" for Sendmail 8.12.9, when using the nonstandard rulesets (1) recipient (2), final, or (3) mailer-specific envelope recipients, has unknown consequences.</description>
      <reference source="CVE">CVE-2003-0681</reference>
      <status>DRAFT</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="sat-3" comment="Sendmail - root (SUNWsndmr) installed" negate="false"/>
          <criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" negate="false"/>
          <criterion test_ref="spt-238" comment="Patch 107684-11 or later installed" negate="true"/>
          <criterion test_ref="spt-239" comment="Patch 110615-11 or later installed" negate="true"/>
          <criterion test_ref="spt-240" comment="Patch 113575-05 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-11" comment="Sendmail running" negate="false"/>
          <criterion test_ref="ukn-36" comment="Sendmail has recipient or final rulesets" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL3637" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>priocntl()</product>
      </affected>
      <dates>
        <submitted date="2005-02-01-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-02-01-08:41">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Directory traversal vulnerability in priocntl system call in Solaris does allows local users to execute arbitrary code via ".." sequences in the pc_clname field of a pcinfo_t structure, which cause priocntl to load a malicious kernel module.</description>
      <reference source="CVE">CVE-2002-1296</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" negate="false"/>
          <criterion test_ref="spt-33" comment="Patch 106541-24 or later installed" negate="true"/>
          <criterion test_ref="spt-113" comment="Patch 108528-18 or later installed" negate="true"/>
          <criterion test_ref="spt-114" comment="Patch 112233-04 or later installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL3657" class="vulnerability">
      <affected family="redhat">
        <redhat:platform>Red Hat Enterprise Linux 3</redhat:platform>
        <product>libpng</product>
      </affected>
      <dates>
        <submitted date="2004-09-03-04:26">
          <contributor organization="The MITRE Corporation">Jay Beale</contributor>
        </submitted>
        <status_change date="2004-09-08-10:41">DRAFT</status_change>
        <status_change date="2004-09-22-12:00">INTERIM</status_change>
        <status_change date="2004-10-06-12:00">ACCEPTED</status_change>
      </dates>
      <description>Portable Network Graphics (PNG) library libpng 1.2.5 and earlier does not correctly calculate offsets, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a buffer overflow attack on the row buffers.</description>
      <reference source="CVE">CVE-2002-1363</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="rrt-206" comment="Red Hat Enterprise 3 is installed" negate="false"/>
          <criterion test_ref="cmp-1101" comment="libpng or libpng-devel rpm older than 1.2.2-24, Epoch 2 OR libpng10or libpng10-devel rpm older than 1.0.13-14, Epoch 0" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL3677" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Windows Internet Naming Service (WINS)</product>
      </affected>
      <dates>
        <submitted date="2005-01-03-12:00">
          <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
        </submitted>
        <status_change date="2005-01-12-12:41">DRAFT</status_change>
        <status_change date="2005-02-02-12:00">INTERIM</status_change>
        <status_change date="2005-02-23-09:25">ACCEPTED</status_change>
      </dates>
      <description>The WINS service (wins.exe) on Microsoft Windows NT Server 4.0, Windows 2000 Server, and Windows Server 2003 allows remote attackers to write to arbitrary memory locations and possibly execute arbitrary code via a modified memory pointer in a WINS replication packet to TCP port 42, aka the "Association Context Vulnerability."</description>
      <reference source="CVE">CVE-2004-1080</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-193" comment="Windows Server 2003 (excluding WinXP 64-bit, Version 2003) is installed" negate="false"/>
          <criterion test_ref="wft-350" comment="the version of wins.exe is less than 5.2.3790.239" negate="false"/>
          <criterion test_ref="wrt-38" comment="the patch KB870763 is installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-98" comment="the wins service is enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL3685" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Help and Support Center (HSC)</product>
      </affected>
      <dates>
        <submitted date="2005-01-18-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2005-01-20-02:31">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Stack-based buffer overflow in the PCHealth system in the Help and Support Center function in Windows XP and Windows Server 2003 allows remote attackers to execute arbitrary code via a long query in an HCP URL.</description>
      <reference source="CVE">CVE-2003-0711</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1112" comment="Windows XP 64-bit" negate="false"/>
          <criterion test_ref="wrt-308" comment="Patch KB825119 Installed" negate="true"/>
          <criterion test_ref="wft-261" comment="the version of itircl.dll is less than 5.2.3790.80" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-309" comment="HCP Protocol" negate="true"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL3743" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Word for Windows 6.0 Converter</product>
      </affected>
      <dates>
        <submitted date="2005-01-05-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2005-01-12-12:41">DRAFT</status_change>
        <status_change date="2005-02-02-12:00">INTERIM</status_change>
        <status_change date="2005-02-23-09:25">ACCEPTED</status_change>
        <modified date="2005-12-20-07:05" comment="Replaced all criteria. 1) Included all S03 versions, 2) dropped explicit check for Hotfix kb885836, 3) check version of wordpad.exe rather than mswrd wpc files.">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </modified>
        <status_change date="2006-01-04-08:04">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Word for Windows 6.0 Converter does not properly validate certain data lengths, which allows remote attackers to execute arbitrary code via a .wri, .rtf, and .doc file sent by email or malicious web site, aka "Table Conversion Vulnerability," a different vulnerability than CVE-2004-0901.</description>
      <reference source="CVE">CVE-2004-0571</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wft-713" comment="the version of wordpad.exe is less than 5.2.3790.224" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL3752" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Microsoft Internet Explorer 6 Service Pack 1</product>
      </affected>
      <dates>
        <submitted date="2005-05-10-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2005-05-11-05:38">DRAFT</status_change>
        <status_change date="2005-06-01-03:30">INTERIM</status_change>
        <status_change date="2005-06-22-12:38">ACCEPTED</status_change>
      </dates>
      <description>Race condition in the memory management routines in the DHTML object processor in Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a malicious web page or HTML e-mail, aka "DHTML Object Memory Corruption Vulnerability".</description>
      <reference source="CVE">CVE-2005-0553</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-50" comment="Internet Explorer 6 Service Pack 1 is installed" negate="false"/>
          <criterion test_ref="cmp-292" comment="a vulnerable version of mshtml.dll exisits GDR/QFE" negate="false"/>
          <criterion test_ref="wrt-440" comment="the patch kb890923  is installed (XP Win2K Hotfix key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL3768" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows ME</windows:platform>
        <product>Program Group Converter</product>
      </affected>
      <dates>
        <submitted date="2004-10-14-03:38">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <status_change date="2004-10-20-02:35">DRAFT</status_change>
        <status_change date="2004-11-03-12:00">INTERIM</status_change>
        <status_change date="2004-12-09-08:46">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the Windows Program Group Converter (grpconv.exe) may allow remote attackers to execute arbitrary code via a shell: URL with a long filename and a .grp extension, which is not properly handled when the shell capability launches grpconv.exe.</description>
      <reference source="CVE">CVE-2004-0572</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-550" comment="Windows ME Installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL3773" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows ME</windows:platform>
        <product>Internet Explorer 5.5 Service Pack 2</product>
      </affected>
      <dates>
        <submitted date="2005-01-18-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2005-01-20-02:31">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
        <modified date="2005-09-26-12:42" comment="modified wft-562 - Changed comment to match test">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-28-01:04">INTERIM</status_change>
        <status_change date="2005-10-19-05:47">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer in Windows XP SP2, and other versions including 5.01 and 5.5, allows remote attackers to install arbitrary programs via a web page that uses certain styles and the AnchorClick behavior, popup windows, and drag-and-drop capabilities to drop the program in the local startup folder, as demonstrated by "wottapoop.html".</description>
      <reference source="CVE">CVE-2004-0839</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-53" comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false"/>
          <criterion test_ref="wft-562" comment="the version of mshtml.dll is less than 5.50.4945.2800 " negate="false"/>
          <criterion test_ref="wrt-561" comment="the patch kb834707 is installed (Installed Components key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL3799" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Apache</product>
      </affected>
      <dates>
        <submitted date="2004-10-19-03:08">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2004-10-20-02:35">DRAFT</status_change>
        <status_change date="2004-11-03-12:00">INTERIM</status_change>
        <status_change date="2004-12-09-08:46">ACCEPTED</status_change>
      </dates>
      <description>Multiple stack-based buffer overflows in (1) mod_alias and (2) mod_rewrite for Apache before 1.3.29 allow attackers to create configuration files to cause a denial of service (crash) or execute arbitrary code via a regular expression with more than 9 captures.</description>
      <reference source="CVE">CVE-2003-0542</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" negate="false"/>
          <criterion test_ref="spt-263" comment="Patch 113146-03 or later installed" negate="true"/>
          <criterion test_ref="spt-253" comment="Patch 116973-01 or later installed" negate="true"/>
          <criterion test_ref="sat-5" comment="Apache (SUNWapchu) installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-10" comment="Apache running (httpd)" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL3810" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Microsoft Project Professional 2003</product>
      </affected>
      <dates>
        <submitted date="2004-09-24-12:00">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </submitted>
        <status_change date="2004-09-29-12:00">DRAFT</status_change>
        <modified date="2004-09-30-12:00" comment="Changed affected platforms">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <status_change date="2004-10-20-12:00">INTERIM</status_change>
        <status_change date="2004-11-03-12:00">ACCEPTED</status_change>
        <modified date="2005-02-10-12:00" comment="modified wft-495 - corrected registry path check for .dll file">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <status_change date="2005-02-11-09:31">INTERIM</status_change>
        <status_change date="2005-03-02-09:01">ACCEPTED</status_change>
        <modified date="2005-12-26-09:40" comment="Changed criteria to remove test for KB838344.">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </modified>
        <status_change date="2006-01-12-08:59">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length before a memory copy operation.</description>
      <reference source="CVE">CVE-2004-0200</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-521" comment="Project Professional 2003 Installed" negate="false"/>
          <criterion test_ref="wft-495" comment="the version of gdiplus.dll is less than 6.0.3264.0" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL3817" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Microsoft Internet Explorer 6</product>
      </affected>
      <dates>
        <submitted date="2005-05-10-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2005-05-11-05:38">DRAFT</status_change>
        <status_change date="2005-06-01-03:30">INTERIM</status_change>
        <status_change date="2005-06-22-12:38">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the URL processor of Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a URL with a long hostname, aka "URL Parsing Memory Corruption Vulnerability."</description>
      <reference source="CVE">CVE-2005-0554</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-200" comment="Internet Explorer 6.0 Installed XP SP2" negate="false"/>
          <criterion test_ref="wft-595" comment="the version of mshtml.dll is less than 6.0.2900.2627" negate="false"/>
          <criterion test_ref="wrt-439" comment="the patch kb890923  is installed (XP SP2 Hotfix key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL3822" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Windows Shell</product>
      </affected>
      <dates>
        <submitted date="2004-10-14-03:38">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <status_change date="2004-10-20-02:35">DRAFT</status_change>
        <status_change date="2004-11-03-12:00">INTERIM</status_change>
        <status_change date="2004-12-09-08:46">ACCEPTED</status_change>
        <modified date="2005-09-26-12:39" comment="modified wft-509 - Changed test to match comment">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-28-01:04">INTERIM</status_change>
        <status_change date="2005-10-19-05:47">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the Windows Program Group Converter (grpconv.exe) may allow remote attackers to execute arbitrary code via a shell: URL with a long filename and a .grp extension, which is not properly handled when the shell capability launches grpconv.exe.</description>
      <reference source="CVE">CVE-2004-0572</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-2" comment="Windows XP is installed" negate="false"/>
          <criterion test_ref="wrt-70" comment="64-Bit version of Windows is installed" negate="false"/>
          <criterion test_ref="wrt-29" comment="Win2K/XP/2003 service pack 2 (or later) is installed" negate="true"/>
          <criterion test_ref="cmp-1115" comment="a vulnerable version of shell32.dll exists" negate="false"/>
          <criterion test_ref="wrt-537" comment="the patch q841356 is installed (Hotfix key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL3824" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Windows 2000</product>
      </affected>
      <dates>
        <submitted date="2005-04-22-12:00">
          <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
        </submitted>
        <status_change date="2005-04-27-12:06">DRAFT</status_change>
        <status_change date="2005-06-01-03:30">INTERIM</status_change>
        <status_change date="2005-06-22-12:38">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Windows XP SP2 and earlier, 2000 SP3 and SP4, Server 2003, and older operating systems allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted IP packets with malformed options, aka the "IP Validation Vulnerability."</description>
      <reference source="CVE">CVE-2005-0048</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
          <criterion test_ref="wrt-538" comment="Win2K/XP/2003 service pack 4 (or earlier) is installed" negate="false"/>
          <criterion test_ref="wft-593" comment="the version of Tcpip.sys is less than 5.0.2195.7035" negate="false"/>
          <criterion test_ref="wrt-443" comment="the patch KB893066 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL3826" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Windows XP</product>
      </affected>
      <dates>
        <submitted date="2005-08-18-04:00">
          <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
        </submitted>
        <status_change date="2005-08-25-10:05">DRAFT</status_change>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Multiple TCP/IP and ICMP implementations, when using Path MTU (PMTU) discovery (PMTUD), allow remote attackers to cause a denial of service (network throughput reduction for TCP connections) via forged ICMP ("Fragmentation Needed and Don't Fragment was Set") packets with a low next-hop MTU value, aka the "Path MTU discovery attack."  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</description>
      <reference source="CVE">CVE-2004-1060</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-2" comment="Windows XP is installed" negate="false"/>
          <criterion test_ref="cmp-23" comment="32-bit version of Windows or 64-bit (itanium architecture) version of Windows is installed" negate="false"/>
          <criterion test_ref="wrt-79" comment="Win2K/XP/2003 service pack 2 (or earlier) is installed" negate="false"/>
          <criterion test_ref="cmp-298" comment="A vulnerable version of tcpip.sys is installed." negate="false"/>
          <criterion test_ref="wrt-443" comment="the patch KB893066 is installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-380" comment="Enable Path MTU Discovery is Disabled" negate="true"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL3831" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>sendfilev()</product>
      </affected>
      <dates>
        <submitted date="2005-04-13-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-04-20-12:13">DRAFT</status_change>
        <status_change date="2005-05-11-05:41">INTERIM</status_change>
        <status_change date="2005-06-01-03:30">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in ntpd ntp daemon 4.0.99k and earlier (aka xntpd and xntp3) allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long readvar argument.</description>
      <reference source="CVE">CVE-2001-0414</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-43" comment="Solaris 7 or 8 installed" negate="false"/>
          <criterion test_ref="sat-35" comment="NTP daemon - Usr (SUNWntpu) installed" negate="false"/>
          <criterion test_ref="spt-61" comment="Patch 109409-04 or later installed" negate="true"/>
          <criterion test_ref="spt-62" comment="Patch 109667-04 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-18" comment="xntpd running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL3851" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Internet Explorer 6.0</product>
      </affected>
      <dates>
        <submitted date="2005-02-10-12:00">
          <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
        </submitted>
        <status_change date="2005-02-11-12:00">DRAFT</status_change>
        <status_change date="2005-03-02-12:00">INTERIM</status_change>
        <status_change date="2005-03-23-12:00">ACCEPTED</status_change>
        <modified date="2005-06-02-12:00" comment="Added product">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-06-08-12:00">INTERIM</status_change>
        <modified date="2005-06-17-12:00" comment="modified cmp-1106 - Replaced the test that checks for the service pack level, instead of checking for sp4 or ealier (did not check for GOLD edition) it is now negating the test that checks for sp5 for later.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <status_change date="2005-07-27-10:37">ACCEPTED</status_change>
      </dates>
      <description>The DHTML Edit Control (dhtmled.ocx) allows remote attackers to inject arbitrary web script into other domains by setting a name for a window, opening a child page whose target is the window with the given name, then injecting the script from the parent into the child using execScript, as demonstrated by "AbusiveParent" in Internet Explorer 6.0.2900.2180.</description>
      <reference source="CVE">CVE-2004-1319</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1106" comment="Windows 2000 (sp4 or earlier) is installed" negate="false"/>
          <criterion test_ref="wft-375" comment="the version of dhtmled.ocx is less than 6.1.0.9232" negate="false"/>
          <criterion test_ref="wrt-87" comment="the patch kb891781 is installed (Hotfix key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL3872" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Internet Explorer 6 Service Pack 1 for Windows Server 2003</product>
      </affected>
      <dates>
        <submitted date="2004-10-26-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2004-10-27-12:00">DRAFT</status_change>
        <status_change date="2004-11-17-12:00">INTERIM</status_change>
        <status_change date="2004-12-09-12:00">ACCEPTED</status_change>
        <modified date="2005-05-10-12:00" comment="modified wrt-51 - Comment updated to indicate IE 6.">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </modified>
        <status_change date="2005-05-11-05:33">INTERIM</status_change>
        <status_change date="2005-06-01-03:30">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 5.01, 5.5, and 6 does not properly cache SSL content, which allows remote attackers to obtain information or spoof content via a web site with the same host name as the target web site, whose content is cached and reused when the user visits the target web site.</description>
      <reference source="CVE">CVE-2004-0845</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-51" comment="Internet Explorer 6  for Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wft-558" comment="the version of mshtml.dll is less than 6.0.3790.219" negate="false"/>
          <criterion test_ref="wrt-557" comment="the patch kb834707 is installed (Hotfix key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-567" comment="Users not saving encrypted pages to disk  (DisableCachingOfSSLPages)" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL3881" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Microsoft Office XP SP2</product>
      </affected>
      <dates>
        <submitted date="2004-10-04-12:00">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </submitted>
        <status_change date="2004-10-06-12:00">DRAFT</status_change>
        <status_change date="2004-10-20-12:00">INTERIM</status_change>
        <status_change date="2004-11-03-12:00">ACCEPTED</status_change>
        <modified date="2005-02-10-12:00" comment="modified wft-496 - corrected registry path check">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <status_change date="2005-02-11-09:31">INTERIM</status_change>
        <status_change date="2005-03-02-09:01">ACCEPTED</status_change>
        <modified date="2005-12-26-09:40" comment="Changed criteria to remove test for KB832332.">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </modified>
        <status_change date="2006-01-12-08:59">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length before a memory copy operation.</description>
      <reference source="CVE">CVE-2004-0200</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-514" comment="Microsoft Office XP Service Pack 2 is installed" negate="false"/>
          <criterion test_ref="wft-496" comment="the version of mso.dll is less than 10.0.6714.0" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL3882" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Microsoft Word for Windows 6.0 Converter</product>
      </affected>
      <dates>
        <submitted date="2005-01-05-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2005-01-06-09:33">DRAFT</status_change>
        <status_change date="2005-02-02-12:00">INTERIM</status_change>
        <status_change date="2005-02-23-09:25">ACCEPTED</status_change>
        <modified date="2005-12-20-07:05" comment="Edited criteria. 1) dropped explicit check for Hotfix kb885836, 2) dropped version checks on mswrd wpc files.">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </modified>
        <status_change date="2006-01-04-08:04">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Word for Windows 6.0 Converter (MSWRD632.WPC), as used in WordPad, does not properly validate certain data lengths, which allows remote attackers to execute arbitrary code via a .wri, .rtf, and .doc file sent by email or malicious web site, aka "Font Conversion Vulnerability," a different vulnerability than CVE-2004-0571.</description>
      <reference source="CVE">CVE-2004-0901</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1058" comment="Windows XP 32-bit edition is installed" negate="false"/>
          <criterion test_ref="wft-123" comment="the version of wordpad.exe is less than 5.1.2600.1606" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL3889" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Windows Help and Support Center</product>
      </affected>
      <dates>
        <submitted date="2005-01-18-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2005-01-20-12:00">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-12:00">ACCEPTED</status_change>
        <modified date="2005-06-02-12:00" comment="Added product">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-06-08-03:17">INTERIM</status_change>
        <status_change date="2005-06-29-06:49">ACCEPTED</status_change>
      </dates>
      <description>Stack-based buffer overflow in the PCHealth system in the Help and Support Center function in Windows XP and Windows Server 2003 allows remote attackers to execute arbitrary code via a long query in an HCP URL.</description>
      <reference source="CVE">CVE-2003-0711</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1058" comment="Windows XP 32-bit edition is installed" negate="false"/>
          <criterion test_ref="wft-261" comment="the version of itircl.dll is less than 5.2.3790.80" negate="false"/>
          <criterion test_ref="wrt-308" comment="Patch KB825119 Installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-309" comment="HCP Protocol" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL3910" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Internet Explorer 5.01 Service Pack 4</product>
      </affected>
      <dates>
        <submitted date="2005-03-17-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2005-03-23-08:09">DRAFT</status_change>
        <status_change date="2005-04-13-12:15">INTERIM</status_change>
        <status_change date="2005-05-04-12:33">ACCEPTED</status_change>
        <modified date="2005-12-26-09:40" comment="Removed test to check kb867282.">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </modified>
        <status_change date="2006-01-12-08:59">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 5.01, 5.5, and 6 does not properly validate buffers when handling certain DHTML methods including the createControlRange Javascript function, which allows remote attackers to execute arbitrary code, aka the "DHTML Method Heap Memory Corruption Vulnerability."</description>
      <reference source="CVE">CVE-2005-0055</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-54" comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false"/>
          <criterion test_ref="wft-407" comment="the version of mshtml.dll is less than 5.0.3825.700" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL3913" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Compressed Folders</product>
      </affected>
      <dates>
        <submitted date="2004-10-14-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
        <status_change date="2004-10-20-12:00">DRAFT</status_change>
        <status_change date="2004-11-03-12:00">INTERIM</status_change>
        <status_change date="2004-12-09-12:00">ACCEPTED</status_change>
        <modified date="2005-01-13-12:00" comment="modified wrt-554 - corrected regular exprsssion on value. Needed to escape the period in the file name and change the *'s to .*">
          <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
        </modified>
        <status_change date="2005-01-20-12:00">INTERIM</status_change>
        <status_change date="2005-02-16-12:00">ACCEPTED</status_change>
        <modified date="2005-05-05-12:00" comment="Removed the negate=&quot;true&quot; from the config test; should be vulnerable *if* enabled, rather than vulnerable if *not*  enabled.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2005-05-11-05:33">INTERIM</status_change>
        <status_change date="2005-06-01-03:30">ACCEPTED</status_change>
      </dates>
      <description>Integer overflow in DUNZIP32.DLL for Microsoft Windows XP, Windows XP 64-bit Edition, Windows Server 2003, and Windows Server 2003 64-bit Edition allows remote attackers to execute arbitrary code via compressed (zipped) folders that involve an "unchecked buffer" and improper length validation.</description>
      <reference source="CVE">CVE-2004-0575</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wrt-72" comment="32-Bit version of Windows is installed" negate="false"/>
          <criterion test_ref="wft-537" comment="the 32-bit version of zipfldr.dll is less than 6.0.3790.198" negate="false"/>
          <criterion test_ref="wrt-553" comment="the patch q873376 is installed (Hotfix key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-554" comment="Compressed Folders with zipfldr.dll are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL3926" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Microsoft Internet Explorer 6 Service Pack 1</product>
      </affected>
      <dates>
        <submitted date="2005-05-10-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2005-05-11-05:38">DRAFT</status_change>
        <status_change date="2005-06-01-03:30">INTERIM</status_change>
        <status_change date="2005-06-22-12:38">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the Content Advisor in Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a crafted Content Advisor file, aka "Content Advisor Memory Corruption Vulnerability."</description>
      <reference source="CVE">CVE-2005-0555</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-50" comment="Internet Explorer 6 Service Pack 1 is installed" negate="false"/>
          <criterion test_ref="cmp-292" comment="a vulnerable version of mshtml.dll exisits GDR/QFE" negate="false"/>
          <criterion test_ref="wrt-440" comment="the patch kb890923  is installed (XP Win2K Hotfix key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL3941" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Windows kernel</product>
      </affected>
      <dates>
        <submitted date="2005-05-02-12:00">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </submitted>
        <status_change date="2005-05-04-12:00">DRAFT</status_change>
        <status_change date="2005-06-01-12:00">INTERIM</status_change>
        <modified date="2005-06-02-12:00" comment="Added product">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-06-22-12:38">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the font processing component of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via a specially-designed application.</description>
      <reference source="CVE">CVE-2005-0060</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-35" comment="Windows XP 32 bit Service Pack 2" negate="false"/>
          <criterion test_ref="wft-581" comment="The version of Ntoskrnl.exe is less than 5.1.2600.2622" negate="false"/>
          <criterion test_ref="wrt-427" comment="the patch KB890859 is installed (Hotfix key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL3949" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Internet Explorer 5.01 Service Pack 3</product>
      </affected>
      <dates>
        <submitted date="2005-01-18-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2005-01-20-02:31">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 5.5 and 6 does not properly handle plug-in navigation, which allows remote attackers to alter displayed address bars and thereby spoof web pages, facilitating phishing attacks, aka the "Plug-in Navigation Address Bar Spoofing Vulnerability."</description>
      <reference source="CVE">CVE-2004-0843</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-55" comment="Internet Explorer 5.01 Service Pack 3 is installed" negate="false"/>
          <criterion test_ref="wft-560" comment="the version of mshtml.dll is less than 5.0.3821.2800" negate="false"/>
          <criterion test_ref="wrt-559" comment="the patch kb834707-ie501sp3 is installed (Hotfix key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL3953" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>VDM</product>
      </affected>
      <dates>
        <submitted date="2004-10-13-12:05">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </submitted>
        <status_change date="2004-10-13-01:15">DRAFT</status_change>
        <status_change date="2004-10-27-12:00">INTERIM</status_change>
        <status_change date="2004-11-17-10:00">ACCEPTED</status_change>
      </dates>
      <description>The Virtual DOS Machine (VDM) subsystem of Microsoft Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows local users to access kernel memory and gain privileges via a malicious program that modified some system structures in a way that is not properly validated by privileged operating system functions.</description>
      <reference source="CVE">CVE-2004-0208</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-41" comment="this is an NT Server (stand-alone)" negate="false"/>
          <criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" negate="false"/>
          <criterion test_ref="wrt-547" comment="the patch KB840987 is installed (Hotfix key)" negate="true"/>
          <criterion test_ref="wft-512" comment="the version of gdi32.dll is less than 4.0.1381.7270" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL3957" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>Windows Animated Cursor</product>
      </affected>
      <dates>
        <submitted date="2005-01-14-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2005-01-20-02:31">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>The Windows Animated Cursor (ANI) capability in Windows NT, Windows 2000 through SP4, Windows XP through SP1, and Windows 2003 allow remote attackers to cause a denial of service via (1) the frame number set to zero, which causes an invalid memory address to be used and leads to a kernel crash, or (2) the rate number set to zero, which leads to resource exhaustion and hang.</description>
      <reference source="CVE">CVE-2004-1305</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-45" comment="Windows NT Server 4.0, Terminal Server Edition is installed" negate="false"/>
          <criterion test_ref="wft-352" comment="the version of user32.dll is less than 4.0.1381.33630" negate="false"/>
          <criterion test_ref="wrt-68" comment="the patch kb891711 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL3960" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>Bind</product>
      </affected>
      <dates>
        <submitted date="2005-04-13-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-04-20-12:13">DRAFT</status_change>
        <status_change date="2005-05-11-05:41">INTERIM</status_change>
        <status_change date="2005-06-01-03:30">ACCEPTED</status_change>
      </dates>
      <description>Unknown vulnerability in in.named on Solaris 8 allows remote attackers to cause a denial of service (process crash).</description>
      <reference source="CVE">CVE-2004-1348</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="sat-19" comment="Internet Domain Name Server (BIND, SUNWinamd) installed" negate="false"/>
          <criterion test_ref="spt-66" comment="Patch 109326-16 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uft-31" comment="File /etc/named.conf exists " negate="false"/>
          <criterion test_ref="uct-14" comment="in.named running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL3966" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Distributed Component Object Model (DCOM) interface</product>
      </affected>
      <dates>
        <submitted date="2005-01-18-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2005-01-20-02:31">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Heap-based buffer overflow in the Distributed Component Object Model (DCOM) interface in the RPCSS Service allows remote attackers to execute arbitrary code via a malformed RPC request with a long filename parameter, a different vulnerability than CVE-2003-0352 (Blaster/Nachi) and CVE-2003-0715.</description>
      <reference source="CVE">CVE-2003-0528</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-38" comment="Windows Server 2003 or Windows XP 64-Bit Edition Version 2003" negate="false"/>
          <criterion test_ref="wft-358" comment="the version of rpcrt4.dll is less than 5.2.3790.76" negate="false"/>
          <criterion test_ref="wrt-281" comment="the patch kb824146 is installed (Hotfix key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-283" comment="DCOM is enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL3973" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>HyperTerminal</product>
      </affected>
      <dates>
        <submitted date="2004-12-21-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2005-01-18-12:00">DRAFT</status_change>
        <status_change date="2005-02-02-12:00">INTERIM</status_change>
        <modified date="2005-03-02-12:00" comment="modified wft-226 - access DLL via HKLM">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </modified>
        <status_change date="2005-03-23-08:09">ACCEPTED</status_change>
      </dates>
      <description>HyperTerminal application for Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 does not properly validate the length of a value that is saved in a session file, which allows remote attackers to execute arbitrary code via a malicious HyperTerminal session file (.ht), web site, or Telnet URL contained in an e-mail message, triggering a buffer overflow.</description>
      <reference source="CVE">CVE-2004-0568</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wft-226" comment="the version of hypertrm.dll is less than 4.0.1381.7323" negate="false"/>
          <criterion test_ref="wrt-47" comment="the patch NT Server kb873339 is installed " negate="true"/>
          <criterion test_ref="cmp-44" comment="Windows NT Server 4.0 is installed" negate="false"/>
        </software>
        <configuration operation="OR">
          <criterion test_ref="wrt-39" comment="If key present hyperterminal will automatically open session files" negate="false"/>
          <criterion test_ref="wrt-67" comment="If the Hyperterminal client is registered as the default telnet client" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL3989" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>mozilla</product>
      </affected>
      <dates>
        <submitted date="2005-01-19-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-24-03:40">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Mozilla Firefox 0.9.1 and 0.9.2 allows remote web sites to spoof certificates of trusted web sites via redirects and Javascript that uses the "onunload" method.</description>
      <reference source="CVE">CVE-2004-0763</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" negate="false"/>
          <criterion test_ref="cmp-72" comment="Mozilla components (any SUNWmoznav/SUNWmozmail) installed" negate="false"/>
          <criterion test_ref="spt-46" comment="Patch 117765-02 or later installed" negate="true"/>
          <criterion test_ref="spt-47" comment="Patch 117767-02 or later installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL3994" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Windows kernel</product>
      </affected>
      <dates>
        <submitted date="2005-05-02-12:00">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </submitted>
        <status_change date="2005-05-04-12:00">DRAFT</status_change>
        <status_change date="2005-06-01-12:00">INTERIM</status_change>
        <modified date="2005-06-02-12:00" comment="Added product">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-06-22-12:38">ACCEPTED</status_change>
      </dates>
      <description>The kernel of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via certain access requests.</description>
      <reference source="CVE">CVE-2005-0061</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-2" comment="Windows XP is installed" negate="false"/>
          <criterion test_ref="wrt-427" comment="the patch KB890859 is installed (Hotfix key)" negate="true"/>
          <criterion test_ref="cmp-328" comment="Windows No Service Pack or Service Pack 1 and Ntoskrnl.exe version less than 5.1.2600.1634" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL4003" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>GDI+</product>
      </affected>
      <dates>
        <submitted date="2004-09-20-03:32">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </submitted>
        <status_change date="2004-09-22-02:10">DRAFT</status_change>
        <status_change date="2004-10-06-12:00">INTERIM</status_change>
        <status_change date="2004-10-20-12:00">ACCEPTED</status_change>
        <modified date="2005-12-26-09:40" comment="Removed test to check KB833987.">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </modified>
        <status_change date="2006-01-12-08:59">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length before a memory copy operation.</description>
      <reference source="CVE">CVE-2004-0200</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-2" comment="Windows XP is installed" negate="false"/>
          <criterion test_ref="wft-494" comment="the version of sxs.dll is less than 5.1.2600.1363" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL4005" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Microsoft Office XP SP2</product>
      </affected>
      <dates>
        <submitted date="2004-09-22-12:00">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </submitted>
        <status_change date="2004-09-23-12:00">DRAFT</status_change>
        <status_change date="2004-10-06-12:00">INTERIM</status_change>
        <status_change date="2004-10-20-12:00">ACCEPTED</status_change>
        <modified date="2005-02-10-12:00" comment="modified wft-489 - corrected registry path check for .dll file">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <status_change date="2005-02-11-09:31">INTERIM</status_change>
        <status_change date="2005-03-02-09:01">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the converter for Microsoft WordPerfect 5.x on Office 2000, Office XP, Office 2003, and Works Suites 2001 through 2004 allows remote attackers to execute arbitrary code via a malicious document or website.</description>
      <reference source="CVE">CVE-2004-0573</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-514" comment="Microsoft Office XP Service Pack 2 is installed" negate="false"/>
          <criterion test_ref="wft-489" comment="the version of msconv97.dll is less than 2003.1100.6252.0 " negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL4021" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>Windows kernel</product>
      </affected>
      <dates>
        <submitted date="2004-12-16-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2005-01-12-12:41">DRAFT</status_change>
        <status_change date="2005-02-02-12:00">INTERIM</status_change>
        <status_change date="2005-02-23-09:25">ACCEPTED</status_change>
      </dates>
      <description>The Local Procedure Call (LPC) interface of the Windows Kernel for Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 does not properly validate the lengths of messages sent to the LPC port, which allows local users to gain privileges, aka "Windows Kernel Vulnerability."</description>
      <reference source="CVE">CVE-2004-0893</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-45" comment="Windows NT Server 4.0, Terminal Server Edition is installed" negate="false"/>
          <criterion test_ref="wft-147" comment="The version of Ntoskrnl.exe is less than 4.0.1381.33591" negate="false"/>
          <criterion test_ref="wrt-36" comment="the patch kb885835is installed (Hotfix key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL4022" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 98</windows:platform>
        <windows:platform>Microsoft Windows ME</windows:platform>
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Office XP SP3</product>
      </affected>
      <dates>
        <submitted date="2005-02-10-12:00">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </submitted>
        <modified date="2005-02-11-12:00" comment="Added patch check">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <modified date="2005-03-29-12:00" comment="corrected patch negation">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <status_change date="2005-03-29-08:38">DRAFT</status_change>
        <status_change date="2005-04-13-12:15">INTERIM</status_change>
        <status_change date="2005-05-04-12:33">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in Microsoft Office XP allows remote attackers to execute arbitrary code via a link with a URL file location containing long inputs after (1) "%00 (null byte) in .doc filenames or (2) "%0a" (carriage return) in .rtf filenames.</description>
      <reference source="CVE">CVE-2004-0848</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-199" comment="Microsoft Office XP Service Pack 3 is installed" negate="false"/>
          <criterion test_ref="wft-377" comment="the version of mso.dll is less than 10.0.6735.0" negate="false"/>
          <criterion test_ref="wrt-95" comment="Patch KB873352 installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL4030" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>DtMail</product>
      </affected>
      <dates>
        <submitted date="2004-10-19-03:09">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2004-10-20-02:35">DRAFT</status_change>
        <status_change date="2004-11-03-12:00">INTERIM</status_change>
        <status_change date="2004-12-09-08:46">ACCEPTED</status_change>
      </dates>
      <description>Format string vulnerability in CDE Mailer (dtmail) on Solaris 8 and 9 allows local users to gain privileges via format strings in the argv[0] value.</description>
      <reference source="CVE">CVE-2004-0800</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" negate="false"/>
          <criterion test_ref="spt-264" comment="Patch 109613-07 or later installed" negate="true"/>
          <criterion test_ref="spt-265" comment="Patch 112810-06 or later installed" negate="true"/>
          <criterion test_ref="sat-9" comment="CDE Desktop Applications (SUNWdtdst) installed                                                                                               " negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL4032" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Exchange Server 2003</product>
      </affected>
      <dates>
        <submitted date="2005-04-21-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2005-04-27-12:06">DRAFT</status_change>
        <status_change date="2005-06-01-03:30">INTERIM</status_change>
        <status_change date="2005-06-22-12:38">ACCEPTED</status_change>
      </dates>
      <description>Heap-based buffer overflow in the SvrAppendReceivedChunk function in xlsasink.dll in the SMTP service of Exchange Server 2000 and 2003 allows remote attackers to execute arbitrary code via a crafted X-LINK2STATE extended verb request to the SMTP port.</description>
      <reference source="CVE">CVE-2005-0560</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-566" comment="Exchange Server 2003 is installed" negate="false"/>
          <criterion test_ref="wft-575" comment="the version of xlsasink.dll is less than 6.5.6981.3" negate="false"/>
          <criterion test_ref="wrt-423" comment="the patch KB894549 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL4043" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>SMB (Server Message Block)</product>
      </affected>
      <dates>
        <submitted date="2005-02-15-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2005-02-18-12:00">DRAFT</status_change>
        <status_change date="2005-03-09-12:00">INTERIM</status_change>
        <status_change date="2005-03-29-12:00">ACCEPTED</status_change>
        <modified date="2005-06-17-12:00" comment="modified cmp-1106 - Replaced the test that checks for the service pack level, instead of checking for sp4 or ealier (did not check for GOLD edition) it is now negating the test that checks for sp5 for later.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <status_change date="2005-06-22-12:35">INTERIM</status_change>
        <status_change date="2005-07-27-10:37">ACCEPTED</status_change>
      </dates>
      <description>The Server Message Block (SMB) implementation for Windows NT 4.0, 2000, XP, and Server 2003 does not properly validate certain SMB packets, which allows remote attackers to execute arbitrary code via Transaction responses containing (1) Trans or (2) Trans2 commands, aka the "Server Message Block Vulnerability," and as demonstrated using Trans2 FIND_FIRST2 responses with large file name length fields.</description>
      <reference source="CVE">CVE-2005-0045</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1106" comment="Windows 2000 (sp4 or earlier) is installed" negate="false"/>
          <criterion test_ref="wft-385" comment="the version of mrxsmb.sys is less than 5.0.2195.7023" negate="false"/>
          <criterion test_ref="wrt-90" comment="the patch KB885250 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL4047" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>bash, tcsh, cash, sh, ksh</product>
      </affected>
      <dates>
        <submitted date="2005-01-19-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-24-03:40">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Multiple shell programs on various Unix systems, including (1) tcsh, (2) csh, (3) sh, and (4) bash, follow symlinks when processing &lt;&lt; redirects (aka here-documents or in-here documents), which allows local users to overwrite files of other users via a symlink attack.</description>
      <reference source="CVE">CVE-2000-1134</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-43" comment="Solaris 7 or 8 installed" negate="false"/>
          <criterion test_ref="cmp-69" comment="Patches 108574-03, 108162-04, and 108416-02 or later installed" negate="true"/>
          <criterion test_ref="cmp-70" comment="Patches 110943-01, 110898-02, and 109324-03 or later installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL4076" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Word for Windows 6.0 Converter</product>
      </affected>
      <dates>
        <submitted date="2005-01-05-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2005-01-12-12:00">DRAFT</status_change>
        <status_change date="2005-02-02-12:00">INTERIM</status_change>
        <status_change date="2005-02-23-12:00">ACCEPTED</status_change>
        <modified date="2005-04-08-12:00" comment="modified wrt-35 - wrt-35 corrected literal string">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <status_change date="2005-04-11-08:48">INTERIM</status_change>
        <status_change date="2005-04-27-12:07">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Word for Windows 6.0 Converter (MSWRD632.WPC), as used in WordPad, does not properly validate certain data lengths, which allows remote attackers to execute arbitrary code via a .wri, .rtf, and .doc file sent by email or malicious web site, aka "Font Conversion Vulnerability," a different vulnerability than CVE-2004-0571.</description>
      <reference source="CVE">CVE-2004-0901</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-25" comment="the patch kb885836 is installed (Hotfix key)" negate="true"/>
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wft-281" comment="the version of mswrd632.wpc is less than 2004.10.25.0" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-35" comment="Word for Windows 6.0 Converter is enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL4085" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Microsoft Internet Explorer 6</product>
      </affected>
      <dates>
        <submitted date="2005-03-17-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2005-03-23-12:00">DRAFT</status_change>
        <status_change date="2005-04-13-12:00">INTERIM</status_change>
        <modified date="2005-04-21-12:00" comment="modified wrt-159 - unchecked value">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </modified>
        <status_change date="2005-05-11-05:41">ACCEPTED</status_change>
        <modified date="2005-12-26-09:40" comment="Removed test to check kb867282.">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </modified>
        <status_change date="2006-01-12-08:59">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 5.01, 5.5, and 6 does not properly validate certain URLs in Channel Definition Format (CDF) files, which allows remote attackers to obtain sensitive information or execute arbitrary code, aka the "Channel Definition Format (CDF) Cross Domain Vulnerability."</description>
      <reference source="CVE">CVE-2005-0056</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-200" comment="Internet Explorer 6.0 Installed XP SP2" negate="false"/>
          <criterion test_ref="wft-500" comment="the version of mshtml.dll is less than 6.0.2900.2604" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL4098" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>lpstat, libprint</product>
      </affected>
      <dates>
        <submitted date="2005-01-19-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-24-03:40">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Unknown multiple vulnerabilities in (1) lpstat and (2) the libprint library in Solaris 2.6 through 9 may allow attackers to execute arbitrary code or read or write arbitrary files.</description>
      <reference source="CVE">CVE-2003-0999</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" negate="false"/>
          <criterion test_ref="cmp-71" comment="Solaris Printing Services installed (any SUNWpcr/SUNWpcu/SUNWpsr/SUNWpsu)" negate="false"/>
          <criterion test_ref="spt-43" comment="Patch 107115-13 or later installed" negate="true"/>
          <criterion test_ref="spt-44" comment="Patch 109320-07 or later installed" negate="true"/>
          <criterion test_ref="spt-45" comment="Patch 113329-02 or later installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL4114" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Apache</product>
      </affected>
      <dates>
        <submitted date="2004-10-14-01:14">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <modified date="2004-10-18-03:14" comment="Change apache test to file test">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </modified>
        <modified date="2004-10-19-11:18" comment="Changed apache test to package test">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </modified>
        <status_change date="2004-10-20-02:35">DRAFT</status_change>
        <status_change date="2004-11-03-12:00">INTERIM</status_change>
        <status_change date="2004-12-09-08:46">ACCEPTED</status_change>
      </dates>
      <description>Apache does not filter terminal escape sequences from its error logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related to escape sequences.</description>
      <reference source="CVE">CVE-2003-0020</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" negate="false"/>
          <criterion test_ref="spt-253" comment="Patch 116973-01 or later installed" negate="true"/>
          <criterion test_ref="spt-254" comment="Patch 113146-05 or later installed" negate="true"/>
          <criterion test_ref="sat-5" comment="Apache (SUNWapchu) installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-10" comment="Apache running (httpd)" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL4152" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Internet Explorer 5.01 Service Pack 4</product>
      </affected>
      <dates>
        <submitted date="2004-10-25-04:44">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2004-10-27-01:04">DRAFT</status_change>
        <status_change date="2004-11-17-10:00">INTERIM</status_change>
        <status_change date="2004-12-09-08:46">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer in Windows XP SP2, and other versions including 5.01 and 5.5, allows remote attackers to install arbitrary programs via a web page that uses certain styles and the AnchorClick behavior, popup windows, and drag-and-drop capabilities to drop the program in the local startup folder, as demonstrated by "wottapoop.html".</description>
      <reference source="CVE">CVE-2004-0839</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-54" comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false"/>
          <criterion test_ref="wft-561" comment="the version of mshtml.dll is less than 5.0.3534.2800" negate="false"/>
          <criterion test_ref="wrt-560" comment="the patch kb834707-ie501sp4 is installed (Hotfix key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL4169" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Internet Explorer 6</product>
      </affected>
      <dates>
        <submitted date="2004-10-19-04:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2004-10-20-04:00">DRAFT</status_change>
        <status_change date="2004-11-03-05:00">INTERIM</status_change>
        <status_change date="2004-12-09-05:00">ACCEPTED</status_change>
        <modified date="2005-09-20-04:00" comment="Changed IE registry test to wrt-18">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-21-01:27">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 6.0 SP1 and earlier, and possibly other versions, allows remote attackers to cause a denial of service (application crash from "memory corruption") via certain malformed Cascading Style Sheet (CSS) elements that trigger heap-based buffer overflows, as demonstrated using the "&lt;STYLE>@;/*" string, possibly due to a missing comment terminator that may cause an invalid length to trigger a large memory copy operation, aka the "CSS Heap Memory Corruption Vulnerability."</description>
      <reference source="CVE">CVE-2004-0842</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wft-563" comment="the version of mshtml.dll is less than 6.0.2745.2800" negate="false"/>
          <criterion test_ref="wrt-562" comment="the patch kb834707 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-18" comment="Internet Explorer 6 is installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL4190" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>Bind</product>
      </affected>
      <dates>
        <submitted date="2005-01-19-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-24-03:40">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the DNS resolver code used in libc, glibc, and libbind, as derived from ISC BIND, allows remote malicious DNS servers to cause a denial of service and possibly execute arbitrary code via the stub resolvers.</description>
      <reference source="CVE">CVE-2002-0651</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" negate="false"/>
          <criterion test_ref="spt-30" comment="Patch 106938-06 or later installed" negate="true"/>
          <criterion test_ref="spt-31" comment="Patch 109326-09 or later installed" negate="true"/>
          <criterion test_ref="spt-32" comment="Patch 112970-02 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="tft-4" comment="/etc/nsswitch.conf configured to resolve hosts through DNS" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL4216" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Internet Explorer 6 SP1</product>
      </affected>
      <dates>
        <submitted date="2004-10-04-09:55">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </submitted>
        <status_change date="2004-10-06-12:57">DRAFT</status_change>
        <status_change date="2004-10-20-12:00">INTERIM</status_change>
        <status_change date="2004-11-03-12:00">ACCEPTED</status_change>
        <modified date="2005-12-26-09:40" comment="Removed test to check q833989, added check for vgx.dll.">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </modified>
        <status_change date="2006-01-12-08:59">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length before a memory copy operation.</description>
      <reference source="CVE">CVE-2004-0200</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
          <criterion test_ref="wrt-50" comment="Internet Explorer 6 Service Pack 1 is installed" negate="false"/>
          <criterion test_ref="wft-10002" comment="the version of vgx.dll is less than 6.0.2800.1411" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL4224" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Distributed Component Object Model (DCOM) interface</product>
      </affected>
      <dates>
        <submitted date="2005-01-18-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2005-01-20-02:31">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Heap-based buffer overflow in the Distributed Component Object Model (DCOM) interface in the RPCSS Service allows remote attackers to execute arbitrary code via a malformed DCERPC DCOM object activation request packet with modified length fields, a different vulnerability than CVE-2003-0352 (Blaster/Nachi) and CVE-2003-0528.</description>
      <reference source="CVE">CVE-2003-0715</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1058" comment="Windows XP 32-bit edition is installed" negate="false"/>
          <criterion test_ref="wft-359" comment="the version of rpcrt4.dll is less than 5.1.2600.109" negate="false"/>
          <criterion test_ref="wrt-281" comment="the patch kb824146 is installed (Hotfix key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-283" comment="DCOM is enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL4226" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 95</windows:platform>
        <windows:platform>Microsoft Windows 98</windows:platform>
        <windows:platform>Microsoft Windows ME</windows:platform>
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Excel 2002</product>
      </affected>
      <dates>
        <submitted date="2004-10-18-12:11">
          <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
        </submitted>
        <status_change date="2004-10-20-02:35">DRAFT</status_change>
      </dates>
      <description>Unknown vulnerability in Microsoft Excel 2000, 2002, 2001 for Mac, and v.X for Mac allows remote attackers to execute arbitrary code via a malicious file containing certain parameters that are not properly validated.</description>
      <reference source="CVE">CVE-2004-0846</reference>
      <status>DRAFT</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-138" comment="Excel 2002 is installed" negate="false"/>
          <criterion test_ref="ukn-38" comment="Service Pack 2 or less for Windows Office XP" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL4234" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 95</windows:platform>
        <windows:platform>Microsoft Windows 98</windows:platform>
        <windows:platform>Microsoft Windows ME</windows:platform>
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Samba</product>
      </affected>
      <dates>
        <submitted date="2005-09-15-04:00">
          <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
        </submitted>
        <status_change date="2005-09-21-01:33">DRAFT</status_change>
        <status_change date="2005-10-12-05:49">INTERIM</status_change>
        <status_change date="2005-11-16-08:02">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in Microsoft Word 2000, Word 2002, and Word 2003 allows remote attackers to execute arbitrary code via a crafted document.</description>
      <reference source="CVE">CVE-2005-0558</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-607" comment="Word 2003 is installed" negate="false"/>
          <criterion test_ref="wft-612" comment="the version of winword.exe is less than 11.0.6502.0" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL4244" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Program Group Converter</product>
      </affected>
      <dates>
        <submitted date="2004-10-14-03:39">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <status_change date="2004-10-20-02:35">DRAFT</status_change>
        <status_change date="2004-11-03-12:00">INTERIM</status_change>
        <status_change date="2004-12-09-08:46">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the Windows Program Group Converter (grpconv.exe) may allow remote attackers to execute arbitrary code via a shell: URL with a long filename and a .grp extension, which is not properly handled when the shell capability launches grpconv.exe.</description>
      <reference source="CVE">CVE-2004-0572</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wrt-72" comment="32-Bit version of Windows is installed" negate="false"/>
          <criterion test_ref="wft-525" comment="the version of grpconv.exe (system32) is less than 5.2.3790.205" negate="false"/>
          <criterion test_ref="wrt-537" comment="the patch q841356 is installed (Hotfix key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL4254" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Sun Cluster</product>
      </affected>
      <dates>
        <submitted date="2004-10-19-03:10">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2004-10-20-02:35">DRAFT</status_change>
        <status_change date="2004-11-03-12:00">INTERIM</status_change>
        <status_change date="2004-12-09-08:46">ACCEPTED</status_change>
      </dates>
      <description>Integer overflow in OpenSSL 0.9.6 and 0.9.7 allows remote attackers to cause a denial of service (crash) via an SSL client certificate with certain ASN.1 tag values.</description>
      <reference source="CVE">CVE-2003-0543</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" negate="false"/>
          <criterion test_ref="spt-266" comment="Patch 113505-02 or later installed" negate="true"/>
          <criterion test_ref="spt-267" comment="Patch 113508-02 or later installed" negate="true"/>
          <criterion test_ref="spt-268" comment="Patch 115054-01 or later installed" negate="true"/>
          <criterion test_ref="spt-269" comment="Patch 115055-01 or later installed" negate="true"/>
          <criterion test_ref="sat-8" comment="SunCluster Component SUNWscvw installed" negate="false"/>
          <criterion test_ref="sat-5" comment="Apache (SUNWapchu) installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-13" comment="Apache running with SunPlex Manager config" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL4264" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>ISA Server 2000</product>
      </affected>
      <dates>
        <submitted date="2004-11-17-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2005-01-12-12:41">DRAFT</status_change>
        <status_change date="2005-02-02-12:00">INTERIM</status_change>
        <status_change date="2005-02-23-09:25">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Proxy Server 2.0 and Microsoft ISA Server 2000 (which is included in Small Business Server 2000 and Small Business Server 2003 Premium Edition) allows remote attackers to spoof trusted Internet content on a specially crafted webpage via spoofed reverse DNS lookup results.</description>
      <reference source="CVE">CVE-2004-0892</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wft-6" comment="the version of msphlpr.dll is less than 3.0.1200.408" negate="false"/>
          <criterion test_ref="wrt-11" comment="ISA Server 2000 SP2 (or earlier) is installed" negate="false"/>
          <criterion test_ref="wrt-13" comment="the patch KB888258 is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL4276" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Compressed Folders</product>
      </affected>
      <dates>
        <submitted date="2004-10-14-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
        <status_change date="2004-10-20-12:00">DRAFT</status_change>
        <status_change date="2004-11-03-12:00">INTERIM</status_change>
        <status_change date="2004-12-09-12:00">ACCEPTED</status_change>
        <modified date="2005-01-13-12:00" comment="modified wrt-554 - corrected regular exprsssion on value. Needed to escape the period in the file name and change the *'s to .*">
          <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
        </modified>
        <status_change date="2005-01-20-12:00">INTERIM</status_change>
        <status_change date="2005-02-16-12:00">ACCEPTED</status_change>
        <modified date="2005-05-05-12:00" comment="Removed the negate=&quot;true&quot; from the config test; should be vulnerable *if* enabled, rather than vulnerable if *not*  enabled.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2005-05-11-05:33">INTERIM</status_change>
        <status_change date="2005-06-01-03:30">ACCEPTED</status_change>
      </dates>
      <description>Integer overflow in DUNZIP32.DLL for Microsoft Windows XP, Windows XP 64-bit Edition, Windows Server 2003, and Windows Server 2003 64-bit Edition allows remote attackers to execute arbitrary code via compressed (zipped) folders that involve an "unchecked buffer" and improper length validation.</description>
      <reference source="CVE">CVE-2004-0575</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wrt-70" comment="64-Bit version of Windows is installed" negate="false"/>
          <criterion test_ref="wft-538" comment="the 64-bit WOW version of zipfldr.dll is less than 6.0.3790.198" negate="false"/>
          <criterion test_ref="wrt-553" comment="the patch q873376 is installed (Hotfix key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-554" comment="Compressed Folders with zipfldr.dll are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL4282" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>DHCP</product>
      </affected>
      <dates>
        <submitted date="2005-01-27-12:00">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </submitted>
        <status_change date="2005-01-28-09:32">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>The DHCP Server service for Microsoft Windows NT 4.0 Server and Terminal Server Edition, with DHCP logging enabled, does not properly validate the length of certain messages, which allows remote attackers to cause a denial of service (application crash) via a malformed DHCP message, aka "Logging Vulnerability."</description>
      <reference source="CVE">CVE-2004-0899</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" negate="false"/>
          <criterion test_ref="wrt-43" comment="this is an NT Terminal Server" negate="false"/>
          <criterion test_ref="wft-162" comment="the version of Dhcpssvc.dll is less than 4.0.1381.33587" negate="false"/>
          <criterion test_ref="wrt-37" comment="the patch KB885249 is installed (Hotfix key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL4307" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Microsoft Visual Studio .NET 2002</product>
      </affected>
      <dates>
        <submitted date="2004-09-30-11:37">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </submitted>
        <status_change date="2004-10-06-12:57">DRAFT</status_change>
        <status_change date="2004-10-20-12:00">INTERIM</status_change>
        <status_change date="2004-11-03-12:00">ACCEPTED</status_change>
        <modified date="2005-12-26-09:40" comment="Removed test to check KB830348.  Added check for VS.NET Gdiplus.dll in WinSxS.">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </modified>
        <status_change date="2006-01-12-08:59">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length before a memory copy operation.</description>
      <reference source="CVE">CVE-2004-0200</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-531" comment="Microsoft Visual Studio .NET 2002 Installed" negate="false"/>
          <criterion test_ref="wft-714" comment="the version of Gdiplus.dll for Visual Studio .NET is less than 5.1.3102.1355" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL4316" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>VDM</product>
      </affected>
      <dates>
        <submitted date="2004-10-13-11:08">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </submitted>
        <status_change date="2004-10-13-01:16">DRAFT</status_change>
        <status_change date="2004-10-27-12:00">INTERIM</status_change>
        <status_change date="2004-11-17-10:00">ACCEPTED</status_change>
      </dates>
      <description>The Virtual DOS Machine (VDM) subsystem of Microsoft Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows local users to access kernel memory and gain privileges via a malicious program that modified some system structures in a way that is not properly validated by privileged operating system functions.</description>
      <reference source="CVE">CVE-2004-0208</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
          <criterion test_ref="wft-505" comment="the version of vdmdbg.dll is less than 5.0.2195.6946" negate="false"/>
          <criterion test_ref="wrt-547" comment="the patch KB840987 is installed (Hotfix key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL4328" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>Microsoft Word for Windows 6.0 Converter</product>
      </affected>
      <dates>
        <submitted date="2005-01-05-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2005-01-12-12:41">DRAFT</status_change>
        <status_change date="2005-02-02-12:00">INTERIM</status_change>
        <status_change date="2005-02-23-09:25">ACCEPTED</status_change>
        <modified date="2005-12-20-07:05" comment="Edited criteria. 1) dropped explicit check for Hotfix kb885836, 2) check version of wordpad.exe rather than mswrd wpc files.">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </modified>
        <status_change date="2006-01-04-08:04">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Word for Windows 6.0 Converter does not properly validate certain data lengths, which allows remote attackers to execute arbitrary code via a .wri, .rtf, and .doc file sent by email or malicious web site, aka "Table Conversion Vulnerability," a different vulnerability than CVE-2004-0901.</description>
      <reference source="CVE">CVE-2004-0571</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-44" comment="Windows NT Server 4.0 is installed" negate="false"/>
          <criterion test_ref="wft-710" comment="the version of wordpad.exe is less than 4.0.1381.7312" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL4329" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>cachefsd</product>
      </affected>
      <dates>
        <submitted date="2005-02-01-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-02-01-08:41">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>cachefsd in Solaris 2.6, 7, and 8 allows remote attackers to cause a denial of service (crash) via an invalid procedure call in an RPC request.</description>
      <reference source="CVE">CVE-2002-0085</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" negate="false"/>
          <criterion test_ref="spt-109" comment="Patch 108800-02 or later installed" negate="true"/>
          <criterion test_ref="spt-110" comment="Patch 110896-02 or later installed" negate="true"/>
          <criterion test_ref="spt-111" comment="Patch 114008-01 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-203" comment="inetd.conf contains cachefsd" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL4345" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Windows Shell</product>
      </affected>
      <dates>
        <submitted date="2004-10-14-03:38">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <status_change date="2004-10-20-02:35">DRAFT</status_change>
        <status_change date="2004-11-03-12:00">INTERIM</status_change>
        <status_change date="2004-12-09-08:46">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in Microsoft Internet Explorer and Explorer on Windows XP SP1, WIndows 2000, Windows 98, and Windows Me may allow remote malicious servers to cause a denial of service (application crash) and possibly execute arbitrary code via long share names, as demonstrated using Samba.</description>
      <reference source="CVE">CVE-2004-0214</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
          <criterion test_ref="wft-499" comment="the version of shell32.dll is less than 5.0.3900.6970" negate="false"/>
          <criterion test_ref="wrt-537" comment="the patch q841356 is installed (Hotfix key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL4363" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Internet Explorer 5.01 Service Pack 3</product>
      </affected>
      <dates>
        <submitted date="2005-01-18-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2005-01-20-02:31">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 6.x allows remote attackers to install arbitrary programs via mousedown events that call the Popup.show method and use drag-and-drop actions in a popup window, aka "HijackClick 3" and the "Script in Image Tag File Download Vulnerability."</description>
      <reference source="CVE">CVE-2004-0841</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-55" comment="Internet Explorer 5.01 Service Pack 3 is installed" negate="false"/>
          <criterion test_ref="wft-560" comment="the version of mshtml.dll is less than 5.0.3821.2800" negate="false"/>
          <criterion test_ref="wrt-559" comment="the patch kb834707-ie501sp3 is installed (Hotfix key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL4368" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Local Security Authority Subsystem Service (LSASS)</product>
      </affected>
      <dates>
        <submitted date="2004-12-28-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2005-01-12-12:41">DRAFT</status_change>
        <status_change date="2005-02-02-12:00">INTERIM</status_change>
        <status_change date="2005-02-23-09:25">ACCEPTED</status_change>
      </dates>
      <description>LSASS (Local Security Authority Subsystem Service) of Windows 2000 Server and Windows Server 2003 does not properly validate connection information, which allows local users to gain privileges via a specially-designed program.</description>
      <reference source="CVE">CVE-2004-0894</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1058" comment="Windows XP 32-bit edition is installed" negate="false"/>
          <criterion test_ref="wrt-250" comment="Win2K/XP/2003 service pack 2 is installed" negate="false"/>
          <criterion test_ref="wft-327" comment="the version of lsasrv.dll is less than 5.1.2600.2525" negate="false"/>
          <criterion test_ref="wrt-36" comment="the patch kb885835is installed (Hotfix key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL4372" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>Windows Internet Naming Service (WINS)</product>
      </affected>
      <dates>
        <submitted date="2004-12-16-12:00">
          <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
        </submitted>
        <status_change date="2005-01-24-12:00">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-12:00">ACCEPTED</status_change>
        <modified date="2005-06-02-12:00" comment="Added product">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-06-08-03:17">INTERIM</status_change>
        <status_change date="2005-06-29-06:49">ACCEPTED</status_change>
      </dates>
      <description>The WINS service (wins.exe) on Microsoft Windows NT Server 4.0, Windows 2000 Server, and Windows Server 2003 allows remote attackers to write to arbitrary memory locations and possibly execute arbitrary code via a modified memory pointer in a WINS replication packet to TCP port 42, aka the "Association Context Vulnerability."</description>
      <reference source="CVE">CVE-2004-1080</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-45" comment="Windows NT Server 4.0, Terminal Server Edition is installed" negate="false"/>
          <criterion test_ref="wft-165" comment="the version of wins.exe is less than 4.0.1381.33618" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-98" comment="the wins service is enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL4374" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>CDE</product>
      </affected>
      <dates>
        <submitted date="2005-02-01-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-02-01-08:41">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in TT_SESSION environment variable in ToolTalk shared library allows local users to gain root privileges.</description>
      <reference source="CVE">CVE-1999-0693</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="sat-47" comment="CDE Desktop Window Manager (SUNWdtwm) installed" negate="false"/>
          <criterion test_ref="spt-108" comment="Patch 107893-05 or later installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL4383" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>lpstat</product>
      </affected>
      <dates>
        <submitted date="2005-02-01-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-02-01-08:41">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Stack-based buffer overflow in the bsd_queue() function for lpq on Solaris 2.6 and 7 allows local users to gain root privilege.</description>
      <reference source="CVE">CVE-2003-0091</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="sat-43" comment="SunSoft Print - Client - Usr (SUNWpcu) installed" negate="false"/>
          <criterion test_ref="spt-112" comment="Patch 107115-12 or later installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL4384" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Message Queuing</product>
      </affected>
      <dates>
        <submitted date="2005-05-02-12:00">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </submitted>
        <status_change date="2005-05-04-12:32">DRAFT</status_change>
        <status_change date="2005-06-01-03:30">INTERIM</status_change>
        <status_change date="2005-06-22-12:38">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the Message Queuing component of Microsoft Windows 2000 and Windows XP SP1 allows remote attackers to execute arbitrary code via a crafted message.</description>
      <reference source="CVE">CVE-2005-0059</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-313" comment="Windows XP Service Pack 1" negate="false"/>
          <criterion test_ref="wft-577" comment="the version of mqrt.dll is less than 5.1.0.1044" negate="false"/>
          <criterion test_ref="wrt-426" comment="the patch KB892944 is installed (Hotfix key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-425" comment="Message Queuing Enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL4392" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Network News Transport Protocol (NNTP)</product>
      </affected>
      <dates>
        <submitted date="2004-10-14-08:47">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2004-10-20-02:35">DRAFT</status_change>
        <status_change date="2004-11-03-12:00">INTERIM</status_change>
        <status_change date="2004-12-09-08:46">ACCEPTED</status_change>
      </dates>
      <description>The Network News Transfer Protocol (NNTP) component of Microsoft Windows NT Server 4.0, Windows 2000 Server, Windows Server 2003, Exchange 2000 Server, and Exchange Server 2003 allows remote attackers to execute arbitrary code via XPAT patterns, possibly related to improper length validation and an "unchecked buffer," leading to off-by-one and heap-based buffer overflows.</description>
      <reference source="CVE">CVE-2004-0574</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wft-506" comment="the version of nntpsvc.dll is less than 6.0.3790.206" negate="false"/>
          <criterion test_ref="wrt-552" comment="the patch WindowsServer2003-KB883935-x86-enu.exe is installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-326" comment="the NNTP service is enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL4397" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Windows kernel</product>
      </affected>
      <dates>
        <submitted date="2005-05-02-12:00">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </submitted>
        <status_change date="2005-05-04-12:00">DRAFT</status_change>
        <status_change date="2005-06-01-12:00">INTERIM</status_change>
        <modified date="2005-06-02-12:00" comment="Added product">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-06-22-12:38">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to cause a denial of service (i.e., system crash) via a malformed request, aka "Object Management Vulnerability".</description>
      <reference source="CVE">CVE-2005-0550</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-2" comment="Windows XP is installed" negate="false"/>
          <criterion test_ref="wrt-427" comment="the patch KB890859 is installed (Hotfix key)" negate="true"/>
          <criterion test_ref="cmp-328" comment="Windows No Service Pack or Service Pack 1 and Ntoskrnl.exe version less than 5.1.2600.1634" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL4403" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>mozilla</product>
      </affected>
      <dates>
        <submitted date="2005-01-19-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-24-03:40">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, allow remote web sites to install arbitrary extensions by using interactive events to manipulate the XPInstall Security dialog box.</description>
      <reference source="CVE">CVE-2004-0762</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" negate="false"/>
          <criterion test_ref="cmp-72" comment="Mozilla components (any SUNWmoznav/SUNWmozmail) installed" negate="false"/>
          <criterion test_ref="spt-46" comment="Patch 117765-02 or later installed" negate="true"/>
          <criterion test_ref="spt-47" comment="Patch 117767-02 or later installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL4416" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Apache</product>
      </affected>
      <dates>
        <submitted date="2004-10-14-01:14">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <modified date="2004-10-18-03:15" comment="Change apache test to file test">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </modified>
        <modified date="2004-10-19-11:19" comment="Changed apache test to package test">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </modified>
        <status_change date="2004-10-20-02:35">DRAFT</status_change>
        <status_change date="2004-11-03-12:00">INTERIM</status_change>
        <status_change date="2004-12-09-08:46">ACCEPTED</status_change>
      </dates>
      <description>mod_digest for Apache before 1.3.31 does not properly verify the nonce of a client response by using a AuthNonce secret.</description>
      <reference source="CVE">CVE-2003-0987</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" negate="false"/>
          <criterion test_ref="spt-253" comment="Patch 116973-01 or later installed" negate="true"/>
          <criterion test_ref="spt-254" comment="Patch 113146-05 or later installed" negate="true"/>
          <criterion test_ref="sat-5" comment="Apache (SUNWapchu) installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-10" comment="Apache running (httpd)" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL4430" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>Solaris Enterprise Authentication Mechanism (SEAM)</product>
      </affected>
      <dates>
        <submitted date="2005-01-19-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-24-03:40">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>The Key Distribution Center (KDC) in Kerberos 5 (krb5) 1.2.7 and earlier allows remote, authenticated attackers to cause a denial of service (crash) on KDCs within the same realm using a certain protocol request that causes the KDC to corrupt its heap (aka "buffer underrun").</description>
      <reference source="CVE">CVE-2003-0082</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <notes>
        <note>Vulnerability exists in standard Solaris kerberos and SEAM.  This definition only covers SEAM</note>
      </notes>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" negate="false"/>
          <criterion test_ref="sat-29" comment="Sun Enterprise Authentication Mechanism (SEAM, SUNWkr5sv) installed" negate="false"/>
          <criterion test_ref="cmp-73" comment="Patches 112536-04 and 110057-07 or later installed" negate="true"/>
          <criterion test_ref="spt-51" comment="Patch 110060-04 or later installed" negate="true"/>
          <criterion test_ref="spt-52" comment="Patch 116462-01 or later installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL4458" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Windows kernel</product>
      </affected>
      <dates>
        <submitted date="2005-01-05-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2005-01-06-09:33">DRAFT</status_change>
        <status_change date="2005-02-02-12:00">INTERIM</status_change>
        <status_change date="2005-02-23-09:25">ACCEPTED</status_change>
      </dates>
      <description>The Local Procedure Call (LPC) interface of the Windows Kernel for Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 does not properly validate the lengths of messages sent to the LPC port, which allows local users to gain privileges, aka "Windows Kernel Vulnerability."</description>
      <reference source="CVE">CVE-2004-0893</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wft-160" comment="the version of lsasrv.dll is less than 5.2.3790.220" negate="false"/>
          <criterion test_ref="wrt-36" comment="the patch kb885835is installed (Hotfix key)" negate="true"/>
          <criterion test_ref="cmp-34" comment="Microsoft Windows Server 2003 64-Bit Edition " negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL4492" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 98</windows:platform>
        <windows:platform>Microsoft Windows ME</windows:platform>
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Adobe Acrobat Reader</product>
      </affected>
      <dates>
        <submitted date="2005-04-26-12:00">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </submitted>
        <status_change date="2005-04-27-12:06">DRAFT</status_change>
        <status_change date="2005-06-01-03:30">INTERIM</status_change>
        <status_change date="2005-06-22-12:38">ACCEPTED</status_change>
      </dates>
      <description>Multiple buffer overflows in libpng 1.2.5 and earlier, as used in multiple products, allow remote attackers to execute arbitrary code via malformed PNG images in which (1) the png_handle_tRNS function does not properly validate the length of transparency chunk (tRNS) data, or the (2) png_handle_sBIT or (3) png_handle_hIST functions do not perform sufficient bounds checking.</description>
      <reference source="CVE">CVE-2004-0597</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-301" comment="the software Adobe Acrobat Reader major version 6, minor version less than 3 is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL4493" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Program Group Converter</product>
      </affected>
      <dates>
        <submitted date="2004-10-14-03:39">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <status_change date="2004-10-20-02:35">DRAFT</status_change>
        <status_change date="2004-11-03-12:00">INTERIM</status_change>
        <status_change date="2004-12-09-08:46">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the Windows Program Group Converter (grpconv.exe) may allow remote attackers to execute arbitrary code via a shell: URL with a long filename and a .grp extension, which is not properly handled when the shell capability launches grpconv.exe.</description>
      <reference source="CVE">CVE-2004-0572</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wrt-70" comment="64-Bit version of Windows is installed" negate="false"/>
          <criterion test_ref="cmp-1137" comment="a vulnerable version of grpconv.exe exists" negate="false"/>
          <criterion test_ref="wrt-537" comment="the patch q841356 is installed (Hotfix key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL4499" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>unknown</product>
      </affected>
      <dates>
        <submitted date="2005-03-29-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2005-03-29-08:38">DRAFT</status_change>
        <status_change date="2005-04-13-12:15">INTERIM</status_change>
        <status_change date="2005-05-04-12:33">ACCEPTED</status_change>
      </dates>
      <description>The OLE component in Windows 98, 2000, XP, and Server 2003, and Exchange Server 5.0 through 2003, does not properly validate the lengths of messages for certain OLE data, which allows remote attackers to execute arbitrary code, aka the "Input Validation Vulnerability."</description>
      <reference source="CVE">CVE-2005-0044</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-61" comment="Windows XP SP1 OR Windows XP 64-bit SP1 is installed" negate="false"/>
          <criterion test_ref="wft-387" comment="the version of ole32.dll is less than 5.1.2600.1619" negate="false"/>
          <criterion test_ref="wrt-91" comment="the patch KB873333 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL4508" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>HyperTerminal</product>
      </affected>
      <dates>
        <submitted date="2004-12-21-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2005-01-18-12:00">DRAFT</status_change>
        <status_change date="2005-02-02-12:00">INTERIM</status_change>
        <modified date="2005-03-02-12:00" comment="modified wft-263 - access DLL via HKLM">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </modified>
        <status_change date="2005-03-23-08:09">ACCEPTED</status_change>
      </dates>
      <description>HyperTerminal application for Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 does not properly validate the length of a value that is saved in a session file, which allows remote attackers to execute arbitrary code via a malicious HyperTerminal session file (.ht), web site, or Telnet URL contained in an e-mail message, triggering a buffer overflow.</description>
      <reference source="CVE">CVE-2004-0568</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wft-263" comment="the version of hypertrm.dll is less than 4.0.1381.842" negate="false"/>
          <criterion test_ref="wrt-47" comment="the patch NT Server kb873339 is installed " negate="true"/>
          <criterion test_ref="cmp-45" comment="Windows NT Server 4.0, Terminal Server Edition is installed" negate="false"/>
        </software>
        <configuration operation="OR">
          <criterion test_ref="wrt-39" comment="If key present hyperterminal will automatically open session files" negate="false"/>
          <criterion test_ref="wrt-67" comment="If the Hyperterminal client is registered as the default telnet client" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL4549" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Word 2003</product>
      </affected>
      <dates>
        <submitted date="2005-08-18-04:00">
          <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
        </submitted>
        <status_change date="2005-08-25-10:05">DRAFT</status_change>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Windows XP SP2 and earlier, 2000 SP3 and SP4, Server 2003, and older operating systems allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted IP packets with malformed options, aka the "IP Validation Vulnerability."</description>
      <reference source="CVE">CVE-2005-0048</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="cmp-23" comment="32-bit version of Windows or 64-bit (itanium architecture) version of Windows is installed" negate="false"/>
          <criterion test_ref="wft-600" comment="the version of Tcpip.sys is less than 5.2.3790.336" negate="false"/>
          <criterion test_ref="wrt-3" comment="a Win2K/XP/2003 service pack is installed" negate="true"/>
          <criterion test_ref="wrt-443" comment="the patch KB893066 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL4561" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>kernel</product>
      </affected>
      <dates>
        <submitted date="2005-04-13-04:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-04-20-04:00">DRAFT</status_change>
        <status_change date="2005-05-11-04:00">INTERIM</status_change>
        <status_change date="2005-06-01-04:00">ACCEPTED</status_change>
        <status_change date="2005-08-25-10:03">INTERIM</status_change>
        <status_change date="2005-08-25-10:05">DRAFT</status_change>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Unknown vulnerability in Solaris 2.6 through 9 causes a denial of service (system panic) via "a rare race condition" or an attack by local users.</description>
      <reference source="CVE">CVE-2003-0669</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" negate="false"/>
          <criterion test_ref="spt-92" comment="Patch 106541-25 or later installed" negate="true"/>
          <criterion test_ref="spt-93" comment="Patch 108528-19 or later installed" negate="true"/>
          <criterion test_ref="spt-94" comment="Patch 112233-05 or later installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL4574" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Sun Cluster</product>
      </affected>
      <dates>
        <submitted date="2004-10-19-03:10">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2004-10-20-02:35">DRAFT</status_change>
        <status_change date="2004-11-03-12:00">INTERIM</status_change>
        <status_change date="2004-12-09-08:46">ACCEPTED</status_change>
      </dates>
      <description>OpenSSL 0.9.6 and 0.9.7 does not properly track the number of characters in certain ASN.1 inputs, which allows remote attackers to cause a denial of service (crash) via an SSL client certificate that causes OpenSSL to read past the end of a buffer when the long form is used.</description>
      <reference source="CVE">CVE-2003-0544</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" negate="false"/>
          <criterion test_ref="spt-266" comment="Patch 113505-02 or later installed" negate="true"/>
          <criterion test_ref="spt-267" comment="Patch 113508-02 or later installed" negate="true"/>
          <criterion test_ref="spt-268" comment="Patch 115054-01 or later installed" negate="true"/>
          <criterion test_ref="spt-269" comment="Patch 115055-01 or later installed" negate="true"/>
          <criterion test_ref="sat-8" comment="SunCluster Component SUNWscvw installed" negate="false"/>
          <criterion test_ref="sat-5" comment="Apache (SUNWapchu) installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-13" comment="Apache running with SunPlex Manager config" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL4576" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>Microsoft Word for Windows 6.0 Converter</product>
      </affected>
      <dates>
        <submitted date="2005-01-05-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2005-01-06-09:33">DRAFT</status_change>
        <status_change date="2005-02-02-12:00">INTERIM</status_change>
        <status_change date="2005-02-23-09:25">ACCEPTED</status_change>
        <modified date="2005-12-20-07:05" comment="Edited criteria. 1) dropped explicit check for Hotfix kb885836, 2) check version of wordpad.exe rather than mswrd wpc files.">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </modified>
        <status_change date="2006-01-04-08:04">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Word for Windows 6.0 Converter (MSWRD632.WPC), as used in WordPad, does not properly validate certain data lengths, which allows remote attackers to execute arbitrary code via a .wri, .rtf, and .doc file sent by email or malicious web site, aka "Font Conversion Vulnerability," a different vulnerability than CVE-2004-0571.</description>
      <reference source="CVE">CVE-2004-0901</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-45" comment="Windows NT Server 4.0, Terminal Server Edition is installed" negate="false"/>
          <criterion test_ref="wft-711" comment="the version of wordpad.exe is less than 4.0.1381.33598" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL4592" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>NetDDE</product>
      </affected>
      <dates>
        <submitted date="2004-10-14-04:38">
          <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
        </submitted>
        <status_change date="2004-10-20-02:35">DRAFT</status_change>
        <status_change date="2004-11-03-12:00">INTERIM</status_change>
        <status_change date="2004-12-09-08:46">ACCEPTED</status_change>
      </dates>
      <description>Network Dynamic Data Exchange (NetDDE) services for Microsoft Windows 98, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows attackers to remotely execute arbitrary code or locally gain privileges via a malicious message or application that involves an "unchecked buffer," possibly a buffer overflow.</description>
      <reference source="CVE">CVE-2004-0206</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wrt-72" comment="32-Bit version of Windows is installed" negate="false"/>
          <criterion test_ref="wft-540" comment="the version of nddenb32.dll is less than 5.2.3790.173" negate="false"/>
          <criterion test_ref="wft-541" comment="the version of netdde.exe is less than 5.2.3790.184" negate="false"/>
          <criterion test_ref="wrt-551" comment="the patch KB841533 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL4593" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Windows kernel</product>
      </affected>
      <dates>
        <submitted date="2005-05-02-12:00">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </submitted>
        <status_change date="2005-05-04-12:00">DRAFT</status_change>
        <status_change date="2005-06-01-12:00">INTERIM</status_change>
        <modified date="2005-06-02-12:00" comment="Added product">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <modified date="2005-06-17-12:00" comment="modified cmp-1106 - Replaced the test that checks for the service pack level, instead of checking for sp4 or ealier (did not check for GOLD edition) it is now negating the test that checks for sp5 for later.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <status_change date="2005-07-27-10:37">ACCEPTED</status_change>
      </dates>
      <description>The kernel of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via certain access requests.</description>
      <reference source="CVE">CVE-2005-0061</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1106" comment="Windows 2000 (sp4 or earlier) is installed" negate="false"/>
          <criterion test_ref="wft-579" comment="The version of Ntoskrnl.exe is less than 5.0.2195.7035" negate="false"/>
          <criterion test_ref="wrt-427" comment="the patch KB890859 is installed (Hotfix key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL4629" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>mozilla</product>
      </affected>
      <dates>
        <submitted date="2005-01-19-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-24-03:40">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Integer overflow in the SOAPParameter object constructor in (1) Netscape version 7.0 and 7.1 and (2) Mozilla 1.6, and possibly earlier versions, allows remote attackers to execute arbitrary code.</description>
      <reference source="CVE">CVE-2004-0722</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" negate="false"/>
          <criterion test_ref="cmp-72" comment="Mozilla components (any SUNWmoznav/SUNWmozmail) installed" negate="false"/>
          <criterion test_ref="spt-46" comment="Patch 117765-02 or later installed" negate="true"/>
          <criterion test_ref="spt-47" comment="Patch 117767-02 or later installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL4661" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Kerberos5</product>
      </affected>
      <dates>
        <submitted date="2004-10-12-03:18">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2004-10-13-01:16">DRAFT</status_change>
        <status_change date="2004-10-27-12:00">INTERIM</status_change>
        <status_change date="2004-11-17-10:00">ACCEPTED</status_change>
      </dates>
      <description>Double-free vulnerabilities in error handling code in krb524d for MIT Kerberos 5 (krb5) 1.2.8 and earlier may allow remote attackers to execute arbitrary code.</description>
      <reference source="CVE">CVE-2004-0772</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-6" comment="Solaris 9 Installed" negate="false"/>
          <criterion test_ref="uft-25" comment="Kerberos 5 installed" negate="false"/>
          <criterion test_ref="spt-250" comment="Patch 112908-15 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-12" comment="Kerberos Key Distribution Center (krb5kdc) running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL4670" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Apache</product>
      </affected>
      <dates>
        <submitted date="2004-10-14-01:13">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <modified date="2004-10-18-03:16" comment="Changes apache test to file test">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </modified>
        <modified date="2004-10-19-11:19" comment="Changed apache test to package test">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </modified>
        <status_change date="2004-10-20-02:35">DRAFT</status_change>
        <status_change date="2004-11-03-12:00">INTERIM</status_change>
        <status_change date="2004-12-09-08:46">ACCEPTED</status_change>
      </dates>
      <description>mod_access in Apache 1.3 before 1.3.30, when running big-endian 64-bit platforms, does not properly parse Allow/Deny rules using IP addresses without a netmask, which could allow remote attackers to bypass intended access restrictions.</description>
      <reference source="CVE">CVE-2003-0993</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" negate="false"/>
          <criterion test_ref="spt-253" comment="Patch 116973-01 or later installed" negate="true"/>
          <criterion test_ref="spt-254" comment="Patch 113146-05 or later installed" negate="true"/>
          <criterion test_ref="sat-5" comment="Apache (SUNWapchu) installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-10" comment="Apache running (httpd)" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL4671" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Cursor and Icon Formatting</product>
      </affected>
      <dates>
        <submitted date="2005-01-14-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2005-01-20-12:00">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-12:00">ACCEPTED</status_change>
        <modified date="2005-06-17-12:00" comment="modified cmp-1106 - Replaced the test that checks for the service pack level, instead of checking for sp4 or ealier (did not check for GOLD edition) it is now negating the test that checks for sp5 for later.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <status_change date="2005-06-22-12:35">INTERIM</status_change>
        <status_change date="2005-07-27-10:37">ACCEPTED</status_change>
      </dates>
      <description>Integer overflow in the LoadImage API of the USER32 Lib for Microsoft Windows allows remote attackers to execute arbitrary code via a .bmp, .cur, .ico or .ani file with a large image size field, which leads to a buffer overflow, aka the "Cursor and Icon Format Handling Vulnerability."</description>
      <reference source="CVE">CVE-2004-1049</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1106" comment="Windows 2000 (sp4 or earlier) is installed" negate="false"/>
          <criterion test_ref="wft-353" comment="the version of user32.dll is less than 5.0.2195.7017" negate="false"/>
          <criterion test_ref="wrt-68" comment="the patch kb891711 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL4674" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Internet Explorer 6.0</product>
      </affected>
      <dates>
        <submitted date="2005-05-10-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2005-05-11-05:38">DRAFT</status_change>
        <status_change date="2005-06-01-03:30">INTERIM</status_change>
        <status_change date="2005-06-22-12:38">ACCEPTED</status_change>
        <modified date="2005-09-26-12:44" comment="modified wft-594 - Changed comment to match test">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-28-01:04">INTERIM</status_change>
        <status_change date="2005-10-19-05:47">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the Content Advisor in Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a crafted Content Advisor file, aka "Content Advisor Memory Corruption Vulnerability."</description>
      <reference source="CVE">CVE-2005-0555</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-51" comment="Internet Explorer 6  for Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wft-594" comment="the version of mshtml.dll is less than 6.0.3790.279" negate="false"/>
          <criterion test_ref="wrt-438" comment="the patch kb890923 is installed (Hotfix key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL4702" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Internet Explorer 5.01 Service Pack 4</product>
      </affected>
      <dates>
        <submitted date="2004-10-19-07:27">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2004-10-20-02:35">DRAFT</status_change>
        <status_change date="2004-11-03-12:00">INTERIM</status_change>
        <status_change date="2004-12-09-08:46">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Internet Explorer 6.0.2800.1106 on Microsoft Windows XP SP2, and other versions including 5.01 and 5.5, allows remote web servers to bypass zone restrictions and execute arbitrary code in the local computer zone by redirecting a function to another function with the same name, as demonstrated by SimilarMethodNameRedir, aka the "Similar Method Name Redirection Cross Domain Vulnerability."</description>
      <reference source="CVE">CVE-2004-0727</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-54" comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false"/>
          <criterion test_ref="wft-561" comment="the version of mshtml.dll is less than 5.0.3534.2800" negate="false"/>
          <criterion test_ref="wrt-560" comment="the patch kb834707-ie501sp4 is installed (Hotfix key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL4706" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Help and Support Center (HSC)</product>
      </affected>
      <dates>
        <submitted date="2005-01-18-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2005-01-20-02:31">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Stack-based buffer overflow in the PCHealth system in the Help and Support Center function in Windows XP and Windows Server 2003 allows remote attackers to execute arbitrary code via a long query in an HCP URL.</description>
      <reference source="CVE">CVE-2003-0711</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1111" comment="Windows Server 2003 or Windows 64-bit Edition is installed" negate="false"/>
          <criterion test_ref="wft-261" comment="the version of itircl.dll is less than 5.2.3790.80" negate="false"/>
          <criterion test_ref="wrt-308" comment="Patch KB825119 Installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL4710" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Windows Shell</product>
      </affected>
      <dates>
        <submitted date="2005-05-04-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2005-05-04-10:01">DRAFT</status_change>
        <status_change date="2005-06-01-12:00">INTERIM</status_change>
        <modified date="2005-06-17-12:00" comment="modified cmp-1106 - Replaced the test that checks for the service pack level, instead of checking for sp4 or ealier (did not check for GOLD edition) it is now negating the test that checks for sp5 for later.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <status_change date="2005-07-27-10:37">ACCEPTED</status_change>
      </dates>
      <description>The document processing application used by the Windows Shell in Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code by modifying the CLSID stored in a file so that it is processed by HTML Application Host (MSHTA), as demonstrated using a Microsoft Word document.</description>
      <reference source="CVE">CVE-2005-0063</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1106" comment="Windows 2000 (sp4 or earlier) is installed" negate="false"/>
          <criterion test_ref="wft-592" comment="the version of shell32.dll is less than 5.0.3900.7032" negate="false"/>
          <criterion test_ref="wrt-436" comment="the patch  KB893086 is installed " negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-280" comment=".hta applications are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL4726" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Windows Messenger</product>
      </affected>
      <dates>
        <submitted date="2005-03-31-12:00">
          <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
        </submitted>
        <status_change date="2005-04-12-08:26">DRAFT</status_change>
        <status_change date="2005-04-27-12:07">INTERIM</status_change>
        <status_change date="2005-06-01-03:30">ACCEPTED</status_change>
        <modified date="2005-12-26-09:40" comment="Removed test to check kb890047.">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </modified>
        <status_change date="2006-01-12-08:59">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via drag and drop events, aka the "Drag-and-Drop Vulnerability."</description>
      <reference source="CVE">CVE-2005-0053</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-38" comment="Windows Server 2003 or Windows XP 64-Bit Edition Version 2003" negate="false"/>
          <criterion test_ref="wft-401" comment="the version of shell32.dll is less than 6.0.3790.241" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-157" comment="Drag-and-Drop disabled when set to 3" negate="true"/>
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL4728" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>Sun RPC</product>
      </affected>
      <dates>
        <submitted date="2005-01-19-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-24-03:40">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC including dietlibc, allows remote attackers to execute arbitrary code by passing a large number of arguments to xdr_array through RPC services such as rpc.cmsd and dmispd.</description>
      <reference source="CVE">CVE-2002-0391</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <notes>
        <note>Specific applications using this library are not tested for because Suns advisory only provides a sample of known vulnerable applications and states that they are still investigating.</note>
      </notes>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" negate="false"/>
          <criterion test_ref="cmp-63" comment="Patches 106942-22 and 108451-06 or later installed" negate="true"/>
          <criterion test_ref="cmp-205" comment="Patches 108827-30 and 108901-06" negate="true"/>
          <criterion test_ref="cmp-64" comment="Patches 113319-01 and 112233-02 or later installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL4741" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>HyperTerminal</product>
      </affected>
      <dates>
        <submitted date="2004-12-21-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2005-01-18-12:00">DRAFT</status_change>
        <status_change date="2005-02-02-12:00">INTERIM</status_change>
        <modified date="2005-03-02-12:00" comment="modified wft-200 - access DLL via HKLM">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </modified>
        <status_change date="2005-03-23-08:09">ACCEPTED</status_change>
      </dates>
      <description>HyperTerminal application for Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 does not properly validate the length of a value that is saved in a session file, which allows remote attackers to execute arbitrary code via a malicious HyperTerminal session file (.ht), web site, or Telnet URL contained in an e-mail message, triggering a buffer overflow.</description>
      <reference source="CVE">CVE-2004-0568</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
          <criterion test_ref="wrt-538" comment="Win2K/XP/2003 service pack 4 (or earlier) is installed" negate="false"/>
          <criterion test_ref="wft-200" comment="the version of hypertrm.dll is less than 5.0.2195.7000" negate="false"/>
          <criterion test_ref="wrt-46" comment="the patch Windows2000-KB873339-x86-ENU.EXE is installed " negate="true"/>
        </software>
        <configuration operation="OR">
          <criterion test_ref="wrt-39" comment="If key present hyperterminal will automatically open session files" negate="false"/>
          <criterion test_ref="wrt-67" comment="If the Hyperterminal client is registered as the default telnet client" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL4749" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Microsoft Word for Windows 6.0 Converter</product>
      </affected>
      <dates>
        <submitted date="2005-01-05-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2005-01-12-12:41">DRAFT</status_change>
        <status_change date="2005-02-02-12:00">INTERIM</status_change>
        <status_change date="2005-02-23-09:25">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Word for Windows 6.0 Converter (MSWRD632.WPC), as used in WordPad, does not properly validate certain data lengths, which allows remote attackers to execute arbitrary code via a .wri, .rtf, and .doc file sent by email or malicious web site, aka "Font Conversion Vulnerability," a different vulnerability than CVE-2004-0571.</description>
      <reference source="CVE">CVE-2004-0901</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-35" comment="Windows XP 32 bit Service Pack 2" negate="false"/>
          <criterion test_ref="wft-300" comment="the version of mswrd6.wpc is less than 10.0.803.2" negate="false"/>
          <criterion test_ref="wrt-25" comment="the patch kb885836 is installed (Hotfix key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL4756" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>mozilla</product>
      </affected>
      <dates>
        <submitted date="2005-01-19-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-24-03:40">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>The (1) Mozilla 1.6, (2) Firebird 0.7, (3) Firefox 0.8, and (4) Netscape 7.1 web browsers do not properly prevent a frame in one domain from injecting content into a frame that belongs to another domain, which facilitates web site spoofing and other attacks, aka the frame injection vulnerability.</description>
      <reference source="CVE">CVE-2004-0718</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" negate="false"/>
          <criterion test_ref="cmp-72" comment="Mozilla components (any SUNWmoznav/SUNWmozmail) installed" negate="false"/>
          <criterion test_ref="spt-46" comment="Patch 117765-02 or later installed" negate="true"/>
          <criterion test_ref="spt-47" comment="Patch 117767-02 or later installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL4758" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Internet Explorer 6.0</product>
      </affected>
      <dates>
        <submitted date="2005-02-10-12:00">
          <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
        </submitted>
        <status_change date="2005-02-11-12:00">DRAFT</status_change>
        <status_change date="2005-03-02-12:00">INTERIM</status_change>
        <status_change date="2005-03-23-12:00">ACCEPTED</status_change>
        <modified date="2005-06-02-12:00" comment="Added product">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-06-08-03:17">INTERIM</status_change>
        <status_change date="2005-06-29-06:49">ACCEPTED</status_change>
      </dates>
      <description>The DHTML Edit Control (dhtmled.ocx) allows remote attackers to inject arbitrary web script into other domains by setting a name for a window, opening a child page whose target is the window with the given name, then injecting the script from the parent into the child using execScript, as demonstrated by "AbusiveParent" in Internet Explorer 6.0.2900.2180.</description>
      <reference source="CVE">CVE-2004-1319</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-183" comment="Windows Server 2003 64-Bit Edition or Windows XP 64-Bit Edition Version 2003 " negate="false"/>
          <criterion test_ref="wft-378" comment="the version of wdhtmled.ocx is less than 6.1.0.9231" negate="false"/>
          <criterion test_ref="wrt-87" comment="the patch kb891781 is installed (Hotfix key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL4762" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>VDM</product>
      </affected>
      <dates>
        <submitted date="2004-10-13-12:02">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </submitted>
        <status_change date="2004-10-13-01:16">DRAFT</status_change>
        <status_change date="2004-10-27-12:00">INTERIM</status_change>
        <status_change date="2004-11-17-10:00">ACCEPTED</status_change>
      </dates>
      <description>The Virtual DOS Machine (VDM) subsystem of Microsoft Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows local users to access kernel memory and gain privileges via a malicious program that modified some system structures in a way that is not properly validated by privileged operating system functions.</description>
      <reference source="CVE">CVE-2004-0208</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-43" comment="this is an NT Terminal Server" negate="false"/>
          <criterion test_ref="wft-511" comment="the version of gdi32.dll is less than 4.0.1381.33566" negate="false"/>
          <criterion test_ref="wrt-547" comment="the patch KB840987 is installed (Hotfix key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL4767" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>IIS 6.0</product>
      </affected>
      <dates>
        <submitted date="2004-10-13-12:13">
          <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
        </submitted>
        <status_change date="2004-10-13-01:16">DRAFT</status_change>
        <status_change date="2004-10-27-12:00">INTERIM</status_change>
        <status_change date="2004-11-17-10:00">ACCEPTED</status_change>
      </dates>
      <description>The WebDAV Message Handler for Internet Information Services (IIS) 5.0, 5.1, and 6.0 allows remote attackers to cause a denial of service (memory and CPU exhaustion, application crash) via a PROPFIND request with an XML message containing XML elements with a large number of attributes.</description>
      <reference source="CVE">CVE-2003-0718</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wrt-3" comment="a Win2K/XP/2003 service pack is installed" negate="true"/>
          <criterion test_ref="wft-515" comment="the version of httpext.dll is less than 6.0.3790.212" negate="false"/>
          <criterion test_ref="wrt-549" comment="the patch KB824151 is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL4786" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>MDAC 2.8</product>
      </affected>
      <dates>
        <submitted date="2005-03-29-12:00">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </submitted>
        <status_change date="2005-03-29-08:38">DRAFT</status_change>
        <status_change date="2005-04-13-12:15">INTERIM</status_change>
        <status_change date="2005-05-04-12:33">ACCEPTED</status_change>
      </dates>
      <description>The License Logging service for Windows NT Server, Windows 2000 Server, and Windows Server 2003 does not properly validate the length of messages, which leads to an "unchecked buffer" and allows remote attackers to cause a denial of service (crash) and possibly execute arbtirary code, aka the "License Logging Service Vulnerability."</description>
      <reference source="CVE">CVE-2005-0050</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-44" comment="Windows NT Server 4.0 is installed" negate="false"/>
          <criterion test_ref="wrt-96" comment="the patch kb885834 is installed (Hotfix key)" negate="true"/>
          <criterion test_ref="wft-392" comment="the version of Llssrv.exe is less than 4.0.1381.7345" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-344" comment="license logging service is enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL4791" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Windows 2000</product>
      </affected>
      <dates>
        <submitted date="2005-04-22-12:00">
          <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
        </submitted>
        <status_change date="2005-04-27-12:06">DRAFT</status_change>
        <status_change date="2005-06-01-03:30">INTERIM</status_change>
        <status_change date="2005-06-22-12:38">ACCEPTED</status_change>
      </dates>
      <description>TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial of service (connection loss) to persistent TCP connections by repeatedly injecting a TCP RST packet, especially in protocols that use long-lived connections, such as BGP.</description>
      <reference source="CVE">CVE-2004-0230</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-1" comment="Windows 2000 is installed" negate="false"/>
          <criterion test_ref="wrt-538" comment="Win2K/XP/2003 service pack 4 (or earlier) is installed" negate="false"/>
          <criterion test_ref="wft-593" comment="the version of Tcpip.sys is less than 5.0.2195.7035" negate="false"/>
          <criterion test_ref="wrt-443" comment="the patch KB893066 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL4797" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Windows kernel</product>
      </affected>
      <dates>
        <submitted date="2005-05-02-12:00">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </submitted>
        <status_change date="2005-05-04-12:00">DRAFT</status_change>
        <status_change date="2005-06-01-12:00">INTERIM</status_change>
        <modified date="2005-06-02-12:00" comment="Added product">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-06-22-12:38">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the font processing component of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via a specially-designed application.</description>
      <reference source="CVE">CVE-2005-0060</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-2" comment="Windows XP is installed" negate="false"/>
          <criterion test_ref="wrt-427" comment="the patch KB890859 is installed (Hotfix key)" negate="true"/>
          <criterion test_ref="cmp-328" comment="Windows No Service Pack or Service Pack 1 and Ntoskrnl.exe version less than 5.1.2600.1634" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL4804" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Word 2003</product>
      </affected>
      <dates>
        <submitted date="2005-08-18-04:00">
          <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
        </submitted>
        <status_change date="2005-08-25-10:05">DRAFT</status_change>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (reset TCP connections) via spoofed ICMP error messages, aka the "blind connection-reset attack."  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</description>
      <reference source="CVE">CVE-2004-0790</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="cmp-23" comment="32-bit version of Windows or 64-bit (itanium architecture) version of Windows is installed" negate="false"/>
          <criterion test_ref="wft-600" comment="the version of Tcpip.sys is less than 5.2.3790.336" negate="false"/>
          <criterion test_ref="wrt-3" comment="a Win2K/XP/2003 service pack is installed" negate="true"/>
          <criterion test_ref="wrt-443" comment="the patch KB893066 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL4831" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>Windows NT 4.0</product>
      </affected>
      <dates>
        <submitted date="2005-01-03-12:00">
          <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
        </submitted>
        <status_change date="2005-01-12-12:41">DRAFT</status_change>
        <status_change date="2005-02-02-12:00">INTERIM</status_change>
        <status_change date="2005-02-23-09:25">ACCEPTED</status_change>
      </dates>
      <description>The WINS service (wins.exe) on Microsoft Windows NT Server 4.0, Windows 2000 Server, and Windows Server 2003 allows remote attackers to write to arbitrary memory locations and possibly execute arbitrary code via a modified memory pointer in a WINS replication packet to TCP port 42, aka the "Association Context Vulnerability."</description>
      <reference source="CVE">CVE-2004-1080</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-44" comment="Windows NT Server 4.0 is installed" negate="false"/>
          <criterion test_ref="wft-164" comment="the version of wins.exe is less than 4.0.1381.7329" negate="false"/>
          <criterion test_ref="wrt-38" comment="the patch KB870763 is installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-98" comment="the wins service is enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL4832" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Windows kernel</product>
      </affected>
      <dates>
        <submitted date="2005-05-02-12:00">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </submitted>
        <status_change date="2005-05-04-12:00">DRAFT</status_change>
        <status_change date="2005-06-01-12:00">INTERIM</status_change>
        <modified date="2005-06-02-12:00" comment="Added product">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <modified date="2005-06-17-12:00" comment="modified cmp-1106 - Replaced the test that checks for the service pack level, instead of checking for sp4 or ealier (did not check for GOLD edition) it is now negating the test that checks for sp5 for later.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <status_change date="2005-07-27-10:37">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to cause a denial of service (i.e., system crash) via a malformed request, aka "Object Management Vulnerability".</description>
      <reference source="CVE">CVE-2005-0550</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1106" comment="Windows 2000 (sp4 or earlier) is installed" negate="false"/>
          <criterion test_ref="wft-579" comment="The version of Ntoskrnl.exe is less than 5.0.2195.7035" negate="false"/>
          <criterion test_ref="wrt-427" comment="the patch KB890859 is installed (Hotfix key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL4834" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>LDAP</product>
      </affected>
      <dates>
        <submitted date="2005-04-13-04:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-04-20-04:00">DRAFT</status_change>
        <status_change date="2005-05-11-04:00">INTERIM</status_change>
        <status_change date="2005-06-01-04:00">ACCEPTED</status_change>
        <status_change date="2005-08-25-10:03">INTERIM</status_change>
        <status_change date="2005-08-25-10:05">DRAFT</status_change>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Unknown vulnerability in LDAP on Sun Solaris 8 and 9, when using Role Based Access Control (RBAC), allows local users to execute certain commands with additional privileges.</description>
      <reference source="CVE">CVE-2004-1353</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" negate="false"/>
          <criterion test_ref="spt-74" comment="Patch 108993-38 or later installed" negate="true"/>
          <criterion test_ref="spt-75" comment="Patch 112960-17 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="tft-1" comment="/etc/nsswitch.conf configured to use LDAP with RBAC" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL4846" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>DHCP</product>
      </affected>
      <dates>
        <submitted date="2004-12-16-12:00">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </submitted>
        <status_change date="2005-01-12-12:41">DRAFT</status_change>
        <status_change date="2005-02-02-12:00">INTERIM</status_change>
        <status_change date="2005-02-23-09:25">ACCEPTED</status_change>
      </dates>
      <description>The DHCP Server service for Microsoft Windows NT 4.0 Server and Terminal Server Edition does not properly validate the length of certain messages, which allows remote attackers to execute arbitrary code via a malformed DHCP message, aka the "DHCP Request Vulnerability."</description>
      <reference source="CVE">CVE-2004-0900</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" negate="false"/>
          <criterion test_ref="wrt-43" comment="this is an NT Terminal Server" negate="false"/>
          <criterion test_ref="wrt-37" comment="the patch KB885249 is installed (Hotfix key)" negate="true"/>
          <criterion test_ref="wft-162" comment="the version of Dhcpssvc.dll is less than 4.0.1381.33587" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL4859" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>Proxy Server 2.0 SP1</product>
      </affected>
      <dates>
        <submitted date="2004-11-17-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2005-01-12-12:00">DRAFT</status_change>
        <status_change date="2005-02-02-12:00">INTERIM</status_change>
        <modified date="2005-03-01-12:00" comment="modified wft-7 - Corrected path">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <modified date="2005-06-02-12:00" comment="modified wft-7 - corrected object path">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <status_change date="2005-06-22-12:38">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Proxy Server 2.0 and Microsoft ISA Server 2000 (which is included in Small Business Server 2000 and Small Business Server 2003 Premium Edition) allows remote attackers to spoof trusted Internet content on a specially crafted webpage via spoofed reverse DNS lookup results.</description>
      <reference source="CVE">CVE-2004-0892</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-9" comment="Microsoft Proxy Server 2.0 SP1 is installed" negate="false"/>
          <criterion test_ref="wft-7" comment="the version of w3proxy.dll is less than 2.0.390.16" negate="false"/>
          <criterion test_ref="wrt-14" comment="the patch KB888258 for Proxy Server 2.0 is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL4863" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Apache</product>
      </affected>
      <dates>
        <submitted date="2004-10-14-01:12">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <modified date="2004-10-18-03:16" comment="Changed apache test to file test">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </modified>
        <modified date="2004-10-19-11:20" comment="Changed apache test to package test">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </modified>
        <status_change date="2004-10-20-02:35">DRAFT</status_change>
        <status_change date="2004-11-03-12:00">INTERIM</status_change>
        <status_change date="2004-12-09-08:46">ACCEPTED</status_change>
      </dates>
      <description>Heap-based buffer overflow in proxy_util.c for mod_proxy in Apache 1.3.25 to 1.3.31 allows remote attackers to cause a denial of service (process crash) and possibly execute arbitrary code via a negative Content-Length HTTP header field, which causes a large amount of data to be copied.</description>
      <reference source="CVE">CVE-2004-0492</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" negate="false"/>
          <criterion test_ref="spt-253" comment="Patch 116973-01 or later installed" negate="true"/>
          <criterion test_ref="spt-254" comment="Patch 113146-05 or later installed" negate="true"/>
          <criterion test_ref="sat-5" comment="Apache (SUNWapchu) installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-10" comment="Apache running (httpd)" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL4864" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Internet Explorer 5.01 Service Pack 4</product>
      </affected>
      <dates>
        <submitted date="2005-03-17-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2005-03-23-08:09">DRAFT</status_change>
        <status_change date="2005-04-13-12:15">INTERIM</status_change>
        <status_change date="2005-05-04-12:33">ACCEPTED</status_change>
        <modified date="2005-12-26-09:40" comment="Removed test to check kb867282.">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </modified>
        <status_change date="2006-01-12-08:59">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via drag and drop events, aka the "Drag-and-Drop Vulnerability."</description>
      <reference source="CVE">CVE-2005-0053</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-54" comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false"/>
          <criterion test_ref="wft-407" comment="the version of mshtml.dll is less than 5.0.3825.700" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-258" comment="Check for Drag&amp;Drop enabled and the patch kb834707(wildcard*)  missing" negate="false"/>
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL4874" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Internet Explorer 5.01 Service Pack 3</product>
      </affected>
      <dates>
        <submitted date="2005-05-10-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2005-05-11-05:38">DRAFT</status_change>
        <status_change date="2005-06-01-03:30">INTERIM</status_change>
        <status_change date="2005-06-22-12:38">ACCEPTED</status_change>
      </dates>
      <description>Race condition in the memory management routines in the DHTML object processor in Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a malicious web page or HTML e-mail, aka "DHTML Object Memory Corruption Vulnerability".</description>
      <reference source="CVE">CVE-2005-0553</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-55" comment="Internet Explorer 5.01 Service Pack 3 is installed" negate="false"/>
          <criterion test_ref="wft-598" comment="the version of mshtml.dll is less than 5.0.3539.2400" negate="false"/>
          <criterion test_ref="wrt-441" comment="the patch kb890923  is installed (Win2K SP3  Hotfix key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL4893" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Windows kernel</product>
      </affected>
      <dates>
        <submitted date="2004-10-13-11:31">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </submitted>
        <modified date="2004-10-13-11:43" comment="changed OS ">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </modified>
        <status_change date="2004-10-13-01:16">DRAFT</status_change>
        <status_change date="2004-10-27-12:00">INTERIM</status_change>
        <status_change date="2004-11-17-10:00">ACCEPTED</status_change>
      </dates>
      <description>The kernel for Microsoft Windows Server 2003 does not reset certain values in CPU data structures, which allows local users to cause a denial of service (system crash) via a malicious program.</description>
      <reference source="CVE">CVE-2004-0211</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wft-508" comment="the version of win32k.sys is less than 5.2.3790.198" negate="false"/>
          <criterion test_ref="wrt-547" comment="the patch KB840987 is installed (Hotfix key)" negate="true"/>
          <criterion test_ref="cmp-1113" comment="Windows 2003 Server or Windows XP 64-bit" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL4927" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>MSN Messenger</product>
      </affected>
      <dates>
        <submitted date="2005-04-19-12:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2005-04-20-12:13">DRAFT</status_change>
        <status_change date="2005-05-11-05:41">INTERIM</status_change>
        <status_change date="2005-06-01-03:30">ACCEPTED</status_change>
        <modified date="2005-11-24-12:00" comment="Added wrt-620 to see if MSN Messenger 6.2 is installed.  Changed wrt-431 to check 'DisplayVersion' rather than 'MSN Messenger 6.2'.">
          <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
        </modified>
        <status_change date="2005-12-12-09:30">INTERIM</status_change>
        <modified date="2005-12-20-07:05" comment="Added wrt-431.">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </modified>
        <status_change date="2006-01-04-08:04">ACCEPTED</status_change>
      </dates>
      <description>GIF file validation error in MSN Messenger 6.2 allows remote attackers in a user's contact list to execute arbitrary code via a GIF image with an improper height and width.</description>
      <reference source="CVE">CVE-2005-0562</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-620" comment="MSN Messenger 6.2 is installed" negate="false"/>
          <criterion test_ref="wrt-431" comment="MSN Messenger 6.2.0208 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL4936" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Kerberos5</product>
      </affected>
      <dates>
        <submitted date="2004-10-12-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2004-10-13-12:00">DRAFT</status_change>
        <modified date="2005-01-14-12:00" comment="Changed kerberos unknown test to solaris file contents test">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </modified>
        <status_change date="2005-02-02-12:00">INTERIM</status_change>
        <status_change date="2005-02-23-09:25">ACCEPTED</status_change>
      </dates>
      <description>Double-free vulnerabilities in the error handling code for ASN.1 decoders in the (1) Key Distribution Center (KDC) library and (2) client library for MIT Kerberos 5 (krb5) 1.3.4 and earlier may allow remote attackers to execute arbitrary code.</description>
      <reference source="CVE">CVE-2004-0642</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-6" comment="Solaris 9 Installed" negate="false"/>
          <criterion test_ref="uft-25" comment="Kerberos 5 installed" negate="false"/>
          <criterion test_ref="spt-250" comment="Patch 112908-15 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="tft-5" comment="/etc/krb5/krb5.conf is configured with a kerberos domain" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL4947" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Internet Explorer 5.01 Service Pack 4</product>
      </affected>
      <dates>
        <submitted date="2005-03-17-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2005-03-23-08:09">DRAFT</status_change>
        <status_change date="2005-04-13-12:15">INTERIM</status_change>
        <status_change date="2005-05-04-12:33">ACCEPTED</status_change>
        <modified date="2005-12-26-09:40" comment="Removed test to check kb867282.">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </modified>
        <status_change date="2006-01-12-08:59">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 5.01, 5.5, and 6 does not properly validate certain URLs in Channel Definition Format (CDF) files, which allows remote attackers to obtain sensitive information or execute arbitrary code, aka the "Channel Definition Format (CDF) Cross Domain Vulnerability."</description>
      <reference source="CVE">CVE-2005-0056</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-54" comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false"/>
          <criterion test_ref="wft-407" comment="the version of mshtml.dll is less than 5.0.3825.700" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL4978" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Word 2003</product>
      </affected>
      <dates>
        <submitted date="2005-08-18-04:00">
          <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
        </submitted>
        <status_change date="2005-08-25-10:05">DRAFT</status_change>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Windows Server 2003 and XP SP2, with Windows Firewall turned off, allows remote attackers to cause a denial of service (CPU consumption) via a TCP packet with the SYN flag set and the same destination and source address and port, aka a reoccurrence of the "Land" vulnerability (CVE-1999-0016).</description>
      <reference source="CVE">CVE-2005-0688</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="cmp-23" comment="32-bit version of Windows or 64-bit (itanium architecture) version of Windows is installed" negate="false"/>
          <criterion test_ref="wrt-3" comment="a Win2K/XP/2003 service pack is installed" negate="true"/>
          <criterion test_ref="wft-600" comment="the version of Tcpip.sys is less than 5.2.3790.336" negate="false"/>
          <criterion test_ref="wrt-443" comment="the patch KB893066 is installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-448" comment="The SynAttackProtect parameter is set to 2" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL4985" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Internet Explorer 5.01 Service Pack 4</product>
      </affected>
      <dates>
        <submitted date="2005-05-10-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2005-05-11-05:38">DRAFT</status_change>
        <status_change date="2005-06-01-03:30">INTERIM</status_change>
        <status_change date="2005-06-22-12:38">ACCEPTED</status_change>
      </dates>
      <description>Race condition in the memory management routines in the DHTML object processor in Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a malicious web page or HTML e-mail, aka "DHTML Object Memory Corruption Vulnerability".</description>
      <reference source="CVE">CVE-2005-0553</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-54" comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false"/>
          <criterion test_ref="wft-599" comment="the version of mshtml.dll is less than 5.0.3826.2400" negate="false"/>
          <criterion test_ref="wrt-442" comment="the patch kb890923 is installed (Win2K SP4  Hotfix key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL4987" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>MDAC 2.7</product>
      </affected>
      <dates>
        <submitted date="2005-03-31-12:00">
          <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
        </submitted>
        <status_change date="2005-04-12-08:26">DRAFT</status_change>
        <status_change date="2005-04-27-12:07">INTERIM</status_change>
        <status_change date="2005-06-01-03:30">ACCEPTED</status_change>
      </dates>
      <description>The Microsoft .NET forms authentication capability for ASP.NET allows remote attackers to bypass authentication for .aspx files in restricted directories via a request containing a (1) "\" (backslash) or (2) "%5C" (encoded backslash), aka "Path Validation Vulnerability."</description>
      <reference source="CVE">CVE-2004-0847</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-116" comment="Is the .NET Framework 1.0 installed" negate="false"/>
          <criterion test_ref="cmp-252" comment="A vulnerable version of .NET Framework v1.0 is installed. " negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL4988" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Message Queuing</product>
      </affected>
      <dates>
        <submitted date="2005-05-02-12:00">
          <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
        </submitted>
        <status_change date="2005-05-04-12:00">DRAFT</status_change>
        <status_change date="2005-06-01-12:00">INTERIM</status_change>
        <modified date="2005-06-02-12:00" comment="Added product">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <modified date="2005-06-17-12:00" comment="modified cmp-1106 - Replaced the test that checks for the service pack level, instead of checking for sp4 or ealier (did not check for GOLD edition) it is now negating the test that checks for sp5 for later.">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </modified>
        <status_change date="2005-07-27-10:37">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the Message Queuing component of Microsoft Windows 2000 and Windows XP SP1 allows remote attackers to execute arbitrary code via a crafted message.</description>
      <reference source="CVE">CVE-2005-0059</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1106" comment="Windows 2000 (sp4 or earlier) is installed" negate="false"/>
          <criterion test_ref="wft-576" comment="the version of mqrt.dll is less than 5.0.0.799" negate="false"/>
          <criterion test_ref="wrt-426" comment="the patch KB892944 is installed (Hotfix key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL5021" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Network News Transport Protocol (NNTP)</product>
      </affected>
      <dates>
        <submitted date="2004-10-13-12:21">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2004-10-13-01:16">DRAFT</status_change>
        <status_change date="2004-10-27-12:00">INTERIM</status_change>
        <status_change date="2004-11-17-10:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the converter for Microsoft WordPerfect 5.x on Office 2000, Office XP, Office 2003, and Works Suites 2001 through 2004 allows remote attackers to execute arbitrary code via a malicious document or website.</description>
      <reference source="CVE">CVE-2004-0573</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wrt-70" comment="64-Bit version of Windows is installed" negate="false"/>
          <criterion test_ref="wft-506" comment="the version of nntpsvc.dll is less than 6.0.3790.206" negate="false"/>
          <criterion test_ref="wrt-548" comment="the patch WindowsServer2003-KB883935-ia64-enu.exe is installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-326" comment="the NNTP service is enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL5070" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>Network News Transport Protocol (NNTP)</product>
      </affected>
      <dates>
        <submitted date="2004-10-14-01:15">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2004-10-20-02:35">DRAFT</status_change>
        <status_change date="2004-11-03-12:00">INTERIM</status_change>
        <status_change date="2004-12-09-08:46">ACCEPTED</status_change>
      </dates>
      <description>The Network News Transfer Protocol (NNTP) component of Microsoft Windows NT Server 4.0, Windows 2000 Server, Windows Server 2003, Exchange 2000 Server, and Exchange Server 2003 allows remote attackers to execute arbitrary code via XPAT patterns, possibly related to improper length validation and an "unchecked buffer," leading to off-by-one and heap-based buffer overflows.</description>
      <reference source="CVE">CVE-2004-0574</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" negate="false"/>
          <criterion test_ref="wft-539" comment="the version of nntpsvc.dll is less than 5.5.1877.79" negate="false"/>
          <criterion test_ref="wrt-556" comment="Patch WindowsNT4OptionPack-KB883935-x86-enu.EXE" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-326" comment="the NNTP service is enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL5074" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>NetDDE</product>
      </affected>
      <dates>
        <submitted date="2004-10-14-05:10">
          <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
        </submitted>
        <status_change date="2004-10-20-02:35">DRAFT</status_change>
        <status_change date="2004-11-03-12:00">INTERIM</status_change>
        <status_change date="2004-12-09-08:46">ACCEPTED</status_change>
      </dates>
      <description>Network Dynamic Data Exchange (NetDDE) services for Microsoft Windows 98, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows attackers to remotely execute arbitrary code or locally gain privileges via a malicious message or application that involves an "unchecked buffer," possibly a buffer overflow.</description>
      <reference source="CVE">CVE-2004-0206</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-2" comment="Windows XP is installed" negate="false"/>
          <criterion test_ref="wrt-72" comment="32-Bit version of Windows is installed" negate="false"/>
          <criterion test_ref="wrt-29" comment="Win2K/XP/2003 service pack 2 (or later) is installed" negate="true"/>
          <criterion test_ref="cmp-1147" comment="a vulnerable version of nddenb32.dll exists" negate="false"/>
          <criterion test_ref="cmp-1150" comment="a vulnerable version of netdde.exe exists" negate="false"/>
          <criterion test_ref="wrt-551" comment="the patch KB841533 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL5141" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>CDE</product>
      </affected>
      <dates>
        <submitted date="2005-01-19-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-24-12:00">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-12:00">ACCEPTED</status_change>
        <modified date="2005-06-02-12:00" comment="Added product">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-06-08-03:17">INTERIM</status_change>
        <status_change date="2005-06-29-06:49">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in CDE libDtHelp library allows local users to execute arbitrary code via (1) a modified DTHELPUSERSEARCHPATH environment variable and the Help feature, (2) DTSEARCHPATH, or (3) LOGNAME.</description>
      <reference source="CVE">CVE-2003-0834</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" negate="false"/>
          <criterion test_ref="cmp-82" comment="CDE Application Runtime or CDE Separable Help (any SUNWdtbas/SUNWdtbax/SUNWdthep) installed " negate="false"/>
          <criterion test_ref="spt-256" comment="Patch 107178-03 or later installed" negate="true"/>
          <criterion test_ref="spt-257" comment="Patch 108949-08 or later installed" negate="true"/>
          <criterion test_ref="spt-258" comment="Patch 116308-01 or later installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL5150" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Internet Explorer 5.01 Service Pack 4</product>
      </affected>
      <dates>
        <submitted date="2005-01-18-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2005-01-20-02:31">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 5.01, 5.5, and 6 does not properly cache SSL content, which allows remote attackers to obtain information or spoof content via a web site with the same host name as the target web site, whose content is cached and reused when the user visits the target web site.</description>
      <reference source="CVE">CVE-2004-0845</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-54" comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false"/>
          <criterion test_ref="wft-561" comment="the version of mshtml.dll is less than 5.0.3534.2800" negate="false"/>
          <criterion test_ref="wrt-560" comment="the patch kb834707-ie501sp4 is installed (Hotfix key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-567" comment="Users not saving encrypted pages to disk  (DisableCachingOfSSLPages)" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL5277" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <product>Remote Procedure Call (RPC)</product>
      </affected>
      <dates>
        <submitted date="2004-10-18-11:46">
          <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
        </submitted>
        <status_change date="2004-10-20-02:41">DRAFT</status_change>
        <status_change date="2004-11-03-12:00">INTERIM</status_change>
        <status_change date="2004-12-09-08:46">ACCEPTED</status_change>
        <modified date="2005-02-22-09:29" comment="Changed CVE entry from 2003-0569 to 2004-0569">
          <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
        </modified>
        <status_change date="2005-12-12-09:59">INTERIM</status_change>
        <status_change date="2005-12-28-04:28">ACCEPTED</status_change>
      </dates>
      <description>The RPC Runtime Library for Microsoft Windows NT 4.0 allows remote attackers to read active memory or cause a denial of service (system crash) via a malicious message, possibly related to improper length values.</description>
      <reference source="CVE">CVE-2004-0569</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-43" comment="this is an NT Terminal Server" negate="false"/>
          <criterion test_ref="wft-559" comment="the version of rpcrt4.dll is less than 4.0.1381.33578" negate="false"/>
          <criterion test_ref="wrt-558" comment="Patch KB873350 Installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL5307" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Windows Shell</product>
      </affected>
      <dates>
        <submitted date="2004-10-14-03:38">
          <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
        </submitted>
        <status_change date="2004-10-20-02:41">DRAFT</status_change>
        <status_change date="2004-11-03-12:00">INTERIM</status_change>
        <status_change date="2004-12-09-08:46">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in Microsoft Internet Explorer and Explorer on Windows XP SP1, WIndows 2000, Windows 98, and Windows Me may allow remote malicious servers to cause a denial of service (application crash) and possibly execute arbitrary code via long share names, as demonstrated using Samba.</description>
      <reference source="CVE">CVE-2004-0214</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-2" comment="Windows XP is installed" negate="false"/>
          <criterion test_ref="wrt-72" comment="32-Bit version of Windows is installed" negate="false"/>
          <criterion test_ref="wrt-29" comment="Win2K/XP/2003 service pack 2 (or later) is installed" negate="true"/>
          <criterion test_ref="cmp-1118" comment="a vulnerable version of shell32.dll exists" negate="false"/>
          <criterion test_ref="wrt-537" comment="the patch q841356 is installed (Hotfix key)" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL5316" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Internet Explorer 6 Service Pack 1 for Windows Server 2003</product>
      </affected>
      <dates>
        <submitted date="2004-10-25-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2004-10-27-12:00">DRAFT</status_change>
        <status_change date="2004-11-17-12:00">INTERIM</status_change>
        <status_change date="2004-12-09-12:00">ACCEPTED</status_change>
        <modified date="2005-05-10-12:00" comment="modified wrt-51 - Comment updated to indicate IE 6.">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </modified>
        <status_change date="2005-05-11-05:33">INTERIM</status_change>
        <status_change date="2005-06-01-03:30">ACCEPTED</status_change>
      </dates>
      <description>Integer overflow in the Install Engine (inseng.dll) for Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a malicious website or HTML email with a long .CAB file name, which triggers the integer overflow when calculating a buffer length and leads to a heap-based buffer overflow.</description>
      <reference source="CVE">CVE-2004-0216</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-51" comment="Internet Explorer 6  for Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wft-558" comment="the version of mshtml.dll is less than 6.0.3790.219" negate="false"/>
          <criterion test_ref="wrt-557" comment="the patch kb834707 is installed (Hotfix key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL5329" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows ME</windows:platform>
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Internet Explorer 6 SP1</product>
      </affected>
      <dates>
        <submitted date="2004-10-25-04:35">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2004-10-27-01:04">DRAFT</status_change>
        <status_change date="2004-11-17-10:00">INTERIM</status_change>
        <status_change date="2004-12-09-08:46">ACCEPTED</status_change>
        <modified date="2005-09-27-10:50" comment="modified wft-564 - Changed test to match comment">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-28-01:04">INTERIM</status_change>
        <status_change date="2005-10-19-05:47">ACCEPTED</status_change>
      </dates>
      <description>Integer overflow in the Install Engine (inseng.dll) for Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a malicious website or HTML email with a long .CAB file name, which triggers the integer overflow when calculating a buffer length and leads to a heap-based buffer overflow.</description>
      <reference source="CVE">CVE-2004-0216</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-50" comment="Internet Explorer 6 Service Pack 1 is installed" negate="false"/>
          <criterion test_ref="wft-564" comment="the version of mshtml.dll is less than 6.0.2800.1476   " negate="false"/>
          <criterion test_ref="wrt-561" comment="the patch kb834707 is installed (Installed Components key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL5509" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>SMTP</product>
      </affected>
      <dates>
        <submitted date="2004-10-13-10:00">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2004-10-13-01:16">DRAFT</status_change>
        <status_change date="2004-10-27-12:00">INTERIM</status_change>
        <status_change date="2004-11-17-10:00">ACCEPTED</status_change>
      </dates>
      <description>The SMTP (Simple Mail Transfer Protocol) component of Microsoft Windows XP 64-bit Edition, Windows Server 2003, Windows Server 2003 64-bit Edition, and the Exchange Routing Engine component of Exchange Server 2003, allows remote attackers to execute arbitrary code via a malicious DNS response message containing length values that are not properly validated.</description>
      <reference source="CVE">CVE-2004-0840</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wft-502" comment="The version of smtpsvc.dll is less than 6.0.3790.211" negate="false"/>
          <criterion test_ref="wrt-542" comment="the patch WindowsServer2003-KB885881-x86-enu.exe is installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-240" comment="SMTP Enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL5520" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows ME</windows:platform>
        <product>Internet Explorer 5.5 Service Pack 2</product>
      </affected>
      <dates>
        <submitted date="2005-01-18-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2005-01-20-02:31">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
        <modified date="2005-09-26-12:42" comment="modified wft-562 - Changed comment to match test">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-28-01:04">INTERIM</status_change>
        <status_change date="2005-10-19-05:47">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 5.01, 5.5, and 6 does not properly cache SSL content, which allows remote attackers to obtain information or spoof content via a web site with the same host name as the target web site, whose content is cached and reused when the user visits the target web site.</description>
      <reference source="CVE">CVE-2004-0845</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-53" comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false"/>
          <criterion test_ref="wft-562" comment="the version of mshtml.dll is less than 5.50.4945.2800 " negate="false"/>
          <criterion test_ref="wrt-561" comment="the patch kb834707 is installed (Installed Components key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-567" comment="Users not saving encrypted pages to disk  (DisableCachingOfSSLPages)" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL5592" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows ME</windows:platform>
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Internet Explorer 5.5 Service Pack 2</product>
      </affected>
      <dates>
        <submitted date="2004-10-19-04:49">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2004-10-20-02:41">DRAFT</status_change>
        <status_change date="2004-11-03-12:00">INTERIM</status_change>
        <status_change date="2004-12-09-08:46">ACCEPTED</status_change>
        <modified date="2005-09-26-12:42" comment="modified wft-562 - Changed comment to match test">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-28-01:04">INTERIM</status_change>
        <status_change date="2005-10-19-05:47">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 6.0 SP1 and earlier, and possibly other versions, allows remote attackers to cause a denial of service (application crash from "memory corruption") via certain malformed Cascading Style Sheet (CSS) elements that trigger heap-based buffer overflows, as demonstrated using the "&lt;STYLE>@;/*" string, possibly due to a missing comment terminator that may cause an invalid length to trigger a large memory copy operation, aka the "CSS Heap Memory Corruption Vulnerability."</description>
      <reference source="CVE">CVE-2004-0842</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-53" comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false"/>
          <criterion test_ref="wft-562" comment="the version of mshtml.dll is less than 5.50.4945.2800 " negate="false"/>
          <criterion test_ref="wrt-561" comment="the patch kb834707 is installed (Installed Components key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL5620" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Internet Explorer 6 Service Pack 1 for Windows Server 2003</product>
      </affected>
      <dates>
        <submitted date="2005-01-18-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2005-01-20-12:00">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-12:00">ACCEPTED</status_change>
        <modified date="2005-05-10-12:00" comment="modified wrt-51 - Comment updated to indicate IE 6.">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </modified>
        <status_change date="2005-05-11-05:33">INTERIM</status_change>
        <status_change date="2005-06-01-03:30">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 6.x allows remote attackers to install arbitrary programs via mousedown events that call the Popup.show method and use drag-and-drop actions in a popup window, aka "HijackClick 3" and the "Script in Image Tag File Download Vulnerability."</description>
      <reference source="CVE">CVE-2004-0841</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-51" comment="Internet Explorer 6  for Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wft-558" comment="the version of mshtml.dll is less than 6.0.3790.219" negate="false"/>
          <criterion test_ref="wrt-557" comment="the patch kb834707 is installed (Hotfix key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL5740" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows ME</windows:platform>
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Internet Explorer 6 SP1</product>
      </affected>
      <dates>
        <submitted date="2004-10-26-02:20">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2004-10-27-01:05">DRAFT</status_change>
        <status_change date="2004-11-17-10:00">INTERIM</status_change>
        <status_change date="2004-12-09-08:46">ACCEPTED</status_change>
        <modified date="2005-09-27-10:50" comment="modified wft-564 - Changed test to match comment">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-28-01:04">INTERIM</status_change>
        <status_change date="2005-10-19-05:47">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 5.01, 5.5, and 6 does not properly cache SSL content, which allows remote attackers to obtain information or spoof content via a web site with the same host name as the target web site, whose content is cached and reused when the user visits the target web site.</description>
      <reference source="CVE">CVE-2004-0845</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-50" comment="Internet Explorer 6 Service Pack 1 is installed" negate="false"/>
          <criterion test_ref="wft-564" comment="the version of mshtml.dll is less than 6.0.2800.1476   " negate="false"/>
          <criterion test_ref="wrt-561" comment="the patch kb834707 is installed (Installed Components key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-567" comment="Users not saving encrypted pages to disk  (DisableCachingOfSSLPages)" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL5926" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Network News Transport Protocol (NNTP)</product>
      </affected>
      <dates>
        <submitted date="2004-10-14-08:58">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </submitted>
        <status_change date="2004-10-20-02:41">DRAFT</status_change>
        <status_change date="2004-11-03-12:00">INTERIM</status_change>
        <status_change date="2004-12-09-08:46">ACCEPTED</status_change>
      </dates>
      <description>The Network News Transfer Protocol (NNTP) component of Microsoft Windows NT Server 4.0, Windows 2000 Server, Windows Server 2003, Exchange 2000 Server, and Exchange Server 2003 allows remote attackers to execute arbitrary code via XPAT patterns, possibly related to improper length validation and an "unchecked buffer," leading to off-by-one and heap-based buffer overflows.</description>
      <reference source="CVE">CVE-2004-0574</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-60" comment="Windows 2000 Server is installed" negate="false"/>
          <criterion test_ref="wrt-224" comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="false"/>
          <criterion test_ref="wft-533" comment="the version of nntpsvc.dll is less than 5.0.2195.6972" negate="false"/>
          <criterion test_ref="wrt-555" comment="Patch Windows2000-KB883935-x86-ENU.exe Installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-326" comment="the NNTP service is enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL6031" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows ME</windows:platform>
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Internet Explorer 5.5 Service Pack 2</product>
      </affected>
      <dates>
        <submitted date="2004-10-25-07:54">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2004-10-27-01:05">DRAFT</status_change>
        <status_change date="2004-11-17-10:00">INTERIM</status_change>
        <status_change date="2004-12-09-08:46">ACCEPTED</status_change>
        <modified date="2005-09-26-12:42" comment="modified wft-562 - Changed comment to match test">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-28-01:04">INTERIM</status_change>
        <status_change date="2005-10-19-05:47">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 6.x allows remote attackers to install arbitrary programs via mousedown events that call the Popup.show method and use drag-and-drop actions in a popup window, aka "HijackClick 3" and the "Script in Image Tag File Download Vulnerability."</description>
      <reference source="CVE">CVE-2004-0841</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-53" comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false"/>
          <criterion test_ref="wft-562" comment="the version of mshtml.dll is less than 5.50.4945.2800 " negate="false"/>
          <criterion test_ref="wrt-561" comment="the patch kb834707 is installed (Installed Components key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL6048" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Internet Explorer 5.01 Service Pack 4</product>
      </affected>
      <dates>
        <submitted date="2005-01-18-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2005-01-20-02:31">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 6.x allows remote attackers to install arbitrary programs via mousedown events that call the Popup.show method and use drag-and-drop actions in a popup window, aka "HijackClick 3" and the "Script in Image Tag File Download Vulnerability."</description>
      <reference source="CVE">CVE-2004-0841</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-54" comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false"/>
          <criterion test_ref="wft-561" comment="the version of mshtml.dll is less than 5.0.3534.2800" negate="false"/>
          <criterion test_ref="wrt-560" comment="the patch kb834707-ie501sp4 is installed (Hotfix key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL6100" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows ME</windows:platform>
        <product>Internet Explorer 5.5 Service Pack 2</product>
      </affected>
      <dates>
        <submitted date="2005-01-18-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2005-01-20-02:31">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
        <modified date="2005-09-26-12:42" comment="modified wft-562 - Changed comment to match test">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-28-01:04">INTERIM</status_change>
        <status_change date="2005-10-19-05:47">ACCEPTED</status_change>
      </dates>
      <description>Integer overflow in the Install Engine (inseng.dll) for Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a malicious website or HTML email with a long .CAB file name, which triggers the integer overflow when calculating a buffer length and leads to a heap-based buffer overflow.</description>
      <reference source="CVE">CVE-2004-0216</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-53" comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false"/>
          <criterion test_ref="wft-562" comment="the version of mshtml.dll is less than 5.50.4945.2800 " negate="false"/>
          <criterion test_ref="wrt-561" comment="the patch kb834707 is installed (Installed Components key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL6272" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Internet Explorer 6 Service Pack 1 for Windows Server 2003</product>
      </affected>
      <dates>
        <submitted date="2004-10-25-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2004-10-27-12:00">DRAFT</status_change>
        <status_change date="2004-11-17-12:00">INTERIM</status_change>
        <status_change date="2004-12-09-12:00">ACCEPTED</status_change>
        <modified date="2005-05-10-12:00" comment="modified wrt-51 - Comment updated to indicate IE 6.">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </modified>
        <status_change date="2005-05-11-05:33">INTERIM</status_change>
        <status_change date="2005-06-01-03:30">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer in Windows XP SP2, and other versions including 5.01 and 5.5, allows remote attackers to install arbitrary programs via a web page that uses certain styles and the AnchorClick behavior, popup windows, and drag-and-drop capabilities to drop the program in the local startup folder, as demonstrated by "wottapoop.html".</description>
      <reference source="CVE">CVE-2004-0839</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-51" comment="Internet Explorer 6  for Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wft-558" comment="the version of mshtml.dll is less than 6.0.3790.219" negate="false"/>
          <criterion test_ref="wrt-557" comment="the patch kb834707 is installed (Hotfix key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL6313" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Internet Explorer 6 Service Pack 1 for Windows Server 2003</product>
      </affected>
      <dates>
        <submitted date="2004-10-25-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2004-10-27-12:00">DRAFT</status_change>
        <status_change date="2004-11-17-12:00">INTERIM</status_change>
        <status_change date="2004-12-09-12:00">ACCEPTED</status_change>
        <modified date="2005-05-10-12:00" comment="modified wrt-51 - Comment updated to indicate IE 6.">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </modified>
        <status_change date="2005-05-11-05:33">INTERIM</status_change>
        <status_change date="2005-06-01-03:30">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 5.5 and 6 does not properly handle plug-in navigation, which allows remote attackers to alter displayed address bars and thereby spoof web pages, facilitating phishing attacks, aka the "Plug-in Navigation Address Bar Spoofing Vulnerability."</description>
      <reference source="CVE">CVE-2004-0843</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-51" comment="Internet Explorer 6  for Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wft-558" comment="the version of mshtml.dll is less than 6.0.3790.219" negate="false"/>
          <criterion test_ref="wrt-557" comment="the patch kb834707 is installed (Hotfix key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL6397" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Compressed Folders</product>
      </affected>
      <dates>
        <submitted date="2004-10-14-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
        <status_change date="2004-10-20-12:00">DRAFT</status_change>
        <status_change date="2004-11-03-12:00">INTERIM</status_change>
        <status_change date="2004-12-09-12:00">ACCEPTED</status_change>
        <modified date="2005-01-13-12:00" comment="modified wrt-554 - corrected regular exprsssion on value. Needed to escape the period in the file name and change the *'s to .*">
          <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
        </modified>
        <status_change date="2005-01-20-12:00">INTERIM</status_change>
        <status_change date="2005-02-16-12:00">ACCEPTED</status_change>
        <modified date="2005-05-05-12:00" comment="Removed the negate=&quot;true&quot; from the config test; should be vulnerable *if* enabled, rather than vulnerable if *not*  enabled.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2005-05-11-05:33">INTERIM</status_change>
        <status_change date="2005-06-01-03:30">ACCEPTED</status_change>
      </dates>
      <description>Integer overflow in DUNZIP32.DLL for Microsoft Windows XP, Windows XP 64-bit Edition, Windows Server 2003, and Windows Server 2003 64-bit Edition allows remote attackers to execute arbitrary code via compressed (zipped) folders that involve an "unchecked buffer" and improper length validation.</description>
      <reference source="CVE">CVE-2004-0575</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-2" comment="Windows XP is installed" negate="false"/>
          <criterion test_ref="wrt-70" comment="64-Bit version of Windows is installed" negate="false"/>
          <criterion test_ref="wrt-29" comment="Win2K/XP/2003 service pack 2 (or later) is installed" negate="true"/>
          <criterion test_ref="wft-536" comment="the 64-bit WOW version of zipfldr.dll is less than 6.0.2800.1584" negate="false"/>
          <criterion test_ref="wrt-553" comment="the patch q873376 is installed (Hotfix key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-554" comment="Compressed Folders with zipfldr.dll are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL6579" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows ME</windows:platform>
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Internet Explorer 6 SP1</product>
      </affected>
      <dates>
        <submitted date="2004-10-19-04:56">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2004-10-20-02:41">DRAFT</status_change>
        <status_change date="2004-11-03-12:00">INTERIM</status_change>
        <status_change date="2004-12-09-08:46">ACCEPTED</status_change>
        <modified date="2005-09-27-10:50" comment="modified wft-564 - Changed test to match comment">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-28-01:04">INTERIM</status_change>
        <status_change date="2005-10-19-05:47">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 6.0 SP1 and earlier, and possibly other versions, allows remote attackers to cause a denial of service (application crash from "memory corruption") via certain malformed Cascading Style Sheet (CSS) elements that trigger heap-based buffer overflows, as demonstrated using the "&lt;STYLE>@;/*" string, possibly due to a missing comment terminator that may cause an invalid length to trigger a large memory copy operation, aka the "CSS Heap Memory Corruption Vulnerability."</description>
      <reference source="CVE">CVE-2004-0842</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-50" comment="Internet Explorer 6 Service Pack 1 is installed" negate="false"/>
          <criterion test_ref="wft-564" comment="the version of mshtml.dll is less than 6.0.2800.1476   " negate="false"/>
          <criterion test_ref="wrt-561" comment="the patch kb834707 is installed (Installed Components key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL6600" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Internet Explorer 5.01 Service Pack 4</product>
      </affected>
      <dates>
        <submitted date="2004-10-25-04:23">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2004-10-27-01:05">DRAFT</status_change>
        <status_change date="2004-11-17-10:00">INTERIM</status_change>
        <status_change date="2004-12-09-08:46">ACCEPTED</status_change>
      </dates>
      <description>Integer overflow in the Install Engine (inseng.dll) for Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a malicious website or HTML email with a long .CAB file name, which triggers the integer overflow when calculating a buffer length and leads to a heap-based buffer overflow.</description>
      <reference source="CVE">CVE-2004-0216</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-54" comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false"/>
          <criterion test_ref="wft-561" comment="the version of mshtml.dll is less than 5.0.3534.2800" negate="false"/>
          <criterion test_ref="wrt-560" comment="the patch kb834707-ie501sp4 is installed (Hotfix key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL6788" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>NetDDE</product>
      </affected>
      <dates>
        <submitted date="2004-10-14-04:23">
          <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
        </submitted>
        <status_change date="2004-10-20-02:41">DRAFT</status_change>
        <status_change date="2004-11-03-12:00">INTERIM</status_change>
        <status_change date="2004-12-09-08:46">ACCEPTED</status_change>
      </dates>
      <description>Network Dynamic Data Exchange (NetDDE) services for Microsoft Windows 98, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows attackers to remotely execute arbitrary code or locally gain privileges via a malicious message or application that involves an "unchecked buffer," possibly a buffer overflow.</description>
      <reference source="CVE">CVE-2004-0206</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wrt-70" comment="64-Bit version of Windows is installed" negate="false"/>
          <criterion test_ref="cmp-1143" comment="a vulnerable version of netdde.exe exists" negate="false"/>
          <criterion test_ref="cmp-1144" comment="a vulnerable version of nddenb32.dll exists" negate="false"/>
          <criterion test_ref="wrt-551" comment="the patch KB841533 is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL6829" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows ME</windows:platform>
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Internet Explorer 6 SP1</product>
      </affected>
      <dates>
        <submitted date="2004-10-19-07:37">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2004-10-20-02:41">DRAFT</status_change>
        <status_change date="2004-11-03-12:00">INTERIM</status_change>
        <status_change date="2004-12-09-08:46">ACCEPTED</status_change>
        <modified date="2005-09-27-10:50" comment="modified wft-564 - Changed test to match comment">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-28-01:04">INTERIM</status_change>
        <status_change date="2005-10-19-05:47">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Internet Explorer 6.0.2800.1106 on Microsoft Windows XP SP2, and other versions including 5.01 and 5.5, allows remote web servers to bypass zone restrictions and execute arbitrary code in the local computer zone by redirecting a function to another function with the same name, as demonstrated by SimilarMethodNameRedir, aka the "Similar Method Name Redirection Cross Domain Vulnerability."</description>
      <reference source="CVE">CVE-2004-0727</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-50" comment="Internet Explorer 6 Service Pack 1 is installed" negate="false"/>
          <criterion test_ref="wrt-561" comment="the patch kb834707 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wft-564" comment="the version of mshtml.dll is less than 6.0.2800.1476   " negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL7084" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Internet Explorer 5.01 Service Pack 3</product>
      </affected>
      <dates>
        <submitted date="2004-10-19-07:22">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2004-10-20-02:41">DRAFT</status_change>
        <status_change date="2004-11-03-12:00">INTERIM</status_change>
        <status_change date="2004-12-09-08:46">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Internet Explorer 6.0.2800.1106 on Microsoft Windows XP SP2, and other versions including 5.01 and 5.5, allows remote web servers to bypass zone restrictions and execute arbitrary code in the local computer zone by redirecting a function to another function with the same name, as demonstrated by SimilarMethodNameRedir, aka the "Similar Method Name Redirection Cross Domain Vulnerability."</description>
      <reference source="CVE">CVE-2004-0727</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-55" comment="Internet Explorer 5.01 Service Pack 3 is installed" negate="false"/>
          <criterion test_ref="wft-560" comment="the version of mshtml.dll is less than 5.0.3821.2800" negate="false"/>
          <criterion test_ref="wrt-559" comment="the patch kb834707-ie501sp3 is installed (Hotfix key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL7095" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows ME</windows:platform>
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Internet Explorer 5.5 Service Pack 2</product>
      </affected>
      <dates>
        <submitted date="2004-10-25-05:31">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2004-10-27-01:05">DRAFT</status_change>
        <status_change date="2004-11-17-10:00">INTERIM</status_change>
        <status_change date="2004-12-09-08:46">ACCEPTED</status_change>
        <modified date="2005-09-26-12:42" comment="modified wft-562 - Changed comment to match test">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-28-01:04">INTERIM</status_change>
        <status_change date="2005-10-19-05:47">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 5.5 and 6 does not properly handle plug-in navigation, which allows remote attackers to alter displayed address bars and thereby spoof web pages, facilitating phishing attacks, aka the "Plug-in Navigation Address Bar Spoofing Vulnerability."</description>
      <reference source="CVE">CVE-2004-0843</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-53" comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false"/>
          <criterion test_ref="wft-562" comment="the version of mshtml.dll is less than 5.50.4945.2800 " negate="false"/>
          <criterion test_ref="wrt-561" comment="the patch kb834707 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL7194" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows ME</windows:platform>
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Internet Explorer 6 SP1</product>
      </affected>
      <dates>
        <submitted date="2004-10-25-07:44">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2004-10-27-01:05">DRAFT</status_change>
        <status_change date="2004-11-17-10:00">INTERIM</status_change>
        <status_change date="2004-12-09-08:46">ACCEPTED</status_change>
        <modified date="2005-09-27-10:50" comment="modified wft-564 - Changed test to match comment">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-28-01:04">INTERIM</status_change>
        <status_change date="2005-10-19-05:47">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 5.5 and 6 does not properly handle plug-in navigation, which allows remote attackers to alter displayed address bars and thereby spoof web pages, facilitating phishing attacks, aka the "Plug-in Navigation Address Bar Spoofing Vulnerability."</description>
      <reference source="CVE">CVE-2004-0843</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-50" comment="Internet Explorer 6 Service Pack 1 is installed" negate="false"/>
          <criterion test_ref="wft-564" comment="the version of mshtml.dll is less than 6.0.2800.1476   " negate="false"/>
          <criterion test_ref="wrt-561" comment="the patch kb834707 is installed (Installed Components key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL7448" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows ME</windows:platform>
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Internet Explorer 5.5 Service Pack 2</product>
      </affected>
      <dates>
        <submitted date="2004-10-19-07:31">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2004-10-20-02:41">DRAFT</status_change>
        <status_change date="2004-11-03-12:00">INTERIM</status_change>
        <status_change date="2004-12-09-08:46">ACCEPTED</status_change>
        <modified date="2005-09-26-12:42" comment="modified wft-562 - Changed comment to match test">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-28-01:04">INTERIM</status_change>
        <status_change date="2005-10-19-05:47">ACCEPTED</status_change>
        <modified date="2005-12-14-11:25" comment="correct CVE from CAN-2003-0727 to CAN-2004-0727">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </modified>
        <modified date="2005-12-14-11:27" comment="Fixed CVE reference; was CVE-2003-0727 because of a typo.  Now correctly refers to CVE-2004-0727.  Thanks to Andrew Simmons of MessageLabs for pointing out the error.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2005-12-16-12:49">INTERIM</status_change>
        <status_change date="2006-01-04-08:04">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Internet Explorer 6.0.2800.1106 on Microsoft Windows XP SP2, and other versions including 5.01 and 5.5, allows remote web servers to bypass zone restrictions and execute arbitrary code in the local computer zone by redirecting a function to another function with the same name, as demonstrated by SimilarMethodNameRedir, aka the "Similar Method Name Redirection Cross Domain Vulnerability."</description>
      <reference source="CVE">CVE-2004-0727</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-53" comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false"/>
          <criterion test_ref="wft-562" comment="the version of mshtml.dll is less than 5.50.4945.2800 " negate="false"/>
          <criterion test_ref="wrt-561" comment="the patch kb834707 is installed (Installed Components key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL7496" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Microsoft Internet Explorer 6 Service Pack 1 for Windows Server 2003</product>
      </affected>
      <dates>
        <submitted date="2004-10-19-07:40">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2004-10-20-02:41">DRAFT</status_change>
        <status_change date="2004-11-03-12:00">INTERIM</status_change>
        <status_change date="2004-12-09-08:46">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Internet Explorer 6.0.2800.1106 on Microsoft Windows XP SP2, and other versions including 5.01 and 5.5, allows remote web servers to bypass zone restrictions and execute arbitrary code in the local computer zone by redirecting a function to another function with the same name, as demonstrated by SimilarMethodNameRedir, aka the "Similar Method Name Redirection Cross Domain Vulnerability."</description>
      <reference source="CVE">CVE-2004-0727</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-565" comment="Internet Explorer 6 Service Pack 2 for XP is installed" negate="false"/>
          <criterion test_ref="cmp-1154" comment="a vulnerable version of mshtml.dll exisits" negate="false"/>
          <criterion test_ref="wrt-564" comment="the patch kb834707  is installed (Installed Components key) " negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL7611" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Internet Explorer 5.01 Service Pack 3</product>
      </affected>
      <dates>
        <submitted date="2004-10-26-02:09">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2004-10-27-01:05">DRAFT</status_change>
        <status_change date="2004-11-17-10:00">INTERIM</status_change>
        <status_change date="2004-12-09-08:46">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 5.01, 5.5, and 6 does not properly cache SSL content, which allows remote attackers to obtain information or spoof content via a web site with the same host name as the target web site, whose content is cached and reused when the user visits the target web site.</description>
      <reference source="CVE">CVE-2004-0845</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-55" comment="Internet Explorer 5.01 Service Pack 3 is installed" negate="false"/>
          <criterion test_ref="wft-560" comment="the version of mshtml.dll is less than 5.0.3821.2800" negate="false"/>
          <criterion test_ref="wrt-559" comment="the patch kb834707-ie501sp3 is installed (Hotfix key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="wrt-567" comment="Users not saving encrypted pages to disk  (DisableCachingOfSSLPages)" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL7717" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Internet Explorer 6</product>
      </affected>
      <dates>
        <submitted date="2004-10-25-04:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2004-10-27-04:00">DRAFT</status_change>
        <status_change date="2004-11-17-05:00">INTERIM</status_change>
        <status_change date="2004-12-09-05:00">ACCEPTED</status_change>
        <modified date="2005-09-20-04:00" comment="Changed IE registry test to wrt-18">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-21-01:27">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Integer overflow in the Install Engine (inseng.dll) for Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a malicious website or HTML email with a long .CAB file name, which triggers the integer overflow when calculating a buffer length and leads to a heap-based buffer overflow.</description>
      <reference source="CVE">CVE-2004-0216</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wft-563" comment="the version of mshtml.dll is less than 6.0.2745.2800" negate="false"/>
          <criterion test_ref="wrt-562" comment="the patch kb834707 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-18" comment="Internet Explorer 6 is installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL7721" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Internet Explorer 6</product>
      </affected>
      <dates>
        <submitted date="2004-10-25-04:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2004-10-27-04:00">DRAFT</status_change>
        <status_change date="2004-11-17-05:00">INTERIM</status_change>
        <status_change date="2004-12-09-05:00">ACCEPTED</status_change>
        <modified date="2005-09-20-04:00" comment="Changed IE registry test to wrt-18">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-21-01:27">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer in Windows XP SP2, and other versions including 5.01 and 5.5, allows remote attackers to install arbitrary programs via a web page that uses certain styles and the AnchorClick behavior, popup windows, and drag-and-drop capabilities to drop the program in the local startup folder, as demonstrated by "wottapoop.html".</description>
      <reference source="CVE">CVE-2004-0839</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wft-563" comment="the version of mshtml.dll is less than 6.0.2745.2800" negate="false"/>
          <criterion test_ref="wrt-562" comment="the patch kb834707 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-18" comment="Internet Explorer 6 is installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL7865" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Microsoft Internet Explorer 5.01 Service Pack 3</product>
      </affected>
      <dates>
        <submitted date="2004-10-25-04:20">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2004-10-27-01:05">DRAFT</status_change>
        <status_change date="2004-11-17-10:00">INTERIM</status_change>
        <status_change date="2004-12-09-08:46">ACCEPTED</status_change>
      </dates>
      <description>Integer overflow in the Install Engine (inseng.dll) for Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a malicious website or HTML email with a long .CAB file name, which triggers the integer overflow when calculating a buffer length and leads to a heap-based buffer overflow.</description>
      <reference source="CVE">CVE-2004-0216</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-55" comment="Internet Explorer 5.01 Service Pack 3 is installed" negate="false"/>
          <criterion test_ref="wft-560" comment="the version of mshtml.dll is less than 5.0.3821.2800" negate="false"/>
          <criterion test_ref="wrt-559" comment="the patch kb834707-ie501sp3 is installed (Hotfix key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL7906" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Internet Explorer 6</product>
      </affected>
      <dates>
        <submitted date="2004-10-19-04:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2004-10-20-04:00">DRAFT</status_change>
        <status_change date="2004-11-03-05:00">INTERIM</status_change>
        <status_change date="2004-12-09-05:00">ACCEPTED</status_change>
        <modified date="2005-09-20-04:00" comment="Changed IE registry test to wrt-18">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-21-01:27">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Microsoft Internet Explorer 6.0.2800.1106 on Microsoft Windows XP SP2, and other versions including 5.01 and 5.5, allows remote web servers to bypass zone restrictions and execute arbitrary code in the local computer zone by redirecting a function to another function with the same name, as demonstrated by SimilarMethodNameRedir, aka the "Similar Method Name Redirection Cross Domain Vulnerability."</description>
      <reference source="CVE">CVE-2004-0727</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wft-563" comment="the version of mshtml.dll is less than 6.0.2745.2800" negate="false"/>
          <criterion test_ref="wrt-562" comment="the patch kb834707 is installed (Installed Components key)" negate="true"/>
          <criterion test_ref="wrt-18" comment="Internet Explorer 6 is installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL8077" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows ME</windows:platform>
        <product>Internet Explorer 6 SP1</product>
      </affected>
      <dates>
        <submitted date="2005-01-18-12:00">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2005-01-20-02:31">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
        <modified date="2005-09-27-10:50" comment="modified wft-564 - Changed test to match comment">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-28-01:04">INTERIM</status_change>
        <status_change date="2005-10-19-05:47">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 6.x allows remote attackers to install arbitrary programs via mousedown events that call the Popup.show method and use drag-and-drop actions in a popup window, aka "HijackClick 3" and the "Script in Image Tag File Download Vulnerability."</description>
      <reference source="CVE">CVE-2004-0841</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-50" comment="Internet Explorer 6 Service Pack 1 is installed" negate="false"/>
          <criterion test_ref="wft-564" comment="the version of mshtml.dll is less than 6.0.2800.1476   " negate="false"/>
          <criterion test_ref="wrt-561" comment="the patch kb834707 is installed (Installed Components key)" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL8127" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows ME</windows:platform>
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Internet Explorer 6 SP1</product>
      </affected>
      <dates>
        <submitted date="2004-10-25-05:13">
          <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
        </submitted>
        <status_change date="2004-10-27-01:05">DRAFT</status_change>
        <status_change date="2004-11-17-10:00">INTERIM</status_change>
        <status_change date="2004-12-09-08:46">ACCEPTED</status_change>
        <modified date="2005-09-27-10:50" comment="modified wft-564 - Changed test to match comment">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-28-01:04">INTERIM</status_change>
        <status_change date="2005-10-19-05:47">ACCEPTED</status_change>
      </dates>
      <description>Internet Explorer 6 on Double Byte Character Set (DBCS) systems allows remote attackers to alter displayed address bars and spoof web pages via a URL containing special characters, facilitating phishing attacks, aka the "Address Bar Spoofing on Double Byte Character Set Systems Vulnerability."</description>
      <reference source="CVE">CVE-2004-0844</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-50" comment="Internet Explorer 6 Service Pack 1 is installed" negate="false"/>
          <criterion test_ref="wft-564" comment="the version of mshtml.dll is less than 6.0.2800.1476   " negate="false"/>
          <criterion test_ref="wft-561" comment="the version of mshtml.dll is less than 5.0.3534.2800" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-97" comment="ActiveX controls and active scripting are enabled" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL100001" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>mozilla</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-04:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <modified date="2005-09-19-04:00" comment="modified wrt-10025 - Reomved extra \\ in key">
          <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
        </modified>
        <status_change date="2005-10-05-11:37">INTERIM</status_change>
        <modified date="2005-10-11-04:13" comment="modified wrt-10024 - Removed doubled backslashes in string literal test.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2005-10-26-06:46">ACCEPTED</status_change>
      </dates>
      <description>The install function in Firefox 1.0.3 allows remote web sites on the browser's whitelist, such as update.mozilla.org or addon.mozilla.org, to execute arbitrary Javascript with chrome privileges, leading to arbitrary code execution on the system when combined with vulnerabilities such as CVE-2005-1476, as demonstrated using a javascript: URL as the package icon and a cross-site scripting (XSS) attack on a vulnerable whitelist site.</description>
      <reference source="CVE">CVE-2005-1477</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-10012" comment="Firefox &lt;= 1.0.3 or Mozilla Suite &lt;= 1.7.7 is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100002" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>mozilla</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-04:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <modified date="2005-09-19-04:00" comment="modified wrt-10025 - Reomved extra \\ in key">
          <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
        </modified>
        <status_change date="2005-10-05-11:37">INTERIM</status_change>
        <modified date="2005-10-11-04:13" comment="modified wrt-10024 - Removed doubled backslashes in string literal test.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2005-10-26-06:46">ACCEPTED</status_change>
      </dates>
      <description>Firefox 1.0.3 allows remote attackers to execute arbitrary Javascript in other domains by using an IFRAME and causing the browser to navigate to a previous javascript: URL, which can lead to arbitrary code execution when combined with CVE-2005-1477.</description>
      <reference source="CVE">CVE-2005-1476</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-10012" comment="Firefox &lt;= 1.0.3 or Mozilla Suite &lt;= 1.7.7 is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100003" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>mozilla</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-04:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <modified date="2005-09-19-04:00" comment="modified wrt-10048 - Removed extra \\ in key">
          <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
        </modified>
        <status_change date="2005-10-05-11:37">INTERIM</status_change>
        <status_change date="2005-10-26-06:46">ACCEPTED</status_change>
        <status_change date="2005-12-12-09:30">INTERIM</status_change>
        <status_change date="2005-12-28-04:28">ACCEPTED</status_change>
        <modified date="2006-01-25-04:02" comment="Added Mozilla as affected product.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2006-01-25-07:27">INTERIM</status_change>
        <status_change date="2006-02-22-08:27">ACCEPTED</status_change>
      </dates>
      <description>Firefox before 1.0.5 and Mozilla before 1.7.9 does not properly clone base objects, which allows remote attackers to execute arbitrary code by navigating the prototype chain to reach a privileged object.</description>
      <reference source="CVE">CVE-2005-2270</reference>
      <status>ACCEPTED</status>
      <version>5</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-659" comment="Mozilla Firefox version 1.0.4 or earlier is installed" negate="false"/>
          <criterion test_ref="cmp-652" comment="Mozilla Suite version 1.7.8 or earlier is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100004" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>mozilla</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-04:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <modified date="2005-09-19-04:00" comment="modified wrt-10048 - Removed extra \\ in key">
          <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
        </modified>
        <status_change date="2005-10-05-11:37">INTERIM</status_change>
        <status_change date="2005-10-26-06:46">ACCEPTED</status_change>
        <status_change date="2005-12-12-09:30">INTERIM</status_change>
        <status_change date="2005-12-28-04:28">ACCEPTED</status_change>
        <modified date="2006-02-01-04:43" comment="Added Mozilla as affected product.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2006-02-01-09:07">INTERIM</status_change>
        <status_change date="2006-02-22-08:27">ACCEPTED</status_change>
      </dates>
      <description>Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 does not properly verify the associated types of DOM node names within the context of their namespaces, which allows remote attackers to modify certain tag properties, possibly leading to execution of arbitrary script or code, as demonstrated using an XHTML document with IMG tags with custom properties ("XHTML node spoofing").</description>
      <reference source="CVE">CVE-2005-2269</reference>
      <status>ACCEPTED</status>
      <version>5</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-659" comment="Mozilla Firefox version 1.0.4 or earlier is installed" negate="false"/>
          <criterion test_ref="cmp-652" comment="Mozilla Suite version 1.7.8 or earlier is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100005" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>mozilla</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-04:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <modified date="2005-09-07-04:00" comment="Added Description">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <modified date="2005-09-19-04:00" comment="modified wrt-10048 - Removed extra \\ in key">
          <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
        </modified>
        <modified date="2005-10-04-08:47" comment="Changed CVE reference to CAN-2005-2268, per Rob Hollis">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2005-10-19-05:47">INTERIM</status_change>
        <status_change date="2005-11-16-08:02">ACCEPTED</status_change>
        <status_change date="2005-12-12-09:30">INTERIM</status_change>
        <status_change date="2005-12-28-04:28">ACCEPTED</status_change>
        <modified date="2006-02-01-04:45" comment="Added Mozilla as affected product.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2006-02-01-09:07">INTERIM</status_change>
        <status_change date="2006-02-22-08:27">ACCEPTED</status_change>
      </dates>
      <description>Firefox before 1.0.5 and Mozilla before 1.7.9 does not clearly associate a Javascript dialog box with the web page that generated it, which allows remote attackers to spoof a dialog box from a trusted site and facilitates phishing attacks, aka the "Dialog Origin Spoofing Vulnerability."</description>
      <reference source="CVE">CVE-2005-2268</reference>
      <status>ACCEPTED</status>
      <version>6</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-659" comment="Mozilla Firefox version 1.0.4 or earlier is installed" negate="false"/>
          <criterion test_ref="cmp-652" comment="Mozilla Suite version 1.7.8 or earlier is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100006" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Firefox</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-04:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <modified date="2005-09-07-04:00" comment="Added description">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <modified date="2005-09-19-04:00" comment="modified wrt-10048 - Removed extra \\ in key">
          <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
        </modified>
        <status_change date="2005-10-05-11:37">INTERIM</status_change>
        <modified date="2005-10-08-01:14" comment="Removed test for Mozilla Suite 1.7.8.  Per Rob Hollis &amp;#60;rob@threatguard.com> this definition should not have tested for Mozilla Suite; only Firefox is vulnerable.  Vendor advisory agrees.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2005-10-26-06:46">ACCEPTED</status_change>
        <status_change date="2005-12-12-09:30">INTERIM</status_change>
        <status_change date="2005-12-28-04:28">ACCEPTED</status_change>
        <modified date="2006-02-01-04:47" comment="Added Mozilla as affected product.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <modified date="2006-02-01-05:47" comment="Changed affected product to Firefox.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2006-02-01-09:07">INTERIM</status_change>
        <status_change date="2006-02-22-08:27">ACCEPTED</status_change>
      </dates>
      <description>Firefox before 1.0.5 allows remote attackers to steal information and possibly execute arbitrary code by using standalone applications such as Flash and QuickTime to open a javascript: URL, which is run in the context of the previous page, and may lead to code execution if the standalone application loads a privileged chrome: URL.</description>
      <reference source="CVE">CVE-2005-2267</reference>
      <status>ACCEPTED</status>
      <version>5</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-659" comment="Mozilla Firefox version 1.0.4 or earlier is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100007" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>mozilla</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-04:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <modified date="2005-09-19-04:00" comment="modified wrt-10048 - Removed extra \\ in key">
          <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
        </modified>
        <modified date="2005-09-22-09:45" comment="Added CVE#">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-10-12-05:49">INTERIM</status_change>
        <status_change date="2005-11-16-08:02">ACCEPTED</status_change>
        <status_change date="2005-12-12-09:30">INTERIM</status_change>
        <status_change date="2005-12-28-04:28">ACCEPTED</status_change>
        <modified date="2006-02-01-04:49" comment="Added Mozilla as affected product.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2006-02-01-09:07">INTERIM</status_change>
        <status_change date="2006-02-22-08:27">ACCEPTED</status_change>
      </dates>
      <description>A regression error in Firefox 1.0.3 and Mozilla 1.7.7 allows remote attackers to inject arbitrary Javascript from one page into the frameset of another site, aka the frame injection spoofing vulnerability, a re-introduction of a vulnerability that was originally identified and addressed by CVE-2004-0718.</description>
      <reference source="CVE">CVE-2005-1937</reference>
      <status>ACCEPTED</status>
      <version>5</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-659" comment="Mozilla Firefox version 1.0.4 or earlier is installed" negate="false"/>
          <criterion test_ref="cmp-652" comment="Mozilla Suite version 1.7.8 or earlier is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100008" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>mozilla</product>
        <product>Firefox</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-04:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <modified date="2005-09-19-04:00" comment="modified wrt-10048 - Removed extra \\ in key">
          <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
        </modified>
        <status_change date="2005-10-05-11:37">INTERIM</status_change>
        <status_change date="2005-10-26-06:46">ACCEPTED</status_change>
        <status_change date="2005-12-12-09:30">INTERIM</status_change>
        <status_change date="2005-12-28-04:28">ACCEPTED</status_change>
        <modified date="2006-02-01-04:51" comment="Added Mozilla and Firefox as affected products.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2006-02-01-09:07">INTERIM</status_change>
        <status_change date="2006-02-22-08:27">ACCEPTED</status_change>
      </dates>
      <description>Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 and 7.2 allows remote attackers to cause a denial of service (access violation and crash), and possibly execute arbitrary code, by calling InstallVersion.compareTo with an object instead of a string.</description>
      <reference source="CVE">CVE-2005-2265</reference>
      <status>ACCEPTED</status>
      <version>5</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-659" comment="Mozilla Firefox version 1.0.4 or earlier is installed" negate="false"/>
          <criterion test_ref="cmp-652" comment="Mozilla Suite version 1.7.8 or earlier is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100009" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Firefox</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
        <status_change date="2005-12-12-09:30">INTERIM</status_change>
        <status_change date="2005-12-28-04:28">ACCEPTED</status_change>
        <modified date="2006-02-01-04:52" comment="Added Firefox as affected product.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2006-02-01-09:07">INTERIM</status_change>
        <status_change date="2006-02-22-08:27">ACCEPTED</status_change>
      </dates>
      <description>Firefox before 1.0.5 allows remote attackers to steal sensitive information by opening a malicious link in the Firefox sidebar using the _search target, then injecting script into other pages via a data: URL.</description>
      <reference source="CVE">CVE-2005-2264</reference>
      <status>ACCEPTED</status>
      <version>6</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-659" comment="Mozilla Firefox version 1.0.4 or earlier is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100010" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Firefox</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-04:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <modified date="2005-09-07-04:00" comment="Added description">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-28-01:05">INTERIM</status_change>
        <status_change date="2005-10-19-05:47">ACCEPTED</status_change>
        <status_change date="2005-12-12-09:30">INTERIM</status_change>
        <status_change date="2005-12-28-04:28">ACCEPTED</status_change>
        <modified date="2006-02-01-04:53" comment="Added Firefox as affected product.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2006-02-01-09:07">INTERIM</status_change>
        <status_change date="2006-02-22-08:27">ACCEPTED</status_change>
      </dates>
      <description>The InstallTrigger.install method in Firefox before 1.0.5 and Mozilla before 1.7.9 allows remote attackers to execute a callback function in the context of another domain by forcing a page navigation after the install method has been called, which causes the callback to be run in the context of the new page and results in a same origin violation.</description>
      <reference source="CVE">CVE-2005-2263</reference>
      <status>ACCEPTED</status>
      <version>5</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-659" comment="Mozilla Firefox version 1.0.4 or earlier is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100011" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Firefox</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <modified date="2005-10-04-08:55" comment="Updated reference to CVE-2005-2262 per Rob Hollis">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <modified date="2005-10-11-04:20" comment="modified wrt-10045 - Removed doubled backslash from string literal test.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2005-10-26-06:46">ACCEPTED</status_change>
        <status_change date="2005-12-12-09:30">INTERIM</status_change>
        <status_change date="2005-12-28-04:28">ACCEPTED</status_change>
        <modified date="2006-02-01-04:56" comment="Added Firefox as affected product.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2006-02-01-09:07">INTERIM</status_change>
        <status_change date="2006-02-22-08:27">ACCEPTED</status_change>
      </dates>
      <description>Firefox 1.0.3 and 1.0.4, and Netscape 8.0.2, allows remote attackers to execute arbitrary code by tricking the user into using the "Set As Wallpaper" (in Firefox) or "Set as Background" (in Netscape) context menu on an image URL that is really a javascript: URL with an eval statement, aka "Firewalling."</description>
      <reference source="CVE">CVE-2005-2262</reference>
      <status>ACCEPTED</status>
      <version>6</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-659" comment="Mozilla Firefox version 1.0.4 or earlier is installed" negate="false"/>
          <criterion test_ref="cmp-658" comment="Mozilla Firefox version 1.0.2 or earlier is installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100012" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>mozilla</product>
        <product>Firefox</product>
        <product>Thunderbird</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-04:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <modified date="2005-09-19-04:00" comment="modified wrt-10048 - Removed extra \\ in key">
          <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
        </modified>
        <status_change date="2005-10-05-11:37">INTERIM</status_change>
        <status_change date="2005-10-26-06:46">ACCEPTED</status_change>
        <status_change date="2005-12-12-09:30">INTERIM</status_change>
        <status_change date="2005-12-28-04:28">ACCEPTED</status_change>
        <modified date="2006-02-01-05:01" comment="Added Firefox, Mozilla, and Thunderbird as affected products.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2006-02-01-09:07">INTERIM</status_change>
        <status_change date="2006-02-22-08:27">ACCEPTED</status_change>
      </dates>
      <description>Firefox before 1.0.5, Thunderbird before 1.0.5, Mozilla before 1.7.9, Netscape 8.0.2, and K-Meleon 0.9 runs XBL scripts even when Javascript has been disabled, which makes it easier for remote attackers to bypass such protection.</description>
      <reference source="CVE">CVE-2005-2261</reference>
      <status>ACCEPTED</status>
      <version>5</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-659" comment="Mozilla Firefox version 1.0.4 or earlier is installed" negate="false"/>
          <criterion test_ref="cmp-665" comment="Mozilla Thunderbird version 1.0.2 or earlier is installed" negate="false"/>
          <criterion test_ref="cmp-652" comment="Mozilla Suite version 1.7.8 or earlier is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100013" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>mozilla</product>
        <product>Firefox</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-04:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <modified date="2005-09-19-04:00" comment="modified wrt-10048 - Removed extra \\ in key">
          <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
        </modified>
        <status_change date="2005-10-05-11:37">INTERIM</status_change>
        <status_change date="2005-10-26-06:46">ACCEPTED</status_change>
        <status_change date="2005-12-12-09:30">INTERIM</status_change>
        <status_change date="2005-12-28-04:28">ACCEPTED</status_change>
        <modified date="2006-02-01-05:03" comment="Added Firefox and Mozilla as affected products.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2006-02-01-09:07">INTERIM</status_change>
        <status_change date="2006-02-22-08:27">ACCEPTED</status_change>
      </dates>
      <description>The browser user interface in Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 and 7.2 does not properly distinguish between user-generated events and untrusted synthetic events, which makes it easier for remote attackers to perform dangerous actions that normally could only be performed manually by the user.</description>
      <reference source="CVE">CVE-2005-2260</reference>
      <status>ACCEPTED</status>
      <version>5</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-659" comment="Mozilla Firefox version 1.0.4 or earlier is installed" negate="false"/>
          <criterion test_ref="cmp-652" comment="Mozilla Suite version 1.7.8 or earlier is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100014" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>mozilla</product>
        <product>Firefox</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-04:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <modified date="2005-09-19-04:00" comment="modified wrt-10025 - Reomved extra \\ in key">
          <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
        </modified>
        <status_change date="2005-10-05-11:37">INTERIM</status_change>
        <modified date="2005-10-11-04:13" comment="modified wrt-10024 - Removed doubled backslashes in string literal test.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2005-10-26-06:46">ACCEPTED</status_change>
        <status_change date="2005-12-12-09:30">INTERIM</status_change>
        <status_change date="2005-12-28-04:28">ACCEPTED</status_change>
        <modified date="2006-02-01-05:06" comment="Added Firefox and Mozilla as affected products.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2006-02-01-09:07">INTERIM</status_change>
        <status_change date="2006-02-22-08:27">ACCEPTED</status_change>
      </dates>
      <description>Firefox before 1.0.4 and Mozilla Suite before 1.7.8 does not properly limit privileges of Javascript eval and Script objects in the calling context, which allows remote attackers to conduct unauthorized activities via "non-DOM property overrides," a variant of CVE-2005-1160.</description>
      <reference source="CVE">CVE-2005-1532</reference>
      <status>ACCEPTED</status>
      <version>5</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-660" comment="Mozilla Firefox version 1.0.3 or earlier is installed" negate="false"/>
          <criterion test_ref="cmp-653" comment="Mozilla Suite version 1.7.7 or earlier is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100015" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>mozilla</product>
        <product>Firefox</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-04:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <modified date="2005-09-19-04:00" comment="modified wrt-10025 - Reomved extra \\ in key">
          <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
        </modified>
        <status_change date="2005-10-05-11:37">INTERIM</status_change>
        <modified date="2005-10-11-04:13" comment="modified wrt-10024 - Removed doubled backslashes in string literal test.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2005-10-26-06:46">ACCEPTED</status_change>
        <status_change date="2005-12-12-09:30">INTERIM</status_change>
        <status_change date="2005-12-28-04:28">ACCEPTED</status_change>
        <modified date="2006-02-01-05:07" comment="Added Firefox and Mozilla as affected products.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2006-02-01-09:07">INTERIM</status_change>
        <status_change date="2006-02-22-08:27">ACCEPTED</status_change>
      </dates>
      <description>Firefox before 1.0.4 and Mozilla Suite before 1.7.8 does not properly implement certain security checks for script injection, which allows remote attackers to execute script via "Wrapped" javascript: URLs, as demonstrated using (1) a javascript: URL in a view-source: URL, (2) a javascript: URL in a jar: URL, or (3) "a nested variant."</description>
      <reference source="CVE">CVE-2005-1531</reference>
      <status>ACCEPTED</status>
      <version>5</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-660" comment="Mozilla Firefox version 1.0.3 or earlier is installed" negate="false"/>
          <criterion test_ref="cmp-653" comment="Mozilla Suite version 1.7.7 or earlier is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100016" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>mozilla</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-04:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <modified date="2005-09-07-04:00" comment="Added description">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <modified date="2005-09-19-04:00" comment="modified wrt-10048 - Removed extra \\ in key">
          <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
        </modified>
        <status_change date="2005-10-05-11:37">INTERIM</status_change>
        <status_change date="2005-10-26-06:46">ACCEPTED</status_change>
        <status_change date="2005-12-12-09:30">INTERIM</status_change>
        <status_change date="2005-12-28-04:28">ACCEPTED</status_change>
        <modified date="2006-02-01-05:09" comment="Added Mozilla as affected product.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2006-02-01-09:07">INTERIM</status_change>
        <status_change date="2006-02-22-08:27">ACCEPTED</status_change>
      </dates>
      <description>The InstallTrigger.install method in Firefox before 1.0.5 and Mozilla before 1.7.9 allows remote attackers to execute a callback function in the context of another domain by forcing a page navigation after the install method has been called, which causes the callback to be run in the context of the new page and results in a same origin violation.</description>
      <reference source="CVE">CVE-2005-2263</reference>
      <status>ACCEPTED</status>
      <version>5</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-652" comment="Mozilla Suite version 1.7.8 or earlier is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100017" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>mozilla</product>
        <product>Firefox</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <modified date="2005-10-11-04:20" comment="modified wrt-10045 - Removed doubled backslash from string literal test.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <modified date="2005-10-11-04:51" comment="modified wrt-10049 - Removed doubled backslash from string literal test.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2005-10-26-06:46">ACCEPTED</status_change>
        <status_change date="2005-12-12-09:30">INTERIM</status_change>
        <status_change date="2005-12-28-04:28">ACCEPTED</status_change>
        <modified date="2006-02-01-05:10" comment="Added Firefox and Mozilla as affected products.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2006-02-01-09:07">INTERIM</status_change>
        <status_change date="2006-02-22-08:27">ACCEPTED</status_change>
      </dates>
      <description>The privileged "chrome" UI code in Firefox before 1.0.3 and Mozilla Suite before 1.7.7 allows remote attackers to gain privileges by overriding certain properties or methods of DOM nodes, as demonstrated using multiple attacks involving the eval function or the Script object.</description>
      <reference source="CVE">CVE-2005-1160</reference>
      <status>ACCEPTED</status>
      <version>6</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-658" comment="Mozilla Firefox version 1.0.2 or earlier is installed" negate="false"/>
          <criterion test_ref="cmp-651" comment="Mozilla Suite version 1.7.6 or earlier is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100018" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>mozilla</product>
        <product>Firefox</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <modified date="2005-10-11-04:20" comment="modified wrt-10045 - Removed doubled backslash from string literal test.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2005-10-26-06:46">ACCEPTED</status_change>
        <status_change date="2005-12-12-09:30">INTERIM</status_change>
        <status_change date="2005-12-28-04:28">ACCEPTED</status_change>
        <modified date="2006-02-01-05:11" comment="Added Firefox and Mozilla as affected products.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2006-02-01-09:07">INTERIM</status_change>
        <status_change date="2006-02-22-08:27">ACCEPTED</status_change>
      </dates>
      <description>The native implementations of InstallTrigger and other functions in Firefox before 1.0.3 and Mozilla Suite before 1.7.7 do not properly verify the types of objects being accessed, which causes the Javascript interpreter to continue execution at the wrong memory address, which may allow attackers to cause a denial of service (application crash) and possibly execute arbitrary code by passing objects of the wrong type.</description>
      <reference source="CVE">CVE-2005-1159</reference>
      <status>ACCEPTED</status>
      <version>5</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-658" comment="Mozilla Firefox version 1.0.2 or earlier is installed" negate="false"/>
          <criterion test_ref="cmp-651" comment="Mozilla Suite version 1.7.6 or earlier is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100019" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Firefox</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <modified date="2005-10-11-04:20" comment="modified wrt-10045 - Removed doubled backslash from string literal test.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2005-10-26-06:46">ACCEPTED</status_change>
        <status_change date="2005-12-12-09:30">INTERIM</status_change>
        <status_change date="2005-12-28-04:28">ACCEPTED</status_change>
        <modified date="2006-02-01-05:12" comment="Added Firefox as affected product.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2006-02-01-09:07">INTERIM</status_change>
        <status_change date="2006-02-22-08:27">ACCEPTED</status_change>
      </dates>
      <description>Multiple "missing security checks" in Firefox before 1.0.3 allow remote attackers to inject arbitrary Javascript into privileged pages using the _search target of the Firefox sidebar.</description>
      <reference source="CVE">CVE-2005-1158</reference>
      <status>ACCEPTED</status>
      <version>5</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-658" comment="Mozilla Firefox version 1.0.2 or earlier is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100020" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>mozilla</product>
        <product>Firefox</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <modified date="2005-10-11-04:20" comment="modified wrt-10045 - Removed doubled backslash from string literal test.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2005-10-26-06:46">ACCEPTED</status_change>
        <status_change date="2005-12-12-09:30">INTERIM</status_change>
        <status_change date="2005-12-28-04:28">ACCEPTED</status_change>
        <modified date="2006-02-01-05:14" comment="Added Firefox and Mozilla as affected products.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2006-02-01-09:07">INTERIM</status_change>
        <status_change date="2006-02-22-08:27">ACCEPTED</status_change>
      </dates>
      <description>Firefox before 1.0.3, Mozilla Suite before 1.7.7, and Netscape 7.2 allows remote attackers to execute arbitrary script and code via a new search plugin using sidebar.addSearchEngine, aka "Firesearching 1."</description>
      <reference source="CVE">CVE-2005-1156</reference>
      <status>ACCEPTED</status>
      <version>5</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-658" comment="Mozilla Firefox version 1.0.2 or earlier is installed" negate="false"/>
          <criterion test_ref="cmp-651" comment="Mozilla Suite version 1.7.6 or earlier is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100021" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>mozilla</product>
        <product>Firefox</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <modified date="2005-10-11-04:20" comment="modified wrt-10045 - Removed doubled backslash from string literal test.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2005-10-26-06:46">ACCEPTED</status_change>
        <status_change date="2005-12-12-09:30">INTERIM</status_change>
        <status_change date="2005-12-28-04:28">ACCEPTED</status_change>
        <modified date="2006-02-01-05:16" comment="Added Firefox, Mozilla as affected products.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2006-02-01-09:07">INTERIM</status_change>
        <status_change date="2006-02-22-08:27">ACCEPTED</status_change>
      </dates>
      <description>The favicon functionality in Firefox before 1.0.3 and Mozilla Suite before 1.7.7 allows remote attackers to execute arbitrary code via a &lt;LINK rel="icon"> tag with a javascript: URL in the href attribute, aka "Firelinking."</description>
      <reference source="CVE">CVE-2005-1155</reference>
      <status>ACCEPTED</status>
      <version>5</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-658" comment="Mozilla Firefox version 1.0.2 or earlier is installed" negate="false"/>
          <criterion test_ref="cmp-651" comment="Mozilla Suite version 1.7.6 or earlier is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100022" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>mozilla</product>
        <product>Firefox</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <modified date="2005-10-11-04:20" comment="modified wrt-10045 - Removed doubled backslash from string literal test.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2005-10-26-06:46">ACCEPTED</status_change>
        <status_change date="2005-12-12-09:30">INTERIM</status_change>
        <status_change date="2005-12-28-04:28">ACCEPTED</status_change>
        <modified date="2006-02-01-05:17" comment="Added Firefox, Mozilla as affected products.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2006-02-01-09:07">INTERIM</status_change>
        <status_change date="2006-02-22-08:27">ACCEPTED</status_change>
      </dates>
      <description>Firefox before 1.0.3 and Mozilla Suite before 1.7.7 allows remote attackers to execute arbitrary script in other domains via a setter function for a variable in the target domain, which is executed when the user visits that domain, aka "Cross-site scripting through global scope pollution."</description>
      <reference source="CVE">CVE-2005-1154</reference>
      <status>ACCEPTED</status>
      <version>5</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-658" comment="Mozilla Firefox version 1.0.2 or earlier is installed" negate="false"/>
          <criterion test_ref="cmp-651" comment="Mozilla Suite version 1.7.6 or earlier is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100023" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>mozilla</product>
        <product>Firefox</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <modified date="2005-10-11-04:20" comment="modified wrt-10045 - Removed doubled backslash from string literal test.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <modified date="2005-10-11-04:51" comment="modified wrt-10049 - Removed doubled backslash from string literal test.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2005-10-26-06:46">ACCEPTED</status_change>
        <status_change date="2005-12-12-09:30">INTERIM</status_change>
        <status_change date="2005-12-28-04:28">ACCEPTED</status_change>
        <modified date="2006-02-01-05:18" comment="Added Firefox, Mozilla as affected products.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2006-02-01-09:07">INTERIM</status_change>
        <status_change date="2006-02-22-08:27">ACCEPTED</status_change>
      </dates>
      <description>Firefox before 1.0.3 and Mozilla Suite before 1.7.7, when blocking a popup, allows remote attackers to execute arbitrary code via a javascript: URL that is executed when the user selects the "Show javascript" option.</description>
      <reference source="CVE">CVE-2005-1153</reference>
      <status>ACCEPTED</status>
      <version>5</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-658" comment="Mozilla Firefox version 1.0.2 or earlier is installed" negate="false"/>
          <criterion test_ref="cmp-651" comment="Mozilla Suite version 1.7.6 or earlier is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100024" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Firefox</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <modified date="2005-10-11-04:20" comment="modified wrt-10045 - Removed doubled backslash from string literal test.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2005-10-26-06:46">ACCEPTED</status_change>
        <status_change date="2005-12-12-09:30">INTERIM</status_change>
        <status_change date="2005-12-28-04:28">ACCEPTED</status_change>
        <modified date="2006-02-01-05:19" comment="Added Firefox as affected product.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2006-02-01-09:07">INTERIM</status_change>
        <status_change date="2006-02-22-08:27">ACCEPTED</status_change>
      </dates>
      <description>The Plugin Finder Service (PFS) in Firefox before 1.0.3 allows remote attackers to execute arbitrary code via a javascript: URL in the PLUGINSPAGE attribute of an EMBED tag.</description>
      <reference source="CVE">CVE-2005-0752</reference>
      <status>ACCEPTED</status>
      <version>5</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-658" comment="Mozilla Firefox version 1.0.2 or earlier is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100025" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>mozilla</product>
        <product>Firefox</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <modified date="2005-10-11-04:20" comment="modified wrt-10045 - Removed doubled backslash from string literal test.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2005-10-26-06:46">ACCEPTED</status_change>
        <status_change date="2005-12-12-09:30">INTERIM</status_change>
        <status_change date="2005-12-28-04:28">ACCEPTED</status_change>
        <modified date="2006-02-01-05:20" comment="Added Firefox, Mozilla as affected products.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2006-02-01-09:07">INTERIM</status_change>
        <status_change date="2006-02-22-08:27">ACCEPTED</status_change>
      </dates>
      <description>The find_replen function in jsstr.c in the the Javascript engine for Mozilla Suite 1.7.6, Firefox 1.0.1 and 1.0.2, and Netscape 7.2 allows remote attackers to read portions of heap memory in a Javascript string via the lambda replace method.</description>
      <reference source="CVE">CVE-2005-0989</reference>
      <status>ACCEPTED</status>
      <version>5</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-658" comment="Mozilla Firefox version 1.0.2 or earlier is installed" negate="false"/>
          <criterion test_ref="cmp-651" comment="Mozilla Suite version 1.7.6 or earlier is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100026" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>mozilla</product>
        <product>Firefox</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
        <status_change date="2005-12-12-09:30">INTERIM</status_change>
        <status_change date="2005-12-28-04:28">ACCEPTED</status_change>
        <modified date="2006-02-01-05:22" comment="Added Firefox, Mozilla as affected products.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2006-02-01-09:07">INTERIM</status_change>
        <status_change date="2006-02-22-08:27">ACCEPTED</status_change>
      </dates>
      <description>FireFox 1.0.1 and Mozilla before 1.7.6 do not sufficiently address all attack vectors for loading chrome files and hijacking drag and drop events, which allows remote attackers to execute arbitrary XUL code by tricking a user into dragging a scrollbar, a variant of CVE-2005-0527, aka "Firescrolling 2."</description>
      <reference source="CVE">CVE-2005-0401</reference>
      <status>ACCEPTED</status>
      <version>5</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-657" comment="Mozilla Firefox version 1.0.1 or earlier is installed" negate="false"/>
          <criterion test_ref="cmp-651" comment="Mozilla Suite version 1.7.6 or earlier is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100027" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Firefox</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
        <status_change date="2005-12-12-09:30">INTERIM</status_change>
        <status_change date="2005-12-28-04:28">ACCEPTED</status_change>
        <modified date="2006-02-01-05:23" comment="Added Firefox as affected product.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2006-02-01-09:07">INTERIM</status_change>
        <status_change date="2006-02-22-08:27">ACCEPTED</status_change>
      </dates>
      <description>Firefox before 1.0.2 allows remote attackers to execute arbitrary code by tricking a user into saving a page as a Firefox sidebar panel, then using the sidebar panel to inject Javascript into a privileged page.</description>
      <reference source="CVE">CVE-2005-0402</reference>
      <status>ACCEPTED</status>
      <version>5</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-657" comment="Mozilla Firefox version 1.0.1 or earlier is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100028" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>mozilla</product>
        <product>Firefox</product>
        <product>Thunderbird</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
        <status_change date="2005-12-12-09:30">INTERIM</status_change>
        <status_change date="2005-12-28-04:28">ACCEPTED</status_change>
        <modified date="2006-02-01-05:25" comment="Added Firefox, Mozilla, Thunderbird as affected products.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2006-02-01-09:07">INTERIM</status_change>
        <status_change date="2006-02-22-08:27">ACCEPTED</status_change>
      </dates>
      <description>Heap-based buffer overflow in GIF2.cpp in Firefox before 1.0.2, Mozilla before to 1.7.6, and Thunderbird before 1.0.2, and possibly other applications that use the same library, allows remote attackers to execute arbitrary code via a GIF image with a crafted Netscape extension 2 block and buffer size.</description>
      <reference source="CVE">CVE-2005-0399</reference>
      <status>ACCEPTED</status>
      <version>5</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-657" comment="Mozilla Firefox version 1.0.1 or earlier is installed" negate="false"/>
          <criterion test_ref="cmp-664" comment="Mozilla Thunderbird version 1.0 or earlier is installed" negate="false"/>
          <criterion test_ref="cmp-650" comment="Mozilla Suite version 1.7.5 or earlier is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100029" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>mozilla</product>
        <product>Firefox</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-04:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <modified date="2005-09-20-04:00" comment="Added CVE #">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-10-05-11:37">INTERIM</status_change>
        <status_change date="2005-10-26-06:46">ACCEPTED</status_change>
        <status_change date="2005-12-12-09:30">INTERIM</status_change>
        <status_change date="2005-12-28-04:28">ACCEPTED</status_change>
        <modified date="2006-02-01-05:26" comment="Added Firefox, Mozilla as affected products.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2006-02-01-09:07">INTERIM</status_change>
        <status_change date="2006-02-22-08:27">ACCEPTED</status_change>
      </dates>
      <description>The International Domain Name (IDN) support in Firefox 1.0, Camino .8.5, and Mozilla before 1.7.6 allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates in a way that uses homograph characters from other character sets, which facilitates phishing attacks.</description>
      <reference source="CVE">CVE-2005-0233</reference>
      <status>ACCEPTED</status>
      <version>5</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-656" comment="Mozilla  Firefox version 1.0 or earlier is installed" negate="false"/>
          <criterion test_ref="cmp-650" comment="Mozilla Suite version 1.7.5 or earlier is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100031" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>mozilla</product>
        <product>Firefox</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
        <status_change date="2005-12-12-09:30">INTERIM</status_change>
        <status_change date="2005-12-28-04:28">ACCEPTED</status_change>
        <modified date="2006-02-01-05:27" comment="Added Firefox, Mozilla as affected products.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2006-02-01-09:07">INTERIM</status_change>
        <status_change date="2006-02-22-08:27">ACCEPTED</status_change>
      </dates>
      <description>Firefox 1.0 allows remote attackers to execute arbitrary code via plugins that load "privileged content" into frames, as demonstrated using certain XUL events when a user drags a scrollbar two times, aka "Firescrolling."</description>
      <reference source="CVE">CVE-2005-0527</reference>
      <status>ACCEPTED</status>
      <version>5</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-656" comment="Mozilla  Firefox version 1.0 or earlier is installed" negate="false"/>
          <criterion test_ref="cmp-650" comment="Mozilla Suite version 1.7.5 or earlier is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100032" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>mozilla</product>
        <product>Firefox</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
        <status_change date="2005-12-12-09:30">INTERIM</status_change>
        <status_change date="2005-12-28-04:28">ACCEPTED</status_change>
        <modified date="2006-02-01-05:29" comment="Added Firefox, Mozilla as affected products.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2006-02-01-09:07">INTERIM</status_change>
        <status_change date="2006-02-22-08:27">ACCEPTED</status_change>
      </dates>
      <description>Firefox 1.0 does not invoke the Javascript Security Manager when a user drags a javascript: or data: URL to a tab, which allows remote attackers to bypass the security model, aka "firetabbing."</description>
      <reference source="CVE">CVE-2005-0231</reference>
      <status>ACCEPTED</status>
      <version>5</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-656" comment="Mozilla  Firefox version 1.0 or earlier is installed" negate="false"/>
          <criterion test_ref="cmp-650" comment="Mozilla Suite version 1.7.5 or earlier is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100033" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>mozilla</product>
        <product>Firefox</product>
        <product>Thunderbird</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
        <status_change date="2005-12-12-09:30">INTERIM</status_change>
        <status_change date="2005-12-28-04:28">ACCEPTED</status_change>
        <modified date="2006-02-01-05:30" comment="Added Firefox, Mozilla, Thunderbird as affected products.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2006-02-01-09:07">INTERIM</status_change>
        <status_change date="2006-02-22-08:27">ACCEPTED</status_change>
      </dates>
      <description>Firefox 1.0 does not prevent the user from dragging an executable file to the desktop when it has an image/gif content type but has a dangerous extension such as .bat or .exe, which allows remote attackers to bypass the intended restriction and execute arbitrary commands via malformed GIF files that can still be parsed by the Windows batch file parser, aka "firedragging."</description>
      <reference source="CVE">CVE-2005-0230</reference>
      <status>ACCEPTED</status>
      <version>5</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-656" comment="Mozilla  Firefox version 1.0 or earlier is installed" negate="false"/>
          <criterion test_ref="cmp-664" comment="Mozilla Thunderbird version 1.0 or earlier is installed" negate="false"/>
          <criterion test_ref="cmp-650" comment="Mozilla Suite version 1.7.5 or earlier is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100034" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>mozilla</product>
        <product>Firefox</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
        <status_change date="2005-12-12-09:30">INTERIM</status_change>
        <status_change date="2005-12-28-04:28">ACCEPTED</status_change>
        <modified date="2006-02-01-05:31" comment="Added Firefox, Mozilla as affected products.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2006-02-01-09:07">INTERIM</status_change>
        <status_change date="2006-02-22-08:27">ACCEPTED</status_change>
      </dates>
      <description>Firefox before 1.0.1 and Mozilla before 1.7.6, when displaying the HTTP Authentication dialog, do not change the focus to the tab that generated the prompt, which could facilitate spoofing and phishing attacks.</description>
      <reference source="CVE">CVE-2005-0584</reference>
      <status>ACCEPTED</status>
      <version>5</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-656" comment="Mozilla  Firefox version 1.0 or earlier is installed" negate="false"/>
          <criterion test_ref="cmp-650" comment="Mozilla Suite version 1.7.5 or earlier is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100035" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>mozilla</product>
        <product>Firefox</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
        <status_change date="2005-12-12-09:30">INTERIM</status_change>
        <status_change date="2005-12-28-04:28">ACCEPTED</status_change>
        <modified date="2006-02-01-05:32" comment="Added Firefox, Mozilla as affected products.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2006-02-01-09:07">INTERIM</status_change>
        <status_change date="2006-02-22-08:27">ACCEPTED</status_change>
      </dates>
      <description>Firefox before 1.0.1 and Mozilla before 1.7.6 truncates long sub-domains or paths for display, which may allow remote malicious web sites to spoof legitimate sites and facilitate phishing attacks.</description>
      <reference source="CVE">CVE-2005-0585</reference>
      <status>ACCEPTED</status>
      <version>5</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-656" comment="Mozilla  Firefox version 1.0 or earlier is installed" negate="false"/>
          <criterion test_ref="cmp-650" comment="Mozilla Suite version 1.7.5 or earlier is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100036" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>mozilla</product>
        <product>Firefox</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
        <status_change date="2005-12-12-09:30">INTERIM</status_change>
        <status_change date="2005-12-28-04:28">ACCEPTED</status_change>
        <modified date="2006-02-01-05:33" comment="Added Firefox, Mozilla as affected products.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2006-02-01-09:07">INTERIM</status_change>
        <status_change date="2006-02-22-08:27">ACCEPTED</status_change>
      </dates>
      <description>Firefox before 1.0.1 and Mozilla before 1.7.6 allows remote malicious web sites to spoof the extensions of files to download via the Content-Disposition header, which could be used to trick users into downloading dangerous content.</description>
      <reference source="CVE">CVE-2005-0586</reference>
      <status>ACCEPTED</status>
      <version>5</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-656" comment="Mozilla  Firefox version 1.0 or earlier is installed" negate="false"/>
          <criterion test_ref="cmp-650" comment="Mozilla Suite version 1.7.5 or earlier is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100037" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>mozilla</product>
        <product>Firefox</product>
        <product>Thunderbird</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
        <status_change date="2005-12-12-09:30">INTERIM</status_change>
        <status_change date="2005-12-28-04:28">ACCEPTED</status_change>
        <modified date="2006-02-01-05:34" comment="Added Firefox, Mozilla, Thunderbird as affected products.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2006-02-01-09:07">INTERIM</status_change>
        <status_change date="2006-02-22-08:27">ACCEPTED</status_change>
      </dates>
      <description>Firefox before 1.0.1 and Mozilla before 1.7.6 allows remote malicious web sites to overwrite arbitrary files by tricking the user into downloading a .LNK (link) file twice, which overwrites the file that was referenced in the first .LNK file.</description>
      <reference source="CVE">CVE-2005-0587</reference>
      <status>ACCEPTED</status>
      <version>5</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-656" comment="Mozilla  Firefox version 1.0 or earlier is installed" negate="false"/>
          <criterion test_ref="cmp-664" comment="Mozilla Thunderbird version 1.0 or earlier is installed" negate="false"/>
          <criterion test_ref="cmp-650" comment="Mozilla Suite version 1.7.5 or earlier is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100038" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>mozilla</product>
        <product>Firefox</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
        <status_change date="2005-12-12-09:30">INTERIM</status_change>
        <status_change date="2005-12-28-04:28">ACCEPTED</status_change>
        <modified date="2006-02-01-05:35" comment="Added Firefox, Mozilla as affected products.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2006-02-01-09:07">INTERIM</status_change>
        <status_change date="2006-02-22-08:27">ACCEPTED</status_change>
      </dates>
      <description>Firefox before 1.0.1 and Mozilla before 1.7.6 does not restrict xsl:include and xsl:import tags in XSLT stylesheets to the current domain, which allows remote attackers to determine the existence of files on the local system.</description>
      <reference source="CVE">CVE-2005-0588</reference>
      <status>ACCEPTED</status>
      <version>5</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-656" comment="Mozilla  Firefox version 1.0 or earlier is installed" negate="false"/>
          <criterion test_ref="cmp-650" comment="Mozilla Suite version 1.7.5 or earlier is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100039" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Firefox</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
        <status_change date="2005-12-12-09:30">INTERIM</status_change>
        <status_change date="2005-12-28-04:28">ACCEPTED</status_change>
        <modified date="2006-02-01-05:36" comment="Added Firefox as affected product.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2006-02-01-09:07">INTERIM</status_change>
        <status_change date="2006-02-22-08:27">ACCEPTED</status_change>
      </dates>
      <description>The Form Fill feature in Firefox before 1.0.1 allows remote attackers to steal potentially sensitive information via an input control that monitors the values that are generated by the autocomplete capability.</description>
      <reference source="CVE">CVE-2005-0589</reference>
      <status>ACCEPTED</status>
      <version>5</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-656" comment="Mozilla  Firefox version 1.0 or earlier is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100040" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>mozilla</product>
        <product>Firefox</product>
        <product>Thunderbird</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
        <status_change date="2005-12-12-09:30">INTERIM</status_change>
        <status_change date="2005-12-28-04:28">ACCEPTED</status_change>
        <modified date="2006-02-01-05:37" comment="Added Firefox, Mozilla, Thunderbird as affected products.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2006-02-01-09:07">INTERIM</status_change>
        <status_change date="2006-02-22-08:27">ACCEPTED</status_change>
      </dates>
      <description>String handling functions in Mozilla 1.7.3, Firefox 1.0, and Thunderbird before 1.0.2, such as the nsTSubstring_CharT::Replace function, do not properly check the return values of other functions that resize the string, which allows remote attackers to cause a denial of service and possibly execute arbitrary code by forcing an out-of-memory state that causes a reallocation to fail and return a pointer to a fixed address, which leads to heap corruption.</description>
      <reference source="CVE">CVE-2005-0255</reference>
      <status>ACCEPTED</status>
      <version>5</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-656" comment="Mozilla  Firefox version 1.0 or earlier is installed" negate="false"/>
          <criterion test_ref="cmp-664" comment="Mozilla Thunderbird version 1.0 or earlier is installed" negate="false"/>
          <criterion test_ref="cmp-650" comment="Mozilla Suite version 1.7.5 or earlier is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100041" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>mozilla</product>
        <product>Firefox</product>
        <product>Thunderbird</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
        <status_change date="2005-12-12-09:30">INTERIM</status_change>
        <status_change date="2005-12-28-04:28">ACCEPTED</status_change>
        <modified date="2006-02-01-05:38" comment="Added Firefox, Mozilla, Thunderbird as affected products.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2006-02-01-09:07">INTERIM</status_change>
        <status_change date="2006-02-22-08:27">ACCEPTED</status_change>
      </dates>
      <description>The installation confirmation dialog in Firefox before 1.0.1, Thunderbird before 1.0.1, and Mozilla before 1.7.6 allows remote attackers to use InstallTrigger to spoof the hostname of the host performing the installation via a long "user:pass" sequence in the URL, which appears before the real hostname.</description>
      <reference source="CVE">CVE-2005-0590</reference>
      <status>ACCEPTED</status>
      <version>5</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-656" comment="Mozilla  Firefox version 1.0 or earlier is installed" negate="false"/>
          <criterion test_ref="cmp-664" comment="Mozilla Thunderbird version 1.0 or earlier is installed" negate="false"/>
          <criterion test_ref="cmp-650" comment="Mozilla Suite version 1.7.5 or earlier is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100042" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>mozilla</product>
        <product>Firefox</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
        <status_change date="2005-12-12-09:30">INTERIM</status_change>
        <status_change date="2005-12-28-04:28">ACCEPTED</status_change>
        <modified date="2006-01-31-06:29" comment="Updated reference to CVE-2005-0591.  Set product to Mozilla.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <modified date="2006-02-01-05:40" comment="Added Firefox to affected products.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2006-02-01-09:07">INTERIM</status_change>
        <status_change date="2006-02-22-08:27">ACCEPTED</status_change>
      </dates>
      <description>Firefox before 1.0.1 allows remote attackers to spoof the (1) security and (2) download modal dialog boxes, which could be used to trick users into executing script or downloading and executing a file, aka "Firespoofing."</description>
      <reference source="CVE">CVE-2005-0591</reference>
      <status>ACCEPTED</status>
      <version>5</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-656" comment="Mozilla  Firefox version 1.0 or earlier is installed" negate="false"/>
          <criterion test_ref="cmp-650" comment="Mozilla Suite version 1.7.5 or earlier is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100043" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>mozilla</product>
        <product>Firefox</product>
        <product>Thunderbird</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
        <status_change date="2005-12-12-09:30">INTERIM</status_change>
        <status_change date="2005-12-28-04:28">ACCEPTED</status_change>
        <modified date="2006-02-01-05:41" comment="Added Firefox, Mozilla, Thunderbird as affected products.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2006-02-01-09:07">INTERIM</status_change>
        <status_change date="2006-02-22-08:27">ACCEPTED</status_change>
      </dates>
      <description>Heap-based buffer overflow in the UTF8ToNewUnicode function for Firefox before 1.0.1 and Mozilla before 1.7.6 might allow remote attackers to cause a denial of service (crash) or execute arbitrary code via invalid sequences in a UTF8 encoded string that result in a zero length value.</description>
      <reference source="CVE">CVE-2005-0592</reference>
      <status>ACCEPTED</status>
      <version>5</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-656" comment="Mozilla  Firefox version 1.0 or earlier is installed" negate="false"/>
          <criterion test_ref="cmp-664" comment="Mozilla Thunderbird version 1.0 or earlier is installed" negate="false"/>
          <criterion test_ref="cmp-650" comment="Mozilla Suite version 1.7.5 or earlier is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100044" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>mozilla</product>
        <product>Firefox</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
        <status_change date="2005-12-12-09:30">INTERIM</status_change>
        <status_change date="2005-12-28-04:28">ACCEPTED</status_change>
        <modified date="2006-02-01-05:42" comment="Added Firefox, Mozilla as affected products.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2006-02-01-09:07">INTERIM</status_change>
        <status_change date="2006-02-22-08:27">ACCEPTED</status_change>
      </dates>
      <description>Firefox before 1.0.1 and Mozilla before 1.7.6 allows remote attackers to spoof the SSL "secure site" lock icon via (1) a web site that does not finish loading, which shows the lock of the previous site, (2) a non-HTTP server that uses SSL, which causes the lock to be displayed when the SSL handshake is completed, or (3) a URL that generates an HTTP 204 error, which updates the icon and location information but does not change the display of the original site.</description>
      <reference source="CVE">CVE-2005-0593</reference>
      <status>ACCEPTED</status>
      <version>5</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-656" comment="Mozilla  Firefox version 1.0 or earlier is installed" negate="false"/>
          <criterion test_ref="cmp-650" comment="Mozilla Suite version 1.7.5 or earlier is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100045" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>mozilla</product>
        <product>Firefox</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
        <status_change date="2005-12-12-09:30">INTERIM</status_change>
        <status_change date="2005-12-28-04:28">ACCEPTED</status_change>
        <modified date="2006-02-01-05:43" comment="Added Firefox, Mozilla as affected products.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2006-02-01-09:07">INTERIM</status_change>
        <status_change date="2006-02-22-08:27">ACCEPTED</status_change>
      </dates>
      <description>Mozilla before 1.7.6, and Firefox before 1.0.1, allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the "window injection" vulnerability.</description>
      <reference source="CVE">CVE-2004-1156</reference>
      <status>ACCEPTED</status>
      <version>5</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-656" comment="Mozilla  Firefox version 1.0 or earlier is installed" negate="false"/>
          <criterion test_ref="cmp-650" comment="Mozilla Suite version 1.7.5 or earlier is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100046" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Firefox</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
        <status_change date="2005-12-12-09:30">INTERIM</status_change>
        <status_change date="2005-12-28-04:28">ACCEPTED</status_change>
        <modified date="2006-02-01-05:44" comment="Added Firefox as affected product.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2006-02-01-09:07">INTERIM</status_change>
        <status_change date="2006-02-22-08:27">ACCEPTED</status_change>
      </dates>
      <description>Firefox before 1.0 allows the user to store a (1) javascript: or (2) data: URLs as a Livefeed bookmark, then executes it in the security context of the currently loaded page when the user later accesses the bookmark, which could allow remote attackers to execute arbitrary code.</description>
      <reference source="CVE">CVE-2005-0150</reference>
      <status>ACCEPTED</status>
      <version>5</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-655" comment="Mozilla Firefox version 0.9 or earlier is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100047" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>mozilla</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
        <status_change date="2005-12-12-09:30">INTERIM</status_change>
        <status_change date="2005-12-28-04:28">ACCEPTED</status_change>
        <modified date="2006-01-25-04:03" comment="Added Mozilla as affected product.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2006-01-25-07:27">INTERIM</status_change>
        <status_change date="2006-02-22-08:27">ACCEPTED</status_change>
      </dates>
      <description>Thunderbird 0.6 through 0.9 and Mozilla 1.7 through 1.7.3 does not obey the network.cookie.disableCookieForMailNews preference, which could allow remote attackers bypass the user's intended privacy and security policy by using cookies in e-mail messages.</description>
      <reference source="CVE">CVE-2005-0149</reference>
      <status>ACCEPTED</status>
      <version>5</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-663" comment="Mozilla Thunderbird version 0.6-0.9 or earlier is installed" negate="false"/>
          <criterion test_ref="cmp-649" comment="Mozilla Suite version 1.7-1.7.3 is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100048" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Thunderbird</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
        <status_change date="2005-12-12-09:30">INTERIM</status_change>
        <status_change date="2005-12-28-04:28">ACCEPTED</status_change>
        <modified date="2006-02-01-05:46" comment="Added Thunderbird as affected product.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2006-02-01-09:07">INTERIM</status_change>
        <status_change date="2006-02-22-08:27">ACCEPTED</status_change>
      </dates>
      <description>Thunderbird before 0.9, when running on Windows systems, uses the default handler when processing javascript: links, which invokes Internet Explorer and may expose the Thunderbird user to vulnerabilities in the version of Internet Explorer that is installed on the user's system.  NOTE: since the invocation between multiple products is a common practice, and the vulnerabilities inherent in multi-product interactions are not easily enumerable, this issue might be REJECTED in the future.</description>
      <reference source="CVE">CVE-2005-0148</reference>
      <status>ACCEPTED</status>
      <version>5</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-662" comment="Mozilla Thunderbird version 0.8 or earlier is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100049" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>mozilla</product>
        <product>Firefox</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
        <status_change date="2005-12-12-09:30">INTERIM</status_change>
        <status_change date="2005-12-28-04:28">ACCEPTED</status_change>
        <modified date="2006-02-01-05:47" comment="Added Firefox, Mozilla as affected products.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2006-02-01-09:07">INTERIM</status_change>
        <status_change date="2006-02-22-08:27">ACCEPTED</status_change>
      </dates>
      <description>Firefox before 1.0 and Mozilla before 1.7.5, when configured to use a proxy, respond to 407 proxy auth requests from arbitrary servers, which allows remote attackers to steal NTLM or SPNEGO credentials.</description>
      <reference source="CVE">CVE-2005-0147</reference>
      <status>ACCEPTED</status>
      <version>5</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-655" comment="Mozilla Firefox version 0.9 or earlier is installed" negate="false"/>
          <criterion test_ref="cmp-648" comment="Mozilla Suite version 1.7.4 or earlier is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100050" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
      </affected>
      <dates>
        <submitted date="2005-08-16-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
        <status_change date="2005-12-12-09:30">INTERIM</status_change>
        <status_change date="2005-12-28-04:28">ACCEPTED</status_change>
      </dates>
      <description>Firefox before 1.0 and Mozilla before 1.7.5 allows inactive (background) tabs to launch dialog boxes, which can allow remote attackers to spoof the dialog boxes from web sites in other windows and facilitate phishing attacks, aka the "Dialog Box Spoofing Vulnerability."</description>
      <reference source="CVE">CVE-2004-1380</reference>
      <status>ACCEPTED</status>
      <version>4</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-655" comment="Mozilla Firefox version 0.9 or earlier is installed" negate="false"/>
          <criterion test_ref="cmp-648" comment="Mozilla Suite version 1.7.4 or earlier is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100051" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Firefox</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
        <status_change date="2005-12-12-09:30">INTERIM</status_change>
        <status_change date="2005-12-28-04:28">ACCEPTED</status_change>
        <modified date="2006-02-01-05:49" comment="Added Firefox as affected product.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2006-02-01-09:07">INTERIM</status_change>
        <status_change date="2006-02-22-08:27">ACCEPTED</status_change>
      </dates>
      <description>Firefox before 1.0 does not properly distinguish between user-generated and synthetic click events, which allows remote attackers to use Javascript to bypass the file download prompt when the user uses the Alt-click feature.</description>
      <reference source="CVE">CVE-2005-0145</reference>
      <status>ACCEPTED</status>
      <version>5</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-655" comment="Mozilla Firefox version 0.9 or earlier is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100052" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>mozilla</product>
        <product>Thunderbird</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-04:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <modified date="2005-09-20-04:00" comment="Added CVE #">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-10-05-11:37">INTERIM</status_change>
        <status_change date="2005-10-26-06:46">ACCEPTED</status_change>
        <status_change date="2005-12-12-09:30">INTERIM</status_change>
        <status_change date="2005-12-28-04:28">ACCEPTED</status_change>
        <modified date="2006-02-01-05:51" comment="Added Mozilla, Thunderbird as affected products.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2006-02-01-09:07">INTERIM</status_change>
        <status_change date="2006-02-22-08:27">ACCEPTED</status_change>
      </dates>
      <description>Heap-based buffer overflow in MSG_UnEscapeSearchUrl in nsNNTPProtocol.cpp for Mozilla 1.7.3 and earlier allows remote attackers to cause a denial of service (application crash) via an NNTP URL (news:) with a trailing '\' (backslash) character, which prevents a string from being NULL terminated.</description>
      <reference source="CVE">CVE-2004-1316</reference>
      <status>ACCEPTED</status>
      <version>5</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-662" comment="Mozilla Thunderbird version 0.8 or earlier is installed" negate="false"/>
          <criterion test_ref="cmp-648" comment="Mozilla Suite version 1.7.4 or earlier is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100053" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>mozilla</product>
        <product>Firefox</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
        <status_change date="2005-12-12-09:30">INTERIM</status_change>
        <status_change date="2005-12-28-04:28">ACCEPTED</status_change>
        <modified date="2006-02-01-05:52" comment="Added Firefox, Mozilla as affected products.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2006-02-01-09:07">INTERIM</status_change>
        <status_change date="2006-02-22-08:27">ACCEPTED</status_change>
      </dates>
      <description>Firefox before 1.0 and Mozilla before 1.7.5 allow inactive (background) tabs to focus on input being entered in the active tab, as originally reported using form fields, which allows remote attackers to steal sensitive data that is intended for other sites, which could facilitate phishing attacks.</description>
      <reference source="CVE">CVE-2004-1381</reference>
      <status>ACCEPTED</status>
      <version>5</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-655" comment="Mozilla Firefox version 0.9 or earlier is installed" negate="false"/>
          <criterion test_ref="cmp-648" comment="Mozilla Suite version 1.7.4 or earlier is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100054" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>mozilla</product>
        <product>Firefox</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
        <status_change date="2005-12-12-09:30">INTERIM</status_change>
        <status_change date="2005-12-28-04:28">ACCEPTED</status_change>
        <modified date="2006-02-01-05:54" comment="Added Firefox, Mozilla as affected products.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2006-02-01-09:07">INTERIM</status_change>
        <status_change date="2006-02-22-08:27">ACCEPTED</status_change>
      </dates>
      <description>Firefox before 1.0 and Mozilla before 1.7.5 display the secure site lock icon when a view-source: URL references a secure SSL site while an insecure page is being loaded, which could facilitate phishing attacks.</description>
      <reference source="CVE">CVE-2005-0144</reference>
      <status>ACCEPTED</status>
      <version>5</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-655" comment="Mozilla Firefox version 0.9 or earlier is installed" negate="false"/>
          <criterion test_ref="cmp-648" comment="Mozilla Suite version 1.7.4 or earlier is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100055" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>mozilla</product>
        <product>Firefox</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
        <status_change date="2005-12-12-09:30">INTERIM</status_change>
        <status_change date="2005-12-28-04:28">ACCEPTED</status_change>
        <modified date="2006-02-01-05:55" comment="Added Firefox, Mozilla as affected products.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2006-02-01-09:07">INTERIM</status_change>
        <status_change date="2006-02-22-08:27">ACCEPTED</status_change>
      </dates>
      <description>Firefox before 1.0 and Mozilla before 1.7.5 display the SSL lock icon when an insecure page loads a binary file from a trusted site, which could facilitate phishing attacks.</description>
      <reference source="CVE">CVE-2005-0143</reference>
      <status>ACCEPTED</status>
      <version>5</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-655" comment="Mozilla Firefox version 0.9 or earlier is installed" negate="false"/>
          <criterion test_ref="cmp-648" comment="Mozilla Suite version 1.7.4 or earlier is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100056" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>mozilla</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-04:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <modified date="2005-09-19-04:00" comment="modified wrt-10060 - Removed extra \\ in key">
          <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
        </modified>
        <status_change date="2005-10-05-11:37">INTERIM</status_change>
        <status_change date="2005-10-26-06:46">ACCEPTED</status_change>
        <status_change date="2005-12-12-09:30">INTERIM</status_change>
        <status_change date="2005-12-28-04:28">ACCEPTED</status_change>
      </dates>
      <description>Firefox 0.9, Thunderbird 0.6 and other versions before 0.9, and Mozilla 1.7 before 1.7.5 save temporary files with world-readable permissions, which allows local users to read certain web content or attachments that belong to other users, e.g. content that is managed by helper applications such as PDF.</description>
      <reference source="CVE">CVE-2005-0142</reference>
      <status>ACCEPTED</status>
      <version>4</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-649" comment="Mozilla Suite version 1.7-1.7.3 is installed" negate="false"/>
          <criterion test_ref="cmp-654" comment="Mozilla Firefox version 0.9 is installed" negate="false"/>
          <criterion test_ref="cmp-661" comment="Mozilla Thunderbird version 0.6-0.8 is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100057" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>mozilla</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
        <status_change date="2005-12-12-09:30">INTERIM</status_change>
        <status_change date="2005-12-28-04:28">ACCEPTED</status_change>
      </dates>
      <description>Firefox before 1.0 and Mozilla before 1.7.5 allow remote attackers to load local files via links "with a custom getter and toString method" that are middle-clicked by the user to be opened in a new tab.</description>
      <reference source="CVE">CVE-2005-0141</reference>
      <status>ACCEPTED</status>
      <version>4</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-655" comment="Mozilla Firefox version 0.9 or earlier is installed" negate="false"/>
          <criterion test_ref="cmp-648" comment="Mozilla Suite version 1.7.4 or earlier is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100073" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Stack-based buffer overflow in the Plug and Play (PnP) service for Microsoft Windows 2000 and Windows XP Service Pack 1 allows remote attackers to execute arbitrary code via a crafted packet, and local users to gain privileges via a malicious application, as exploited by the Zotob (aka Mytob) worm.</description>
      <reference source="CVE">CVE-2005-1983</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-2" comment="Windows XP is installed" negate="false"/>
          <criterion test_ref="wrt-70" comment="64-Bit version of Windows is installed" negate="false"/>
          <criterion test_ref="wft-10010" comment="the version of umpnpmgr.dll is less than 5.2.3790.2477" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100077" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the Print Spooler service (Spoolsv.exe) for Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code via a malicious message.</description>
      <reference source="CVE">CVE-2005-1984</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-2" comment="Windows XP is installed" negate="false"/>
          <criterion test_ref="wrt-4" comment="Win2K/XP/2003 service pack 1 is installed" negate="false"/>
          <criterion test_ref="wft-10013" comment="the version of spoolsv.exe is less than 5.1.2600.1699" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100081" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Internet Explorer</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Unknown vulnerability in Internet Explorer 5.0, 5.5, and 6.0 allows remote attackers to obtain information and possibly execute code when browsing from a web site to a web folder view using WebDAV, aka "Web Folder Behaviors Cross-Domain Vulnerability".</description>
      <reference source="CVE">CVE-2005-1989</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wrt-4" comment="Win2K/XP/2003 service pack 1 is installed" negate="false"/>
          <criterion test_ref="wft-10016" comment="the version of mshtml.dll is less than 6.0.3790.2491" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100082" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Internet Explorer</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Unknown vulnerability in Internet Explorer 5.0, 5.5, and 6.0 allows remote attackers to obtain information and possibly execute code when browsing from a web site to a web folder view using WebDAV, aka "Web Folder Behaviors Cross-Domain Vulnerability".</description>
      <reference source="CVE">CVE-2005-1989</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wrt-4" comment="Win2K/XP/2003 service pack 1 is installed" negate="false"/>
          <criterion test_ref="wft-10016" comment="the version of mshtml.dll is less than 6.0.3790.2491" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100084" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the Telephony Application Programming Interface (TAPI) for Microsoft Windows 98, Windows 98 SE, Windows ME, Windows 2000, Windows XP, and Windows Server 2003 allows attackers elevate privileges or execute arbitrary code via a crafted message.</description>
      <reference source="CVE">CVE-2005-0058</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-2" comment="Windows XP is installed" negate="false"/>
          <criterion test_ref="wrt-4" comment="Win2K/XP/2003 service pack 1 is installed" negate="false"/>
          <criterion test_ref="wrt-70" comment="64-Bit version of Windows is installed" negate="true"/>
          <criterion test_ref="wft-10018" comment="the version of tapisrv.dll is less than 5.1.2600.1715" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100085" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the Telephony Application Programming Interface (TAPI) for Microsoft Windows 98, Windows 98 SE, Windows ME, Windows 2000, Windows XP, and Windows Server 2003 allows attackers elevate privileges or execute arbitrary code via a crafted message.</description>
      <reference source="CVE">CVE-2005-0058</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-2" comment="Windows XP is installed" negate="false"/>
          <criterion test_ref="wrt-250" comment="Win2K/XP/2003 service pack 2 is installed" negate="false"/>
          <criterion test_ref="wft-10019" comment="the version of tapisrv.dll is less than 5.1.2600.2716" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100086" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the Telephony Application Programming Interface (TAPI) for Microsoft Windows 98, Windows 98 SE, Windows ME, Windows 2000, Windows XP, and Windows Server 2003 allows attackers elevate privileges or execute arbitrary code via a crafted message.</description>
      <reference source="CVE">CVE-2005-0058</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-2" comment="Windows XP is installed" negate="false"/>
          <criterion test_ref="wrt-4" comment="Win2K/XP/2003 service pack 1 is installed" negate="false"/>
          <criterion test_ref="wrt-70" comment="64-Bit version of Windows is installed" negate="false"/>
          <criterion test_ref="wft-10020" comment="the version of tapisrv.dll is less than 5.2.3790.2483" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100088" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the Telephony Application Programming Interface (TAPI) for Microsoft Windows 98, Windows 98 SE, Windows ME, Windows 2000, Windows XP, and Windows Server 2003 allows attackers elevate privileges or execute arbitrary code via a crafted message.</description>
      <reference source="CVE">CVE-2005-0058</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wrt-4" comment="Win2K/XP/2003 service pack 1 is installed" negate="false"/>
          <criterion test_ref="wft-10020" comment="the version of tapisrv.dll is less than 5.2.3790.2483" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100092" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>The Microsoft Windows kernel in Microsoft Windows 2000 Server, Windows XP, and Windows Server 2003 allows remote attackers to cause a denial of service (crash) via crafted Remote Desktop Protocol (RDP) requests.</description>
      <reference source="CVE">CVE-2005-1218</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-2" comment="Windows XP is installed" negate="false"/>
          <criterion test_ref="wrt-4" comment="Win2K/XP/2003 service pack 1 is installed" negate="false"/>
          <criterion test_ref="wrt-70" comment="64-Bit version of Windows is installed" negate="false"/>
          <criterion test_ref="wft-10025" comment="the version of rdpwd.sys is less than 5.2.3790.2465" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100095" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Unknown vulnerability in Microsoft Windows 2000 Server and Windows Server 2003 domain controllers allows remote authenticated users to cause a denial of service (system crash) via a crafted Kerberos message.</description>
      <reference source="CVE">CVE-2005-1981</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-212" comment="Windows 2000 Service Pack 4 (or later) is installed" negate="false"/>
          <criterion test_ref="wft-10027" comment="the version of kerberos.dll is less than 5.0.2195.7053" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100096" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Unknown vulnerability in the PKINIT Protocol for Microsoft Windows 2000, Windows XP, and Windows Server 2003 could allow a local user to obtain information and spoof a server via a man-in-the-middle (MITM) attack between a client and a domain controller when PKINIT smart card authentication is being used.</description>
      <reference source="CVE">CVE-2005-1982</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-212" comment="Windows 2000 Service Pack 4 (or later) is installed" negate="false"/>
          <criterion test_ref="wft-10027" comment="the version of kerberos.dll is less than 5.0.2195.7053" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100097" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Unknown vulnerability in Microsoft Windows 2000 Server and Windows Server 2003 domain controllers allows remote authenticated users to cause a denial of service (system crash) via a crafted Kerberos message.</description>
      <reference source="CVE">CVE-2005-1981</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-2" comment="Windows XP is installed" negate="false"/>
          <criterion test_ref="wrt-4" comment="Win2K/XP/2003 service pack 1 is installed" negate="false"/>
          <criterion test_ref="wrt-70" comment="64-Bit version of Windows is installed" negate="true"/>
          <criterion test_ref="wft-10028" comment="the version of kerberos.dll is less than 5.1.2600.1701" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100098" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Unknown vulnerability in the PKINIT Protocol for Microsoft Windows 2000, Windows XP, and Windows Server 2003 could allow a local user to obtain information and spoof a server via a man-in-the-middle (MITM) attack between a client and a domain controller when PKINIT smart card authentication is being used.</description>
      <reference source="CVE">CVE-2005-1982</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-2" comment="Windows XP is installed" negate="false"/>
          <criterion test_ref="wrt-4" comment="Win2K/XP/2003 service pack 1 is installed" negate="false"/>
          <criterion test_ref="wrt-70" comment="64-Bit version of Windows is installed" negate="true"/>
          <criterion test_ref="wft-10028" comment="the version of kerberos.dll is less than 5.1.2600.1701" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100099" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Unknown vulnerability in Microsoft Windows 2000 Server and Windows Server 2003 domain controllers allows remote authenticated users to cause a denial of service (system crash) via a crafted Kerberos message.</description>
      <reference source="CVE">CVE-2005-1981</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-2" comment="Windows XP is installed" negate="false"/>
          <criterion test_ref="wrt-250" comment="Win2K/XP/2003 service pack 2 is installed" negate="false"/>
          <criterion test_ref="wft-10029" comment="the version of kerberos.dll is less than 5.1.2600.2698" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100100" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Unknown vulnerability in the PKINIT Protocol for Microsoft Windows 2000, Windows XP, and Windows Server 2003 could allow a local user to obtain information and spoof a server via a man-in-the-middle (MITM) attack between a client and a domain controller when PKINIT smart card authentication is being used.</description>
      <reference source="CVE">CVE-2005-1982</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-2" comment="Windows XP is installed" negate="false"/>
          <criterion test_ref="wrt-250" comment="Win2K/XP/2003 service pack 2 is installed" negate="false"/>
          <criterion test_ref="wft-10029" comment="the version of kerberos.dll is less than 5.1.2600.2698" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100101" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Unknown vulnerability in Microsoft Windows 2000 Server and Windows Server 2003 domain controllers allows remote authenticated users to cause a denial of service (system crash) via a crafted Kerberos message.</description>
      <reference source="CVE">CVE-2005-1981</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-2" comment="Windows XP is installed" negate="false"/>
          <criterion test_ref="wrt-4" comment="Win2K/XP/2003 service pack 1 is installed" negate="false"/>
          <criterion test_ref="wrt-70" comment="64-Bit version of Windows is installed" negate="false"/>
          <criterion test_ref="wft-10030" comment="the version of kerberos.dll is less than 5.2.3790.2464" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100102" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows XP</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Unknown vulnerability in the PKINIT Protocol for Microsoft Windows 2000, Windows XP, and Windows Server 2003 could allow a local user to obtain information and spoof a server via a man-in-the-middle (MITM) attack between a client and a domain controller when PKINIT smart card authentication is being used.</description>
      <reference source="CVE">CVE-2005-1982</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-2" comment="Windows XP is installed" negate="false"/>
          <criterion test_ref="wrt-4" comment="Win2K/XP/2003 service pack 1 is installed" negate="false"/>
          <criterion test_ref="wrt-70" comment="64-Bit version of Windows is installed" negate="false"/>
          <criterion test_ref="wft-10030" comment="the version of kerberos.dll is less than 5.2.3790.2464" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100103" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Unknown vulnerability in Microsoft Windows 2000 Server and Windows Server 2003 domain controllers allows remote authenticated users to cause a denial of service (system crash) via a crafted Kerberos message.</description>
      <reference source="CVE">CVE-2005-1981</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wrt-10026" comment="Win2K/XP/2003 is patched" negate="true"/>
          <criterion test_ref="wft-10031" comment="the version of kerberos.dll is less than 5.2.3790.347" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100104" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Unknown vulnerability in the PKINIT Protocol for Microsoft Windows 2000, Windows XP, and Windows Server 2003 could allow a local user to obtain information and spoof a server via a man-in-the-middle (MITM) attack between a client and a domain controller when PKINIT smart card authentication is being used.</description>
      <reference source="CVE">CVE-2005-1982</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wrt-10026" comment="Win2K/XP/2003 is patched" negate="true"/>
          <criterion test_ref="wft-10031" comment="the version of kerberos.dll is less than 5.2.3790.347" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100105" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Unknown vulnerability in Microsoft Windows 2000 Server and Windows Server 2003 domain controllers allows remote authenticated users to cause a denial of service (system crash) via a crafted Kerberos message.</description>
      <reference source="CVE">CVE-2005-1981</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wrt-4" comment="Win2K/XP/2003 service pack 1 is installed" negate="false"/>
          <criterion test_ref="wft-10030" comment="the version of kerberos.dll is less than 5.2.3790.2464" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100106" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Unknown vulnerability in the PKINIT Protocol for Microsoft Windows 2000, Windows XP, and Windows Server 2003 could allow a local user to obtain information and spoof a server via a man-in-the-middle (MITM) attack between a client and a domain controller when PKINIT smart card authentication is being used.</description>
      <reference source="CVE">CVE-2005-1982</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="wrt-61" comment="Windows Server 2003 is installed" negate="false"/>
          <criterion test_ref="wrt-4" comment="Win2K/XP/2003 service pack 1 is installed" negate="false"/>
          <criterion test_ref="wft-10030" comment="the version of kerberos.dll is less than 5.2.3790.2464" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100107" class="vulnerability">
      <affected family="windows">
        <windows:platform>Microsoft Windows NT</windows:platform>
        <windows:platform>Microsoft Windows 2000</windows:platform>
        <windows:platform>Microsoft Windows XP</windows:platform>
        <windows:platform>Microsoft Windows Server 2003</windows:platform>
        <product>mozilla</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-04:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <modified date="2005-09-07-04:00" comment="Added description">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <modified date="2005-09-19-04:05" comment="modified wrt-10048 - Removed extra \\ in key">
          <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
        </modified>
        <status_change date="2005-10-12-05:49">INTERIM</status_change>
        <status_change date="2005-11-16-08:02">ACCEPTED</status_change>
      </dates>
      <description>Firefox before 1.0.5 and Mozilla before 1.7.9 allows a child frame to call top.focus and other methods in a parent frame, even when the parent is in a different domain, which violates the same origin policy and allows remote attackers to steal sensitive information such as cookies and passwords from web sites whose child frames do not verify that they are in the same domain as their parents.</description>
      <reference source="CVE">CVE-2005-2266</reference>
      <status>ACCEPTED</status>
      <version>4</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="wrt-10043" comment="Firefox version 1.0.4 or earlier is installed" negate="false"/>
          <criterion test_ref="wrt-10048" comment="Mozilla Suite version 1.7.8 or earlier is installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100108" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Apache</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-09-21-01:33">DRAFT</status_change>
        <status_change date="2005-10-12-05:49">INTERIM</status_change>
        <status_change date="2005-11-16-08:02">ACCEPTED</status_change>
      </dates>
      <description>mod_digest for Apache before 1.3.31 does not properly verify the nonce of a client response by using a AuthNonce secret.</description>
      <reference source="CVE">CVE-2003-0987</reference>
      <status>ACCEPTED</status>
      <version>5</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-30002" comment="Solaris 8 (SPARC) meets Sun Alert ID 101555 criteria." negate="false"/>
          <criterion test_ref="cmp-30003" comment="Solaris 8 (x86) meets Sun Alert ID 101555 criteria." negate="false"/>
          <criterion test_ref="cmp-30004" comment="Solaris 9 (SPARC) meets Sun Alert ID 101555 criteria." negate="false"/>
          <criterion test_ref="cmp-30005" comment="Solaris 9 (x86) meets Sun Alert ID 101555 criteria." negate="false"/>
          <criterion test_ref="uct-10" comment="Apache running (httpd)" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100109" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Apache</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-09-21-01:33">DRAFT</status_change>
        <status_change date="2005-10-12-05:49">INTERIM</status_change>
        <status_change date="2005-11-16-08:02">ACCEPTED</status_change>
      </dates>
      <description>Apache does not filter terminal escape sequences from its error logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related to escape sequences.</description>
      <reference source="CVE">CVE-2003-0020</reference>
      <status>ACCEPTED</status>
      <version>5</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-30002" comment="Solaris 8 (SPARC) meets Sun Alert ID 101555 criteria." negate="false"/>
          <criterion test_ref="cmp-30003" comment="Solaris 8 (x86) meets Sun Alert ID 101555 criteria." negate="false"/>
          <criterion test_ref="cmp-30004" comment="Solaris 9 (SPARC) meets Sun Alert ID 101555 criteria." negate="false"/>
          <criterion test_ref="cmp-30005" comment="Solaris 9 (x86) meets Sun Alert ID 101555 criteria." negate="false"/>
          <criterion test_ref="uct-10" comment="Apache running (httpd)" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100110" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Apache</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-09-21-01:33">DRAFT</status_change>
        <status_change date="2005-10-12-05:49">INTERIM</status_change>
        <status_change date="2005-11-16-08:02">ACCEPTED</status_change>
      </dates>
      <description>Apache 1.4.x before 1.3.30, and 2.0.x before 2.0.49, when using multiple listening sockets on certain platforms, allows remote attackers to cause a denial of service (blocked new connections) via a "short-lived connection on a rarely-accessed listening socket."</description>
      <reference source="CVE">CVE-2004-0174</reference>
      <status>ACCEPTED</status>
      <version>5</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-30002" comment="Solaris 8 (SPARC) meets Sun Alert ID 101555 criteria." negate="false"/>
          <criterion test_ref="cmp-30003" comment="Solaris 8 (x86) meets Sun Alert ID 101555 criteria." negate="false"/>
          <criterion test_ref="cmp-30004" comment="Solaris 9 (SPARC) meets Sun Alert ID 101555 criteria." negate="false"/>
          <criterion test_ref="cmp-30005" comment="Solaris 9 (x86) meets Sun Alert ID 101555 criteria." negate="false"/>
          <criterion test_ref="uct-10" comment="Apache running (httpd)" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100111" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Apache</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-09-21-01:33">DRAFT</status_change>
        <status_change date="2005-10-12-05:49">INTERIM</status_change>
        <status_change date="2005-11-16-08:02">ACCEPTED</status_change>
      </dates>
      <description>mod_access in Apache 1.3 before 1.3.30, when running big-endian 64-bit platforms, does not properly parse Allow/Deny rules using IP addresses without a netmask, which could allow remote attackers to bypass intended access restrictions.</description>
      <reference source="CVE">CVE-2003-0993</reference>
      <status>ACCEPTED</status>
      <version>5</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-30002" comment="Solaris 8 (SPARC) meets Sun Alert ID 101555 criteria." negate="false"/>
          <criterion test_ref="cmp-30004" comment="Solaris 9 (SPARC) meets Sun Alert ID 101555 criteria." negate="false"/>
          <criterion test_ref="uct-10" comment="Apache running (httpd)" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100112" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Apache</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-09-21-01:33">DRAFT</status_change>
        <status_change date="2005-10-12-05:49">INTERIM</status_change>
        <status_change date="2005-11-16-08:02">ACCEPTED</status_change>
      </dates>
      <description>Heap-based buffer overflow in proxy_util.c for mod_proxy in Apache 1.3.25 to 1.3.31 allows remote attackers to cause a denial of service (process crash) and possibly execute arbitrary code via a negative Content-Length HTTP header field, which causes a large amount of data to be copied.</description>
      <reference source="CVE">CVE-2004-0492</reference>
      <status>ACCEPTED</status>
      <version>5</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-30002" comment="Solaris 8 (SPARC) meets Sun Alert ID 101555 criteria." negate="false"/>
          <criterion test_ref="cmp-30003" comment="Solaris 8 (x86) meets Sun Alert ID 101555 criteria." negate="false"/>
          <criterion test_ref="cmp-30004" comment="Solaris 9 (SPARC) meets Sun Alert ID 101555 criteria." negate="false"/>
          <criterion test_ref="cmp-30005" comment="Solaris 9 (x86) meets Sun Alert ID 101555 criteria." negate="false"/>
          <criterion test_ref="uct-10" comment="Apache running (httpd)" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100113" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>XDM</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-04:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <modified date="2005-09-20-04:00" comment="Added CVE #">
          <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
        </modified>
        <status_change date="2005-09-21-01:33">DRAFT</status_change>
        <status_change date="2005-10-12-05:49">INTERIM</status_change>
        <status_change date="2005-11-16-08:02">ACCEPTED</status_change>
      </dates>
      <description>X Display Manager (XDM) on Solaris 8 allows remote attackers to cause a denial of service (XDM crash) via an invalid X Display Manager Control Protocol (XDMCP) request.</description>
      <reference source="CVE">CVE-2004-1347</reference>
      <status>ACCEPTED</status>
      <version>5</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="cmp-30006" comment="Solaris 8 (SPARC) meets Sun Alert ID 101549 criteria." negate="false"/>
          <criterion test_ref="cmp-30007" comment="Solaris 8 (x86) meets Sun Alert ID 101549 criteria." negate="false"/>
          <criterion test_ref="cmp-30008" comment="Solaris 9 (SPARC) meets Sun Alert ID 101549 criteria." negate="false"/>
          <criterion test_ref="cmp-30009" comment="Solaris 9 (x86) meets Sun Alert ID 101549 criteria." negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100114" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <solaris:platform>Sun Solaris 10</solaris:platform>
        <product>libtiff</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-09-21-01:33">DRAFT</status_change>
        <status_change date="2005-10-12-05:49">INTERIM</status_change>
        <status_change date="2005-11-16-08:02">ACCEPTED</status_change>
      </dates>
      <description>Multiple vulnerabilities in the RLE (run length encoding) decoders for libtiff 3.6.1 and earlier, related to buffer overflows and integer overflows, allow remote attackers to execute arbitrary code via TIFF files.</description>
      <reference source="CVE">CVE-2004-0803</reference>
      <status>ACCEPTED</status>
      <version>5</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-30014" comment="Solaris 7 (SPARC) meets Sun Alert ID 101677 criteria." negate="false"/>
          <criterion test_ref="cmp-30015" comment="Solaris 7 (x86) meets Sun Alert ID 101677 criteria." negate="false"/>
          <criterion test_ref="cmp-30016" comment="Solaris 8 (SPARC) meets Sun Alert ID 101677 criteria." negate="false"/>
          <criterion test_ref="cmp-30017" comment="Solaris 8 (x86) meets Sun Alert ID 101677 criteria." negate="false"/>
          <criterion test_ref="cmp-30018" comment="Solaris 9 (SPARC) meets Sun Alert ID 101677 criteria." negate="false"/>
          <criterion test_ref="cmp-30019" comment="Solaris 9 (x86) meets Sun Alert ID 101677 criteria." negate="false"/>
          <criterion test_ref="cmp-30020" comment="Solaris 10 (SPARC) meets Sun Alert ID 101677 criteria." negate="false"/>
          <criterion test_ref="cmp-30021" comment="Solaris 10 (x86) meets Sun Alert ID 101677 criteria." negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100115" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <solaris:platform>Sun Solaris 10</solaris:platform>
        <product>libtiff</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-09-21-01:33">DRAFT</status_change>
        <status_change date="2005-10-12-05:49">INTERIM</status_change>
        <status_change date="2005-11-16-08:02">ACCEPTED</status_change>
      </dates>
      <description>Vulnerability in tif_dirread.c for libtiff allows remote attackers to cause a denial of service (application crash) via a TIFF image that causes a divide-by-zero error when the number of row bytes is zero, a different vulnerability than CVE-2005-2452.</description>
      <reference source="CVE">CVE-2004-0804</reference>
      <status>ACCEPTED</status>
      <version>5</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-30014" comment="Solaris 7 (SPARC) meets Sun Alert ID 101677 criteria." negate="false"/>
          <criterion test_ref="cmp-30015" comment="Solaris 7 (x86) meets Sun Alert ID 101677 criteria." negate="false"/>
          <criterion test_ref="cmp-30016" comment="Solaris 8 (SPARC) meets Sun Alert ID 101677 criteria." negate="false"/>
          <criterion test_ref="cmp-30017" comment="Solaris 8 (x86) meets Sun Alert ID 101677 criteria." negate="false"/>
          <criterion test_ref="cmp-30018" comment="Solaris 9 (SPARC) meets Sun Alert ID 101677 criteria." negate="false"/>
          <criterion test_ref="cmp-30019" comment="Solaris 9 (x86) meets Sun Alert ID 101677 criteria." negate="false"/>
          <criterion test_ref="cmp-30020" comment="Solaris 10 (SPARC) meets Sun Alert ID 101677 criteria." negate="false"/>
          <criterion test_ref="cmp-30021" comment="Solaris 10 (x86) meets Sun Alert ID 101677 criteria." negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100116" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <solaris:platform>Sun Solaris 10</solaris:platform>
        <product>libtiff</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-09-21-01:33">DRAFT</status_change>
        <status_change date="2005-10-12-05:49">INTERIM</status_change>
        <status_change date="2005-11-16-08:02">ACCEPTED</status_change>
      </dates>
      <description>Multiple integer overflows in libtiff 3.6.1 and earlier allow remote attackers to cause a denial of service (crash or memory corruption) via TIFF images that lead to incorrect malloc calls.</description>
      <reference source="CVE">CVE-2004-0886</reference>
      <status>ACCEPTED</status>
      <version>5</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-30014" comment="Solaris 7 (SPARC) meets Sun Alert ID 101677 criteria." negate="false"/>
          <criterion test_ref="cmp-30015" comment="Solaris 7 (x86) meets Sun Alert ID 101677 criteria." negate="false"/>
          <criterion test_ref="cmp-30016" comment="Solaris 8 (SPARC) meets Sun Alert ID 101677 criteria." negate="false"/>
          <criterion test_ref="cmp-30017" comment="Solaris 8 (x86) meets Sun Alert ID 101677 criteria." negate="false"/>
          <criterion test_ref="cmp-30018" comment="Solaris 9 (SPARC) meets Sun Alert ID 101677 criteria." negate="false"/>
          <criterion test_ref="cmp-30019" comment="Solaris 9 (x86) meets Sun Alert ID 101677 criteria." negate="false"/>
          <criterion test_ref="cmp-30020" comment="Solaris 10 (SPARC) meets Sun Alert ID 101677 criteria." negate="false"/>
          <criterion test_ref="cmp-30021" comment="Solaris 10 (x86) meets Sun Alert ID 101677 criteria." negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL100117" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <solaris:platform>Sun Solaris 10</solaris:platform>
        <product>libtiff</product>
      </affected>
      <dates>
        <submitted date="2005-08-16-12:00">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2005-09-21-01:33">DRAFT</status_change>
        <status_change date="2005-10-12-05:49">INTERIM</status_change>
        <status_change date="2005-11-16-08:02">ACCEPTED</status_change>
      </dates>
      <description>Integer overflow in (1) tif_dirread.c and (2) tif_fax3.c for libtiff 3.5.7 and 3.7.0 allows remote attackers to execute arbitrary code via a TIFF file containing a TIFF_ASCII or TIFF_UNDEFINED directory entry with a -1 entry count, which leads to a heap-based buffer overflow.</description>
      <reference source="CVE">CVE-2004-1308</reference>
      <status>ACCEPTED</status>
      <version>5</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-30014" comment="Solaris 7 (SPARC) meets Sun Alert ID 101677 criteria." negate="false"/>
          <criterion test_ref="cmp-30015" comment="Solaris 7 (x86) meets Sun Alert ID 101677 criteria." negate="false"/>
          <criterion test_ref="cmp-30016" comment="Solaris 8 (SPARC) meets Sun Alert ID 101677 criteria." negate="false"/>
          <criterion test_ref="cmp-30017" comment="Solaris 8 (x86) meets Sun Alert ID 101677 criteria." negate="false"/>
          <criterion test_ref="cmp-30018" comment="Solaris 9 (SPARC) meets Sun Alert ID 101677 criteria." negate="false"/>
          <criterion test_ref="cmp-30019" comment="Solaris 9 (x86) meets Sun Alert ID 101677 criteria." negate="false"/>
          <criterion test_ref="cmp-30020" comment="Solaris 10 (SPARC) meets Sun Alert ID 101677 criteria." negate="false"/>
          <criterion test_ref="cmp-30021" comment="Solaris 10 (x86) meets Sun Alert ID 101677 criteria." negate="false"/>
        </software>
      </criteria>
    </definition>
  </definitions>
  <tests>
    <patch_test id="spt-10016" comment="Patch 119901-01 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">119901</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">01</version>
      </data>
    </patch_test>
    <compound_test id="cmp-30021" comment="Solaris 10 (x86) meets Sun Alert ID 101677 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-10001"/>
      <subtest test_ref="uut-10002"/>
      <subtest test_ref="sat-10002"/>
      <subtest negate="true" test_ref="spt-10016"/>
    </compound_test>
    <patch_test id="spt-10015" comment="Patch 119900-01 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">119900</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">01</version>
      </data>
    </patch_test>
    <compound_test id="cmp-30020" comment="Solaris 10 (SPARC) meets Sun Alert ID 101677 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-10001"/>
      <subtest test_ref="uut-10003"/>
      <subtest test_ref="sat-10002"/>
      <subtest negate="true" test_ref="spt-10015"/>
    </compound_test>
    <patch_test id="spt-10014" comment="Patch 114220-11 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">114220</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">11</version>
      </data>
    </patch_test>
    <compound_test id="cmp-30011" comment="Solaris 9 (x86) supporting CDE criteria for Sun Alert ID 101677." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="sat-47"/>
      <subtest negate="true" test_ref="spt-10014"/>
    </compound_test>
    <compound_test id="cmp-30013" comment="Solaris 9 (x86) supporting criteria for Sun Alert ID 101677." operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="cmp-30011"/>
      <subtest test_ref="sat-10002"/>
      <subtest test_ref="sat-10003"/>
    </compound_test>
    <compound_test id="cmp-30019" comment="Solaris 9 (x86) meets Sun Alert ID 101677 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-6"/>
      <subtest test_ref="uut-10002"/>
      <subtest test_ref="cmp-30013"/>
    </compound_test>
    <package_test id="sat-10003" comment="Pkg SUNWTiffx is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <pkginst operator="equals">SUNWTiffx</pkginst>
      </object>
    </package_test>
    <package_test id="sat-10002" comment="Pkg SUNWTiff is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <pkginst operator="equals">SUNWTiff</pkginst>
      </object>
    </package_test>
    <patch_test id="spt-10013" comment="Patch 114219-11 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">114219</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">11</version>
      </data>
    </patch_test>
    <compound_test id="cmp-30010" comment="Solaris 9 (SPARC) supporting CDE criteria for Sun Alert ID 101677." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="sat-47"/>
      <subtest negate="true" test_ref="spt-10013"/>
    </compound_test>
    <compound_test id="cmp-30012" comment="Solaris 9 (SPARC) supporting criteria for Sun Alert ID 101677." operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="cmp-30010"/>
      <subtest test_ref="sat-10002"/>
      <subtest test_ref="sat-10003"/>
    </compound_test>
    <compound_test id="cmp-30018" comment="Solaris 9 (SPARC) meets Sun Alert ID 101677 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-6"/>
      <subtest test_ref="uut-10003"/>
      <subtest test_ref="cmp-30012"/>
    </compound_test>
    <patch_test id="spt-10012" comment="Patch 109932-10 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">109932</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">10</version>
      </data>
    </patch_test>
    <compound_test id="cmp-30017" comment="Solaris 8 (x86) meets Sun Alert ID 101677 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-4"/>
      <subtest test_ref="uut-10002"/>
      <subtest negate="true" test_ref="spt-10012"/>
    </compound_test>
    <patch_test id="spt-10011" comment="Patch 109931-10 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">109931</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">10</version>
      </data>
    </patch_test>
    <compound_test id="cmp-30016" comment="Solaris 8 (SPARC) meets Sun Alert ID 101677 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-4"/>
      <subtest test_ref="uut-10003"/>
      <subtest negate="true" test_ref="spt-10011"/>
    </compound_test>
    <patch_test id="spt-10010" comment="Patch 118954-02 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">118954</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">02</version>
      </data>
    </patch_test>
    <compound_test id="cmp-30015" comment="Solaris 7 (x86) meets Sun Alert ID 101677 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-5"/>
      <subtest test_ref="uut-10002"/>
      <subtest negate="true" test_ref="spt-10010"/>
    </compound_test>
    <patch_test id="spt-10009" comment="Patch 118953-02 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">118953</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">02</version>
      </data>
    </patch_test>
    <compound_test id="cmp-30014" comment="Solaris 7 (SPARC) meets Sun Alert ID 101677 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-5"/>
      <subtest test_ref="uut-10003"/>
      <subtest negate="true" test_ref="spt-10009"/>
    </compound_test>
    <patch_test id="spt-10008" comment="Patch 112786-27 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">112786</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">27</version>
      </data>
    </patch_test>
    <compound_test id="cmp-30009" comment="Solaris 9 (x86) meets Sun Alert ID 101549 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-6"/>
      <subtest test_ref="uut-10002"/>
      <subtest negate="true" test_ref="spt-10008"/>
    </compound_test>
    <patch_test id="spt-10007" comment="Patch 112785-38 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">112785</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">38</version>
      </data>
    </patch_test>
    <compound_test id="cmp-30008" comment="Solaris 9 (SPARC) meets Sun Alert ID 101549 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-6"/>
      <subtest test_ref="uut-10003"/>
      <subtest negate="true" test_ref="spt-10007"/>
    </compound_test>
    <patch_test id="spt-10006" comment="Patch 111845-03 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">111845</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">03</version>
      </data>
    </patch_test>
    <compound_test id="cmp-30007" comment="Solaris 8 (x86) meets Sun Alert ID 101549 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-4"/>
      <subtest test_ref="uut-10002"/>
      <subtest negate="true" test_ref="spt-10006"/>
    </compound_test>
    <patch_test id="spt-10005" comment="Patch 111844-03 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">111844</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">03</version>
      </data>
    </patch_test>
    <compound_test id="cmp-30006" comment="Solaris 8 (SPARC) meets Sun Alert ID 101549 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-4"/>
      <subtest test_ref="uut-10003"/>
      <subtest negate="true" test_ref="spt-10005"/>
    </compound_test>
    <patch_test id="spt-10004" comment="Patch 114145-04 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">114145</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">04</version>
      </data>
    </patch_test>
    <compound_test id="cmp-30005" comment="Solaris 9 (x86) meets Sun Alert ID 101555 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-6"/>
      <subtest test_ref="uut-10002"/>
      <subtest negate="true" test_ref="spt-10004"/>
    </compound_test>
    <patch_test id="spt-10002" comment="Patch 113146-05 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">113146</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">05</version>
      </data>
    </patch_test>
    <compound_test id="cmp-30004" comment="Solaris 9 (SPARC) meets Sun Alert ID 101555 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-6"/>
      <subtest test_ref="uut-10003"/>
      <subtest negate="true" test_ref="spt-10002"/>
    </compound_test>
    <patch_test id="spt-10003" comment="Patch 116974-02 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">116974</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">02</version>
      </data>
    </patch_test>
    <compound_test id="cmp-30003" comment="Solaris 8 (x86) meets Sun Alert ID 101555 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-4"/>
      <subtest test_ref="uut-10002"/>
      <subtest negate="true" test_ref="spt-10003"/>
    </compound_test>
    <patch_test id="spt-10001" comment="Patch 116973-02 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">116973</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">02</version>
      </data>
    </patch_test>
    <compound_test id="cmp-30002" comment="Solaris 8 (SPARC) meets Sun Alert ID 101555 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-4"/>
      <subtest test_ref="uut-10003"/>
      <subtest negate="true" test_ref="spt-10001"/>
    </compound_test>
    <file_test id="wft-10031" comment="the version of kerberos.dll is less than 5.2.3790.347" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\kerberos.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>2</minor>
          <build>3790</build>
          <private>347</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-10030" comment="the version of kerberos.dll is less than 5.2.3790.2464" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\kerberos.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>2</minor>
          <build>3790</build>
          <private>2464</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-10029" comment="the version of kerberos.dll is less than 5.1.2600.2698" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\kerberos.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>2698</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-10028" comment="the version of kerberos.dll is less than 5.1.2600.1701" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\kerberos.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>1701</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-10027" comment="the version of kerberos.dll is less than 5.0.2195.7053" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\kerberos.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>2195</build>
          <private>7053</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-10025" comment="the version of rdpwd.sys is less than 5.2.3790.2465" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\drivers\rdpwd.sys</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>2</minor>
          <build>3790</build>
          <private>2465</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-10020" comment="the version of tapisrv.dll is less than 5.2.3790.2483" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\tapisrv.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>2</minor>
          <build>3790</build>
          <private>2483</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-10019" comment="the version of tapisrv.dll is less than 5.1.2600.2716" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\tapisrv.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>2716</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-10018" comment="the version of tapisrv.dll is less than 5.1.2600.1715" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\tapisrv.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>1715</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-10016" comment="the version of mshtml.dll is less than 6.0.3790.2491" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mshtml.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>3790</build>
          <private>2491</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-10013" comment="the version of spoolsv.exe is less than 5.1.2600.1699" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\spoolsv.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>1699</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-10010" comment="the version of umpnpmgr.dll is less than 5.2.3790.2477" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\umpnpmgr.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>2</minor>
          <build>3790</build>
          <private>2477</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-604" comment="Mozilla Thunderbird version 0.6-0.8 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key datatype="string" operator="pattern match">SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Mozilla Thunderbird \(0\.[6-8]\)</key>
        <name datatype="string" operator="equals">DisplayName</name>
      </object>
      <data operation="AND">
        <value datatype="string" operator="pattern match">Mozilla Thunderbird \(0\.[6-8]\)</value>
      </data>
    </registry_test>
    <registry_test id="wrt-10060" comment="Mozilla Thunderbird version 0.6-0.8 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key datatype="string" operator="equals">SOFTWARE\Mozilla\Mozilla Thunderbird</key>
        <name datatype="string" operator="equals">CurrentVersion</name>
      </object>
      <data operation="AND">
        <value datatype="string" operator="pattern match">0\.[6-8]($|\s).*</value>
      </data>
    </registry_test>
    <compound_test id="cmp-661" comment="Mozilla Thunderbird version 0.6-0.8 is installed" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="wrt-10060"/>
      <subtest test_ref="wrt-604"/>
    </compound_test>
    <registry_test id="wrt-597" comment="Mozilla Firefox version 0.9 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key datatype="string" operator="pattern match">SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Mozilla Firefox \(0\.9.*\)</key>
        <name datatype="string" operator="equals">DisplayName</name>
      </object>
      <data operation="AND">
        <value datatype="string" operator="pattern match">Mozilla Firefox \(0\.9.*\)</value>
      </data>
    </registry_test>
    <registry_test id="wrt-10059" comment="Firefox version 0.9 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key datatype="string" operator="equals">SOFTWARE\Mozilla\Mozilla Firefox</key>
        <name datatype="string" operator="equals">CurrentVersion</name>
      </object>
      <data operation="AND">
        <value datatype="string" operator="pattern match">0\.9($|\s).*</value>
      </data>
    </registry_test>
    <compound_test id="cmp-654" comment="Mozilla Firefox version 0.9 is installed" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="wrt-10059"/>
      <subtest test_ref="wrt-597"/>
    </compound_test>
    <registry_test id="wrt-437" comment="Mozilla Suite version 1.7.4 or earlier is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key datatype="string" operator="pattern match">SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Mozilla (\([0-1]\.[0-7]\)|\([0-1]\.[0-7]\.[0-4]\))</key>
        <name datatype="string" operator="equals">DisplayName</name>
      </object>
      <data operation="AND">
        <value datatype="string" operator="pattern match">Mozilla (\([0-1]\.[0-7]\)|\([0-1]\.[0-7]\.[0-4]\))</value>
      </data>
    </registry_test>
    <registry_test id="wrt-10056" comment="Mozilla Suite version 1.7.4 or earlier is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key datatype="string" operator="equals">SOFTWARE\mozilla.org\Mozilla</key>
        <name datatype="string" operator="equals">CurrentVersion</name>
      </object>
      <data operation="AND">
        <value datatype="string" operator="pattern match">[0-1]\.[0-7]($|\s).*|[0-1]\.[0-7]\.[0-4]($|\s).*</value>
      </data>
    </registry_test>
    <compound_test id="cmp-648" comment="Mozilla Suite version 1.7.4 or earlier is installed" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="wrt-10056"/>
      <subtest test_ref="wrt-437"/>
    </compound_test>
    <registry_test id="wrt-610" comment="Mozilla Thunderbird version 0.8 or earlier is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key datatype="string" operator="pattern match">SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Mozilla Thunderbird \(0\.[0-8]\)</key>
        <name datatype="string" operator="equals">DisplayName</name>
      </object>
      <data operation="AND">
        <value datatype="string" operator="pattern match">Mozilla Thunderbird \(0\.[0-8]\)</value>
      </data>
    </registry_test>
    <registry_test id="wrt-10055" comment="Mozilla Thunderbird version 0.8 or earlier is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key datatype="string" operator="equals">SOFTWARE\Mozilla\Mozilla Thunderbird</key>
        <name datatype="string" operator="equals">CurrentVersion</name>
      </object>
      <data operation="AND">
        <value datatype="string" operator="pattern match">0\.[0-8]($|\s).*</value>
      </data>
    </registry_test>
    <compound_test id="cmp-662" comment="Mozilla Thunderbird version 0.8 or earlier is installed" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="wrt-10055"/>
      <subtest test_ref="wrt-610"/>
    </compound_test>
    <registry_test id="wrt-453" comment="Mozilla Suite version 1.7-1.7.3 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key datatype="string" operator="pattern match">SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Mozilla (\(1\.7\)|\(1\.[0-7]\.[0-3]\))</key>
        <name datatype="string" operator="equals">DisplayName</name>
      </object>
      <data operation="AND">
        <value datatype="string" operator="pattern match">Mozilla (\(1\.7\)|\(1\.[0-7]\.[0-3]\))</value>
      </data>
    </registry_test>
    <registry_test id="wrt-10058" comment="Mozilla Suite version 1.7-1.7.3 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key datatype="string" operator="equals">SOFTWARE\mozilla.org\Mozilla</key>
        <name datatype="string" operator="equals">CurrentVersion</name>
      </object>
      <data operation="AND">
        <value datatype="string" operator="pattern match">1\.7($|\s).*|1\.7\.[0-3]($|\s).*</value>
      </data>
    </registry_test>
    <compound_test id="cmp-649" comment="Mozilla Suite version 1.7-1.7.3 is installed" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="wrt-10058"/>
      <subtest test_ref="wrt-453"/>
    </compound_test>
    <registry_test id="wrt-611" comment="Mozilla Thunderbird version 0.6-0.9 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key datatype="string" operator="pattern match">SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Mozilla Thunderbird \(0\.[6-9]\)</key>
        <name datatype="string" operator="equals">DisplayName</name>
      </object>
      <data operation="AND">
        <value datatype="string" operator="pattern match">Mozilla Thunderbird \(0\.[6-9]\)</value>
      </data>
    </registry_test>
    <registry_test id="wrt-10057" comment="Mozilla Thunderbird version 0.6-0.9 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key datatype="string" operator="equals">SOFTWARE\Mozilla\Mozilla Thunderbird</key>
        <name datatype="string" operator="equals">CurrentVersion</name>
      </object>
      <data operation="AND">
        <value datatype="string" operator="pattern match">0\.[6-9]($|\s).*</value>
      </data>
    </registry_test>
    <compound_test id="cmp-663" comment="Mozilla Thunderbird version 0.6-0.9 or earlier is installed" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="wrt-10057"/>
      <subtest test_ref="wrt-611"/>
    </compound_test>
    <registry_test id="wrt-598" comment="Mozilla Firefox version 0.9 or earlier is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key datatype="string" operator="pattern match">SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Mozilla Firefox \(0\.[0-9].*\)</key>
        <name datatype="string" operator="equals">DisplayName</name>
      </object>
      <data operation="AND">
        <value datatype="string" operator="pattern match">Mozilla Firefox \(0\.[0-9].*\)</value>
      </data>
    </registry_test>
    <registry_test id="wrt-10054" comment="Firefox version 0.9 or earlier is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key datatype="string" operator="equals">SOFTWARE\Mozilla\Mozilla Firefox</key>
        <name datatype="string" operator="equals">CurrentVersion</name>
      </object>
      <data operation="AND">
        <value datatype="string" operator="pattern match">0\.[0-9]($|\s).*</value>
      </data>
    </registry_test>
    <compound_test id="cmp-655" comment="Mozilla Firefox version 0.9 or earlier is installed" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="wrt-10054"/>
      <subtest test_ref="wrt-598"/>
    </compound_test>
    <registry_test id="wrt-599" comment="Mozilla Firefox version 1.0 or earlier is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key datatype="string" operator="pattern match">SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Mozilla Firefox (\(0\.[0-9].*\)|\(1\.0\))</key>
        <name datatype="string" operator="equals">DisplayName</name>
      </object>
      <data operation="AND">
        <value datatype="string" operator="pattern match">Mozilla Firefox (\(0\.[0-9].*\)|\(1\.0\))</value>
      </data>
    </registry_test>
    <registry_test id="wrt-10047" comment="Firefox version 1.0 or earlier is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key datatype="string" operator="equals">SOFTWARE\Mozilla\Mozilla Firefox</key>
        <name datatype="string" operator="equals">CurrentVersion</name>
      </object>
      <data operation="AND">
        <value datatype="string" operator="pattern match">[0-1]\.0($|\s).*</value>
      </data>
    </registry_test>
    <compound_test id="cmp-656" comment="Mozilla  Firefox version 1.0 or earlier is installed" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="wrt-10047"/>
      <subtest test_ref="wrt-599"/>
    </compound_test>
    <registry_test id="wrt-487" comment="Mozilla Suite version 1.7.5 or earlier is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key datatype="string" operator="pattern match">SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Mozilla (\([0-1]\.[0-7]\)|\([0-1]\.[0-7]\.[0-5]\))</key>
        <name datatype="string" operator="equals">DisplayName</name>
      </object>
      <data operation="AND">
        <value datatype="string" operator="pattern match">Mozilla (\([0-1]\.[0-7]\)|\([0-1]\.[0-7]\.[0-5]\))</value>
      </data>
    </registry_test>
    <registry_test id="wrt-10050" comment="Mozilla Suite version 1.7.5 or earlier is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key datatype="string" operator="equals">SOFTWARE\mozilla.org\Mozilla</key>
        <name datatype="string" operator="equals">CurrentVersion</name>
      </object>
      <data operation="AND">
        <value datatype="string" operator="pattern match">[0-1]\.[0-7]($|\s).*|[0-1]\.[0-7]\.[0-5]($|\s).*</value>
      </data>
    </registry_test>
    <compound_test id="cmp-650" comment="Mozilla Suite version 1.7.5 or earlier is installed" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="wrt-10050"/>
      <subtest test_ref="wrt-487"/>
    </compound_test>
    <registry_test id="wrt-612" comment="Mozilla Thunderbird version 1.0 or earlier is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key datatype="string" operator="pattern match">SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Mozilla Thunderbird (\(0\.[0-9]\)|\(1\.0\))</key>
        <name datatype="string" operator="equals">DisplayName</name>
      </object>
      <data operation="AND">
        <value datatype="string" operator="pattern match">Mozilla Thunderbird (\(0\.[0-9]\)|\(1\.0\))</value>
      </data>
    </registry_test>
    <registry_test id="wrt-10052" comment="Mozilla Thunderbird version 1.0 or earlier is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key datatype="string" operator="equals">SOFTWARE\Mozilla\Mozilla Thunderbird</key>
        <name datatype="string" operator="equals">CurrentVersion</name>
      </object>
      <data operation="AND">
        <value datatype="string" operator="pattern match">[0-1]\.0($|\s).*</value>
      </data>
    </registry_test>
    <compound_test id="cmp-664" comment="Mozilla Thunderbird version 1.0 or earlier is installed" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="wrt-10052"/>
      <subtest test_ref="wrt-612"/>
    </compound_test>
    <registry_test id="wrt-600" comment="Mozilla Firefox version 1.0.1 or earlier is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key datatype="string" operator="pattern match">SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Mozilla Firefox (\(0\.[0-9].*\)|\(1\.0\)|\(1\.0\.[0-1]\))</key>
        <name datatype="string" operator="equals">DisplayName</name>
      </object>
      <data operation="AND">
        <value datatype="string" operator="pattern match">Mozilla Firefox (\(0\.[0-9].*\)|\(1\.0\)|\(1\.0\.[0-1]\))</value>
      </data>
    </registry_test>
    <registry_test id="wrt-10046" comment="Firefox version 1.0.1 or earlier is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key datatype="string" operator="equals">SOFTWARE\Mozilla\Mozilla Firefox</key>
        <name datatype="string" operator="equals">CurrentVersion</name>
      </object>
      <data operation="AND">
        <value datatype="string" operator="pattern match">[0-1]\.0($|\s).*|[0-1]\.0\.[0-1]($|\s).*</value>
      </data>
    </registry_test>
    <compound_test id="cmp-657" comment="Mozilla Firefox version 1.0.1 or earlier is installed" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="wrt-10046"/>
      <subtest test_ref="wrt-600"/>
    </compound_test>
    <registry_test id="wrt-590" comment="Mozilla Suite version 1.7.6 or earlier is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key datatype="string" operator="pattern match">SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Mozilla (\([0-1]\.[0-7]\)|\([0-1]\.[0-7]\.[0-6]\))</key>
        <name datatype="string" operator="equals">DisplayName</name>
      </object>
      <data operation="AND">
        <value datatype="string" operator="pattern match">Mozilla (\([0-1]\.[0-7]\)|\([0-1]\.[0-7]\.[0-6]\))</value>
      </data>
    </registry_test>
    <registry_test id="wrt-10049" comment="Mozilla Suite version 1.7.6 or earlier is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key datatype="string" operator="equals">SOFTWARE\mozilla.org\Mozilla</key>
        <name datatype="string" operator="equals">CurrentVersion</name>
      </object>
      <data operation="AND">
        <value datatype="string" operator="pattern match">[0-1]\.[0-7]($|\s).*|[0-1]\.[0-7]\.[0-6]($|\s).*</value>
      </data>
    </registry_test>
    <compound_test id="cmp-651" comment="Mozilla Suite version 1.7.6 or earlier is installed" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="wrt-10049"/>
      <subtest test_ref="wrt-590"/>
    </compound_test>
    <registry_test id="wrt-596" comment="Mozilla Suite version 1.7.7 or earlier is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key datatype="string" operator="pattern match">SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Mozilla (\([0-1]\.[0-7]\)|\([0-1]\.[0-7]\.[0-7]\))</key>
        <name datatype="string" operator="equals">DisplayName</name>
      </object>
      <data operation="AND">
        <value datatype="string" operator="pattern match">Mozilla (\([0-1]\.[0-7]\)|\([0-1]\.[0-7]\.[0-7]\))</value>
      </data>
    </registry_test>
    <compound_test id="cmp-653" comment="Mozilla Suite version 1.7.7 or earlier is installed" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="wrt-10025"/>
      <subtest test_ref="wrt-596"/>
    </compound_test>
    <registry_test id="wrt-603" comment="Mozilla Firefox version 1.0.3 or earlier is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key datatype="string" operator="pattern match">SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Mozilla Firefox (\(0\.[0-9].*\)|\(1\.0\)|\(1\.0\.[0-3]\))</key>
        <name datatype="string" operator="equals">DisplayName</name>
      </object>
      <data operation="AND">
        <value datatype="string" operator="pattern match">Mozilla Firefox (\(0\.[0-9].*\)|\(1\.0\)|\(1\.0\.[0-3]\))</value>
      </data>
    </registry_test>
    <compound_test id="cmp-660" comment="Mozilla Firefox version 1.0.3 or earlier is installed" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="wrt-10024"/>
      <subtest test_ref="wrt-603"/>
    </compound_test>
    <registry_test id="wrt-613" comment="Mozilla Thunderbird version 1.0.2 or earlier is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key datatype="string" operator="pattern match">SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Mozilla Thunderbird (\(0\.[0-9]\)|\(1\.0\)|\(1\.0\.[0-2]\))</key>
        <name datatype="string" operator="equals">DisplayName</name>
      </object>
      <data operation="AND">
        <value datatype="string" operator="pattern match">Mozilla Thunderbird (\(0\.[0-9]\)|\(1\.0\)|\(1\.0\.[0-2]\))</value>
      </data>
    </registry_test>
    <registry_test id="wrt-10051" comment="Mozilla Thunderbird version 1.0.2 or earlier is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key datatype="string" operator="equals">SOFTWARE\Mozilla\Mozilla Thunderbird</key>
        <name datatype="string" operator="equals">CurrentVersion</name>
      </object>
      <data operation="AND">
        <value datatype="string" operator="pattern match">[0-1]\.0($|\s).*|[0-1]\.0\.[0-2]($|\s).*</value>
      </data>
    </registry_test>
    <compound_test id="cmp-665" comment="Mozilla Thunderbird version 1.0.2 or earlier is installed" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="wrt-10051"/>
      <subtest test_ref="wrt-613"/>
    </compound_test>
    <registry_test id="wrt-601" comment="Mozilla Firefox version 1.0.2 or earlier is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key datatype="string" operator="pattern match">SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Mozilla Firefox (\(0\.[0-9].*\)|\(1\.0\)|\(1\.0\.[0-2]\))</key>
        <name datatype="string" operator="equals">DisplayName</name>
      </object>
      <data operation="AND">
        <value datatype="string" operator="pattern match">Mozilla Firefox (\(0\.[0-9].*\)|\(1\.0\)|\(1\.0\.[0-2]\))</value>
      </data>
    </registry_test>
    <registry_test id="wrt-10045" comment="Firefox version 1.0.2 or earlier is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key datatype="string" operator="equals">SOFTWARE\Mozilla\Mozilla Firefox</key>
        <name datatype="string" operator="equals">CurrentVersion</name>
      </object>
      <data operation="AND">
        <value datatype="string" operator="pattern match">[0-1]\.0($|\s).*|[0-1]\.0\.[0-2]($|\s).*</value>
      </data>
    </registry_test>
    <compound_test id="cmp-658" comment="Mozilla Firefox version 1.0.2 or earlier is installed" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="wrt-10045"/>
      <subtest test_ref="wrt-601"/>
    </compound_test>
    <registry_test id="wrt-591" comment="Mozilla Suite version 1.7.8 or earlier is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key datatype="string" operator="pattern match">SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Mozilla (\([0-1]\.[0-7]\)|\([0-1]\.[0-7]\.[0-8]\))</key>
        <name datatype="string" operator="equals">DisplayName</name>
      </object>
      <data operation="AND">
        <value datatype="string" operator="pattern match">Mozilla (\([0-1]\.[0-7]\)|\([0-1]\.[0-7]\.[0-8]\))</value>
      </data>
    </registry_test>
    <registry_test id="wrt-10048" comment="Mozilla Suite version 1.7.8 or earlier is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key datatype="string" operator="equals">SOFTWARE\mozilla.org\Mozilla</key>
        <name datatype="string" operator="equals">CurrentVersion</name>
      </object>
      <data operation="AND">
        <value datatype="string" operator="pattern match">[0-1]\.[0-7]($|\s).*|[0-1]\.[0-7]\.[0-8]($|\s).*</value>
      </data>
    </registry_test>
    <compound_test id="cmp-652" comment="Mozilla Suite version 1.7.8 or earlier is installed" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="wrt-10048"/>
      <subtest test_ref="wrt-591"/>
    </compound_test>
    <registry_test id="wrt-602" comment="Mozilla Firefox version 1.0.4 or earlier is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key datatype="string" operator="pattern match">SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Mozilla Firefox (\(0\.[0-9].*\)|\(1\.0\)|\(1\.0\.[0-4]\))</key>
        <name datatype="string" operator="equals">DisplayName</name>
      </object>
      <data operation="AND">
        <value datatype="string" operator="pattern match">Mozilla Firefox (\(0\.[0-9].*\)|\(1\.0\)|\(1\.0\.[0-4]\))</value>
      </data>
    </registry_test>
    <registry_test id="wrt-10043" comment="Firefox version 1.0.4 or earlier is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key datatype="string" operator="equals">SOFTWARE\Mozilla\Mozilla Firefox</key>
        <name datatype="string" operator="equals">CurrentVersion</name>
      </object>
      <data operation="AND">
        <value datatype="string" operator="pattern match">[0-1]\.0($|\s).*|[0-1]\.0\.[0-4]($|\s).*</value>
      </data>
    </registry_test>
    <compound_test id="cmp-659" comment="Mozilla Firefox version 1.0.4 or earlier is installed" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="wrt-10043"/>
      <subtest test_ref="wrt-602"/>
    </compound_test>
    <registry_test id="wrt-10025" comment="Mozilla Suite version 1.7.7 or earlier is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key datatype="string" operator="equals">SOFTWARE\mozilla.org\Mozilla</key>
        <name datatype="string" operator="equals">CurrentVersion</name>
      </object>
      <data operation="AND">
        <value datatype="string" operator="pattern match">[0-1]\.[0-7]($|\s).*|[0-1]\.[0-7]\.[0-7]($|\s).*</value>
      </data>
    </registry_test>
    <registry_test id="wrt-10024" comment="Firefox version 1.0.3 or earlier is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key datatype="string" operator="equals">SOFTWARE\Mozilla\Mozilla Firefox</key>
        <name datatype="string" operator="equals">CurrentVersion</name>
      </object>
      <data operation="AND">
        <value datatype="string" operator="pattern match">[0-1]\.0($|\s).*|[0-1]\.0\.[0-3]($|\s).*</value>
      </data>
    </registry_test>
    <compound_test id="cmp-10012" comment="Firefox &lt;= 1.0.3 or Mozilla Suite &lt;= 1.7.7 is installed" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="wrt-10024"/>
      <subtest test_ref="wrt-10025"/>
    </compound_test>
    <registry_test id="wrt-564" comment="the patch kb834707  is installed (Installed Components key) " check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key datatype="string" operator="equals">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB834707</key>
        <name datatype="string" operator="equals">IsInstalled</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-551" comment="machine has followed the QFE update path and mshtml.dll is less than  6.0.2900.2524 " check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mshtml.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>2900</build>
          <private>2524</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-550" comment="machine has followed the GDR update path and mshtml.dll is less than  6.0.2900.2523 " check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mshtml.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>2900</build>
          <private>2523</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-1154" comment="a vulnerable version of mshtml.dll exisits" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wft-550"/>
      <subtest negate="false" test_ref="wft-551"/>
    </compound_test>
    <registry_test id="wrt-565" comment="Internet Explorer 6 Service Pack 2 for XP is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key datatype="string" operator="equals">SOFTWARE\Microsoft\Internet Explorer</key>
        <name datatype="string" operator="equals">Version</name>
      </object>
      <data operation="AND">
        <value datatype="string" operator="equals">6.00.2900.2180</value>
      </data>
    </registry_test>
    <file_test id="wft-542" comment="the 64-bit WOW version of nddenb32.dll is less than 5.2.3790.193" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\SysWOW64\nddenb32.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>2</minor>
          <build>3790</build>
          <private>193</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-1144" comment="a vulnerable version of nddenb32.dll exists" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wft-540"/>
      <subtest negate="false" test_ref="wft-542"/>
    </compound_test>
    <file_test id="wft-543" comment="the 64-bit WOW version of netdde.exe is less than 5.2.3790.193" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\SysWOW64\netdde.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>2</minor>
          <build>3790</build>
          <private>193</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-1143" comment="a vulnerable version of netdde.exe exists" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wft-541"/>
      <subtest negate="false" test_ref="wft-543"/>
    </compound_test>
    <file_test id="wft-536" comment="the 64-bit WOW version of zipfldr.dll is less than 6.0.2800.1584" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\SysWOW64\zipfldr.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>2800</build>
          <private>1584</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-555" comment="Patch Windows2000-KB883935-x86-ENU.exe Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key datatype="string" operator="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB883935</key>
        <name datatype="string" operator="equals">Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-533" comment="the version of nntpsvc.dll is less than 5.0.2195.6972" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\inetsrv\nntpsvc.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>2195</build>
          <private>6972</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-1116" comment="service pack 1 is installed and a vulnerable version of shell32.dll exists" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-4"/>
      <subtest negate="false" test_ref="wft-510"/>
    </compound_test>
    <file_test id="wft-514" comment="the version of shell32.dll is less than 6.0.2750.166" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\shell32.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>2750</build>
          <private>166</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-1117" comment="no service pack is installed and a vulnerable version of shell32.dll exists" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="true" test_ref="wrt-3"/>
      <subtest negate="false" test_ref="wft-514"/>
    </compound_test>
    <compound_test id="cmp-1118" comment="a vulnerable version of shell32.dll exists" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-1117"/>
      <subtest negate="false" test_ref="cmp-1116"/>
    </compound_test>
    <file_test id="wft-559" comment="the version of rpcrt4.dll is less than 4.0.1381.33578" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\rpcrt4.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>4</major>
          <minor>0</minor>
          <build>1381</build>
          <private>33578</private>
        </version>
      </data>
    </file_test>
    <patch_test id="spt-258" comment="Patch 116308-01 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">116308</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">01</version>
      </data>
    </patch_test>
    <patch_test id="spt-257" comment="Patch 108949-08 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">108949</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">08</version>
      </data>
    </patch_test>
    <patch_test id="spt-256" comment="Patch 107178-03 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">107178</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">03</version>
      </data>
    </patch_test>
    <package_test id="sat-33" comment="Separable help for CDE (SUNWdthep) installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <pkginst operator="equals">SUNWdthep</pkginst>
      </object>
    </package_test>
    <compound_test id="cmp-82" comment="CDE Application Runtime or CDE Separable Help (any SUNWdtbas/SUNWdtbax/SUNWdthep) installed " operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="sat-32"/>
      <subtest negate="false" test_ref="sat-33"/>
    </compound_test>
    <compound_test id="cmp-1149" comment="Service Pack 1 is installed and a vulnerable version of netdde.exe exists" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-4"/>
      <subtest negate="false" test_ref="wft-544"/>
    </compound_test>
    <file_test id="wft-547" comment="the version of netdde.exe is less than 5.1.2600.158" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\inetsrv\netdde.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>158</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-1148" comment="no service pack is installed and a vulnerable version of netdde.exe exists" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="true" test_ref="wrt-3"/>
      <subtest negate="false" test_ref="wft-547"/>
    </compound_test>
    <compound_test id="cmp-1150" comment="a vulnerable version of netdde.exe exists" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-1148"/>
      <subtest negate="false" test_ref="cmp-1149"/>
    </compound_test>
    <compound_test id="cmp-1146" comment="Service Pack 1 is installed and a vulnerable version of nddenb32.dll exists" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-4"/>
      <subtest negate="false" test_ref="wft-545"/>
    </compound_test>
    <file_test id="wft-546" comment="the version of nddenb32.dll is less than 5.1.2600.149" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\inetsrv\nddenb32.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>149</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-1145" comment="no service pack is installed and a vulnerable version of nddenb32.dll exists" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="true" test_ref="wrt-3"/>
      <subtest negate="false" test_ref="wft-546"/>
    </compound_test>
    <compound_test id="cmp-1147" comment="a vulnerable version of nddenb32.dll exists" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-1145"/>
      <subtest negate="false" test_ref="cmp-1146"/>
    </compound_test>
    <registry_test id="wrt-556" comment="Patch WindowsNT4OptionPack-KB883935-x86-enu.EXE" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key datatype="string" operator="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB883935</key>
        <name datatype="string" operator="equals">Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-539" comment="the version of nntpsvc.dll is less than 5.5.1877.79" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\inetsrv\nntpsvc.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>5</minor>
          <build>1877</build>
          <private>79</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-576" comment="the version of mqrt.dll is less than 5.0.0.799" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mqrt.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>0</build>
          <private>799</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-146" comment="Is the KB886906 patch installed for .NET Framework v1.0 sp 3?" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">SOFTWARE\Microsoft\Updates\.NETFramework Setup\1.0\M886906</key>
        <name operator="equals">Installed</name>
      </object>
      <data operation="AND">
        <value operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-397" comment="the version of System.web.dll is less than 1.0.3705.6021" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\Microsoft.NET\Framework\System.web.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>1</major>
          <minor>0</minor>
          <build>3705</build>
          <private>6021</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-123" comment="Is Service Pack 3 for .NET Framework 1.0 installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">SOFTWARE\Microsoft\Active Setup\Installed Components\HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{78705f0d-e8db-4b2d-8193-982bdda15ecd}</key>
        <name operator="equals">Version</name>
      </object>
      <data operation="AND">
        <value operator="equals">1,0,3705,3</value>
      </data>
    </registry_test>
    <compound_test id="cmp-248" comment="A vulnerable version of .NET Framework v1.0 (SP 3) is installed." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-123"/>
      <subtest negate="false" test_ref="wft-397"/>
      <subtest negate="true" test_ref="wrt-146"/>
    </compound_test>
    <registry_test id="wrt-122" comment="Is Service Pack 2 for .NET Framework 1.0 installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">\SOFTWARE\Microsoft\Active Setup\Installed Components\{78705f0d-e8db-4b2d-8193-982bdda15ecd}</key>
        <name operator="equals">Version</name>
      </object>
      <data operation="AND">
        <value operator="equals">1,0,3705,2</value>
      </data>
    </registry_test>
    <file_test id="wft-438" comment="the version of System.web.dll is less than 1.0.3705.556" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\Microsoft.NET\Framework\System.web.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>1</major>
          <minor>0</minor>
          <build>3705</build>
          <private>556</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-145" comment="Is the KB886905 patch installed for .NET Framework v1.0 sp 2?" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">SOFTWARE\Microsoft\Updates\NET Framework Setup\1.0\M886905</key>
        <name operator="equals">Installed</name>
      </object>
      <data operation="AND">
        <value operator="equals">1</value>
      </data>
    </registry_test>
    <compound_test id="cmp-243" comment="A vulnerable version of .NET Framework v1.0 (SP 2) is installed. " operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="true" test_ref="wrt-145"/>
      <subtest negate="false" test_ref="wft-438"/>
      <subtest negate="false" test_ref="wrt-122"/>
    </compound_test>
    <compound_test id="cmp-252" comment="A vulnerable version of .NET Framework v1.0 is installed. " operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-243"/>
      <subtest negate="false" test_ref="cmp-248"/>
    </compound_test>
    <registry_test id="wrt-116" comment="Is the .NET Framework 1.0 installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">SOFTWARE\Microsoft\.NETFramework\policy\v1.0</key>
        <name operator="equals"/>
      </object>
    </registry_test>
    <registry_test id="wrt-448" comment="The SynAttackProtect parameter is set to 2" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key datatype="string" operator="equals">SYSTEM\CurrentControlSet\Services\Tcpip\Parameters</key>
        <name datatype="string" operator="equals">SynAttackProtect</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">2</value>
      </data>
    </registry_test>
    <registry_test id="wrt-431" comment="MSN Messenger 6.2.0208 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{ABEB838C-A1A7-4C5D-B7E1-8B4314600208}</key>
        <name operator="equals">DisplayVersion</name>
      </object>
      <data operation="AND">
        <value operator="equals">6.2.0208</value>
      </data>
    </registry_test>
    <registry_test id="wrt-14" comment="the patch KB888258 for Proxy Server 2.0 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB888258</key>
        <name operator="equals">Installed</name>
      </object>
      <data operation="AND">
        <value operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-7" comment="the version of w3proxy.dll is less than 2.0.390.16" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">InetPub\scripts\proxy\w3proxy.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>2</major>
          <minor>0</minor>
          <build>390</build>
          <private>16</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-9" comment="Microsoft Proxy Server 2.0 SP1 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Microsoft Proxy Server</key>
        <name operator="equals">Microsoft Proxy Server</name>
      </object>
    </registry_test>
    <textfilecontent_test id="tft-1" comment="/etc/nsswitch.conf configured to use LDAP with RBAC" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/etc/nsswitch.conf</component>
        </path>
        <line operator="pattern match">^[^#].*_attr.*ldap</line>
      </object>
    </textfilecontent_test>
    <patch_test id="spt-75" comment="Patch 112960-17 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">112960</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">17</version>
      </data>
    </patch_test>
    <patch_test id="spt-74" comment="Patch 108993-38 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">108993</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">38</version>
      </data>
    </patch_test>
    <file_test id="wft-164" comment="the version of wins.exe is less than 4.0.1381.7329" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\wins.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>4</major>
          <minor>0</minor>
          <build>1381</build>
          <private>7329</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-392" comment="the version of Llssrv.exe is less than 4.0.1381.7345" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\llssrv.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>4</major>
          <minor>0</minor>
          <build>1381</build>
          <private>7345</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-515" comment="the version of httpext.dll is less than 6.0.3790.212" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\inetsrv\httpext.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>3790</build>
          <private>212</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-511" comment="the version of gdi32.dll is less than 4.0.1381.33566" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\gdi32.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>4</major>
          <minor>0</minor>
          <build>1381</build>
          <private>33566</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-378" comment="the version of wdhtmled.ocx is less than 6.1.0.9231" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir</component>
          <component type="literal">\microsoft shared\triedit\wdhtmled.ocx</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>1</minor>
          <build>0</build>
          <private>9231</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-46" comment="the patch Windows2000-KB873339-x86-ENU.EXE is installed " check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_CLASSES_ROOT</hive>
        <key operator="equals">SOFTWARE\Microsoft\Updates\Windows 2000\SP5\KB873339\ Filelist</key>
        <name operator="pattern match">^.*$</name>
      </object>
    </registry_test>
    <file_test id="wft-200" comment="the version of hypertrm.dll is less than 5.0.2195.7000" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\hypertrm.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>2195</build>
          <private>7000</private>
        </version>
      </data>
    </file_test>
    <patch_test id="spt-29" comment="Patch 112233-02 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">11233</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">02</version>
      </data>
    </patch_test>
    <patch_test id="spt-28" comment="Patch 113319-01 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">113319</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">01</version>
      </data>
    </patch_test>
    <compound_test id="cmp-64" comment="Patches 113319-01 and 112233-02 or later installed" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="spt-28"/>
      <subtest negate="false" test_ref="spt-29"/>
    </compound_test>
    <patch_test id="spt-27" comment="Patch 108451-06 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">108451</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">06</version>
      </data>
    </patch_test>
    <compound_test id="cmp-63" comment="Patches 106942-22 and 108451-06 or later installed" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="spt-211"/>
      <subtest negate="false" test_ref="spt-27"/>
    </compound_test>
    <file_test id="wft-401" comment="the version of shell32.dll is less than 6.0.3790.241" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\shell32.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>3790</build>
          <private>241</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-436" comment="the patch  KB893086 is installed " check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">SOFTWARE\Microsoft\Updates\Windows 2000\SP5\KB893086\Filelist</key>
        <name operator="pattern match">^.*$</name>
      </object>
    </registry_test>
    <file_test id="wft-592" comment="the version of shell32.dll is less than 5.0.3900.7032" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\shell32.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>3900</build>
          <private>7032</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-1111" comment="Windows Server 2003 or Windows 64-bit Edition is installed" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-61"/>
      <subtest negate="false" test_ref="cmp-1066"/>
    </compound_test>
    <process_test id="uct-12" comment="Kerberos Key Distribution Center (krb5kdc) running" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <command datatype="string" operator="pattern match">.*krb5kdc.*</command>
      </object>
    </process_test>
    <file_test id="wft-541" comment="the version of netdde.exe is less than 5.2.3790.184" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\inetsrv\netdde.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>2</minor>
          <build>3790</build>
          <private>184</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-540" comment="the version of nddenb32.dll is less than 5.2.3790.173" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\inetsrv\nddenb32.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>2</minor>
          <build>3790</build>
          <private>173</private>
        </version>
      </data>
    </file_test>
    <patch_test id="spt-94" comment="Patch 112233-05 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">112233</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">05</version>
      </data>
    </patch_test>
    <patch_test id="spt-93" comment="Patch 108528-19 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">108528</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">19</version>
      </data>
    </patch_test>
    <patch_test id="spt-92" comment="Patch 106541-25 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">106541</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">25</version>
      </data>
    </patch_test>
    <file_test id="wft-263" comment="the version of hypertrm.dll is less than 4.0.1381.842" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\hypertrm.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>4</major>
          <minor>0</minor>
          <build>1381</build>
          <private>842</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-526" comment="the version of grpconv.exe (syswow64) is less than 5.2.3790.205" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\syswow64\shell32.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>2</minor>
          <build>3790</build>
          <private>205</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-1137" comment="a vulnerable version of grpconv.exe exists" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wft-525"/>
      <subtest negate="false" test_ref="wft-526"/>
    </compound_test>
    <patch_test id="spt-52" comment="Patch 116462-01 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">116462</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">01</version>
      </data>
    </patch_test>
    <patch_test id="spt-51" comment="Patch 110060-04 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">110060</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">04</version>
      </data>
    </patch_test>
    <patch_test id="spt-50" comment="Patch 110057-07 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">110057</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">07</version>
      </data>
    </patch_test>
    <patch_test id="spt-49" comment="Patch 112536-04 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">112536</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">04</version>
      </data>
    </patch_test>
    <compound_test id="cmp-73" comment="Patches 112536-04 and 110057-07 or later installed" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="spt-49"/>
      <subtest negate="false" test_ref="spt-50"/>
    </compound_test>
    <registry_test id="wrt-552" comment="the patch WindowsServer2003-KB883935-x86-enu.exe is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key datatype="string" operator="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB883935</key>
        <name datatype="string" operator="equals">Installed</name>
      </object>
      <data operation="AND">
        <value datatype="string" operator="equals">1</value>
      </data>
    </registry_test>
    <registry_test id="wrt-425" comment="Message Queuing Enabled" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">SOFTWARE\Microsoft\MSMQ</key>
        <name operator="equals"/>
      </object>
    </registry_test>
    <registry_test id="wrt-426" comment="the patch KB892944 is installed (Hotfix key)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB892944</key>
        <name operator="equals">Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-577" comment="the version of mqrt.dll is less than 5.1.0.1044" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mqrt.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>0</build>
          <private>1044</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-313" comment="Windows XP Service Pack 1" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-2"/>
      <subtest negate="false" test_ref="wrt-4"/>
    </compound_test>
    <patch_test id="spt-112" comment="Patch 107115-12 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">107115</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">12</version>
      </data>
    </patch_test>
    <patch_test id="spt-108" comment="Patch 107893-05 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">107893</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">05</version>
      </data>
    </patch_test>
    <file_test id="wft-499" comment="the version of shell32.dll is less than 5.0.3900.6970" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\shell32.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>3900</build>
          <private>6970</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-505" comment="the version of vdmdbg.dll is less than 5.0.2195.6946" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\vdmdbg.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>2195</build>
          <private>6946</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-531" comment="Microsoft Visual Studio .NET 2002 Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key datatype="string" operator="equals">Software\Microsoft\VisualStudio\7.0</key>
        <name operator="pattern match">.*</name>
      </object>
    </registry_test>
    <file_test id="wft-162" comment="the version of Dhcpssvc.dll is less than 4.0.1381.33587" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\Dhcpssvc.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>4</major>
          <minor>0</minor>
          <build>1381</build>
          <private>33587</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-538" comment="the 64-bit WOW version of zipfldr.dll is less than 6.0.3790.198" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\SysWOW64\zipfldr.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>3790</build>
          <private>198</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-13" comment="the patch KB888258 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">SOFTWARE\Microsoft\Fpc\Hotfixes\SP1\408</key>
        <name operator="equals">Kbs</name>
      </object>
      <data operation="AND">
        <value operator="equals">KB888258</value>
      </data>
    </registry_test>
    <file_test id="wft-6" comment="the version of msphlpr.dll is less than 3.0.1200.408" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">Program Files\Microsoft ISA Server\msphlpr.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>3</major>
          <minor>0</minor>
          <build>1200</build>
          <private>408</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-525" comment="the version of grpconv.exe (system32) is less than 5.2.3790.205" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\grpconv.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>2</minor>
          <build>3790</build>
          <private>205</private>
        </version>
      </data>
    </file_test>
    <unknown_test id="ukn-38" comment="Service Pack 2 or less for Windows Office XP" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <oval:notes>
        <oval:note>Service Pack 2 or less for Windows Office XP needs regex involving strings and less than</oval:note>
      </oval:notes>
    </unknown_test>
    <file_test id="wft-10002" comment="the version of vgx.dll is less than 6.0.2800.1411" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir</component>
          <component type="literal">\Common Files\Microsoft Shared\VGX\vgx.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>2800</build>
          <private>1411</private>
        </version>
      </data>
    </file_test>
    <textfilecontent_test id="tft-4" comment="/etc/nsswitch.conf configured to resolve hosts through DNS" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/etc/nsswitch.conf</component>
        </path>
        <line operator="pattern match">^[^#]*hosts:.*dns</line>
      </object>
    </textfilecontent_test>
    <patch_test id="spt-32" comment="Patch 112970-02 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">112970</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">02</version>
      </data>
    </patch_test>
    <patch_test id="spt-31" comment="Patch 109326-09 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">109326</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">09</version>
      </data>
    </patch_test>
    <patch_test id="spt-30" comment="Patch 106938-06 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">106938</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">06</version>
      </data>
    </patch_test>
    <patch_test id="spt-45" comment="Patch 113329-02 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">113329</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">02</version>
      </data>
    </patch_test>
    <patch_test id="spt-44" comment="Patch 109320-07 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">109320</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">07</version>
      </data>
    </patch_test>
    <patch_test id="spt-43" comment="Patch 107115-13 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">107115</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">13</version>
      </data>
    </patch_test>
    <package_test id="sat-25" comment="Solaris Print - LP Server - Usr (SUNWpsu) installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <pkginst operator="equals">SUNWpsu</pkginst>
      </object>
    </package_test>
    <package_test id="sat-24" comment="Solaris Print - LP Server - Root (SUNWpsr) installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <pkginst operator="equals">SUNWpsr</pkginst>
      </object>
    </package_test>
    <package_test id="sat-23" comment="Solaris Print - Client - Usr (SUNWpcu) installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <pkginst operator="equals">SUNWpcu</pkginst>
      </object>
    </package_test>
    <package_test id="sat-22" comment="Solaris Print - Client - Root (SUNWpcr) installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <pkginst operator="equals">SUNWpcr</pkginst>
      </object>
    </package_test>
    <compound_test id="cmp-71" comment="Solaris Printing Services installed (any SUNWpcr/SUNWpcu/SUNWpsr/SUNWpsu)" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="sat-22"/>
      <subtest negate="false" test_ref="sat-23"/>
      <subtest negate="false" test_ref="sat-24"/>
      <subtest negate="false" test_ref="sat-25"/>
    </compound_test>
    <patch_test id="spt-39" comment="Patch 109324-03 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">109324</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">03</version>
      </data>
    </patch_test>
    <patch_test id="spt-37" comment="Patch 110898-02 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">110898</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">02</version>
      </data>
    </patch_test>
    <patch_test id="spt-41" comment="Patch 110943-01 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">110943</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">01</version>
      </data>
    </patch_test>
    <compound_test id="cmp-70" comment="Patches 110943-01, 110898-02, and 109324-03 or later installed" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="spt-41"/>
      <subtest negate="false" test_ref="spt-37"/>
      <subtest negate="false" test_ref="spt-39"/>
    </compound_test>
    <patch_test id="spt-40" comment="Patch 108416-02 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">108416</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">02</version>
      </data>
    </patch_test>
    <patch_test id="spt-38" comment="Patch 108162-04 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">108162</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">04</version>
      </data>
    </patch_test>
    <patch_test id="spt-36" comment="Patch 108574-03 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">108574</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">03</version>
      </data>
    </patch_test>
    <compound_test id="cmp-69" comment="Patches 108574-03, 108162-04, and 108416-02 or later installed" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="spt-36"/>
      <subtest negate="false" test_ref="spt-38"/>
      <subtest negate="false" test_ref="spt-40"/>
    </compound_test>
    <file_test id="wft-385" comment="the version of mrxsmb.sys is less than 5.0.2195.7023" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\drivers\mrxsmb.sys</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>2195</build>
          <private>7023</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-423" comment="the patch KB894549 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">SOFTWARE\Microsoft\Updates\Exchange Server 2003\SP1\KB894549</key>
        <name operator="pattern match">.*</name>
      </object>
    </registry_test>
    <file_test id="wft-575" comment="the version of xlsasink.dll is less than 6.5.6981.3" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Exchange\Setup\Services</component>
          <component type="literal">\bin\xlsasink.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>5</minor>
          <build>6981</build>
          <private>3</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-566" comment="Exchange Server 2003 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\9161A261-6ABE-4668-BBFA-AD06B3F642CF</key>
        <name>Microsoft Exchange</name>
      </object>
    </registry_test>
    <package_test id="sat-9" comment="CDE Desktop Applications (SUNWdtdst) installed                                                                                               " check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <pkginst datatype="string" operator="equals">SUNWdtdst</pkginst>
      </object>
    </package_test>
    <patch_test id="spt-265" comment="Patch 112810-06 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">112810</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">06</version>
      </data>
    </patch_test>
    <patch_test id="spt-264" comment="Patch 109613-07 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">109613</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">07</version>
      </data>
    </patch_test>
    <registry_test id="wrt-95" comment="Patch KB873352 installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90280409-6000-11D3-8CFE-0050048383C9}</key>
        <name operator="equals">DisplayVersion</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">10.0.6626.0</value>
      </data>
    </registry_test>
    <file_test id="wft-147" comment="The version of Ntoskrnl.exe is less than 4.0.1381.33591" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\System32\Ntoskrnl.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>4</major>
          <minor>0</minor>
          <build>1381</build>
          <private>33591</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-494" comment="the version of sxs.dll is less than 5.1.2600.1363" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\sxs.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>1363</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-47" comment="the patch NT Server kb873339 is installed " check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_CLASSES_ROOT</hive>
        <key operator="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix \KB873339\Filelist</key>
        <name operator="pattern match">^.*$</name>
      </object>
    </registry_test>
    <file_test id="wft-226" comment="the version of hypertrm.dll is less than 4.0.1381.7323" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\hypertrm.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>4</major>
          <minor>0</minor>
          <build>1381</build>
          <private>7323</private>
        </version>
      </data>
    </file_test>
    <file_test id="uft-31" comment="File /etc/named.conf exists " check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <oval:notes>
        <oval:note>The presence of /etc/named.conf indicates that system system is probably configured as a DNS server</oval:note>
      </oval:notes>
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/etc/named.conf</component>
        </path>
      </object>
    </file_test>
    <patch_test id="spt-66" comment="Patch 109326-16 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">109326</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">16</version>
      </data>
    </patch_test>
    <file_test id="wft-512" comment="the version of gdi32.dll is less than 4.0.1381.7270" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\gdi32.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>4</major>
          <minor>0</minor>
          <build>1381</build>
          <private>7270</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-537" comment="the 32-bit version of zipfldr.dll is less than 6.0.3790.198" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\zipfldr.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>3790</build>
          <private>198</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-514" comment="Microsoft Office XP Service Pack 2 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90280409-6000-11D3-8CFE-0050048383C9}</key>
        <name>DisplayVersion</name>
      </object>
      <data operation="AND">
        <value>10.0.4330.0</value>
      </data>
    </registry_test>
    <process_test id="uct-18" comment="xntpd running" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <command operator="equals">/usr/lib/inet/xntpd</command>
      </object>
    </process_test>
    <patch_test id="spt-62" comment="Patch 109667-04 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">109667</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">04</version>
      </data>
    </patch_test>
    <patch_test id="spt-61" comment="Patch 109409-04 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">109409</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">04</version>
      </data>
    </patch_test>
    <package_test id="sat-35" comment="NTP daemon - Usr (SUNWntpu) installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <pkginst operator="equals">SUNWntpu</pkginst>
      </object>
    </package_test>
    <file_test id="wft-509" comment="the version of shell32.dll (WOW64) is less than 6.0.2800.1580" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\SysWOW64\shell32.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>2800</build>
          <private>1580</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-510" comment="the version of shell32.dll is less than 6.0.2800.1580" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\shell32.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>2800</build>
          <private>1580</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-1115" comment="a vulnerable version of shell32.dll exists" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wft-510"/>
      <subtest negate="false" test_ref="wft-509"/>
    </compound_test>
    <registry_test id="wrt-521" comment="Project Professional 2003 Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>Software\Microsoft\Windows\CurrentVersion\Uninstall\{903B0409-6000-11D3-8CFE-0150048383C9}</key>
        <name>DisplayVersion</name>
      </object>
      <data operation="AND">
        <value>11.0.5614.0</value>
      </data>
    </registry_test>
    <patch_test id="spt-263" comment="Patch 113146-03 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">113146</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">03</version>
      </data>
    </patch_test>
    <file_test id="wft-562" comment="the version of mshtml.dll is less than 5.50.4945.2800 " check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mshtml.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>50</minor>
          <build>4945</build>
          <private>2800</private>
        </version>
      </data>
    </file_test>
    <rpmversioncompare_test id="rvt-371" comment="libpng10 rpm older than 1.0.13-14, Epoch 0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">libpng10</name>
        <tested_epoch datatype="string" operator="equals">0</tested_epoch>
        <tested_version datatype="string" operator="equals">1.0.13</tested_version>
        <tested_release datatype="string" operator="equals">14</tested_release>
      </object>
      <data operation="AND">
        <installed_version datatype="string" operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <rpmversioncompare_test id="rvt-370" comment="libpng10-devel rpm older than 1.0.13-14, Epoch 0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">libpng10-devel</name>
        <tested_epoch datatype="string" operator="equals">0</tested_epoch>
        <tested_version datatype="string" operator="equals">1.0.13</tested_version>
        <tested_release datatype="string" operator="equals">14</tested_release>
      </object>
      <data operation="AND">
        <installed_version datatype="string" operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <rpmversioncompare_test id="rvt-369" comment="libpng-devel rpm older than 1.2.2-24, Epoch 2" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">libpng-devel</name>
        <tested_epoch datatype="string" operator="equals">2</tested_epoch>
        <tested_version datatype="string" operator="equals">1.2.2</tested_version>
        <tested_release datatype="string" operator="equals">24</tested_release>
      </object>
      <data operation="AND">
        <installed_version datatype="string" operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <rpmversioncompare_test id="rvt-368" comment="libpng rpm older than 1.2.2-24, Epoch 2" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">libpng</name>
        <tested_epoch datatype="string" operator="equals">2</tested_epoch>
        <tested_version datatype="string" operator="equals">1.2.2</tested_version>
        <tested_release datatype="string" operator="equals">24</tested_release>
      </object>
      <data operation="AND">
        <installed_version datatype="string" operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <compound_test id="cmp-1101" comment="libpng or libpng-devel rpm older than 1.2.2-24, Epoch 2 OR libpng10or libpng10-devel rpm older than 1.0.13-14, Epoch 0" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="rvt-368"/>
      <subtest negate="false" test_ref="rvt-369"/>
      <subtest negate="false" test_ref="rvt-370"/>
      <subtest negate="false" test_ref="rvt-371"/>
    </compound_test>
    <patch_test id="spt-114" comment="Patch 112233-04 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">112233</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">04</version>
      </data>
    </patch_test>
    <patch_test id="spt-113" comment="Patch 108528-18 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">108528</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">18</version>
      </data>
    </patch_test>
    <patch_test id="spt-239" comment="Patch 110615-11 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">110615</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">11</version>
      </data>
    </patch_test>
    <patch_test id="spt-238" comment="Patch 107684-11 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">107684</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">11</version>
      </data>
    </patch_test>
    <unknown_test id="ukn-36" comment="Sendmail has recipient or final rulesets" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <oval:notes>
        <oval:note>egrep "^[Srecipient=2|S2]|^[^#]*\$>2|^[^#]*\$>recipient|^[^#]*\$>4|^[^#]*\$>final" /etc/mail/sendmail.cf True if any lines returned</oval:note>
      </oval:notes>
    </unknown_test>
    <file_test id="wft-452" comment="the version of shell32.dll is less than 4.72.3841.1100" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\shell32.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>4</major>
          <minor>72</minor>
          <build>3841</build>
          <private>1100</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-1067" comment="Windows NT 4.0 with Active Desktop Installed" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-490"/>
      <subtest negate="false" test_ref="wrt-77"/>
    </compound_test>
    <patch_test id="spt-12" comment="Patch 112963-09 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">112963</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">09</version>
      </data>
    </patch_test>
    <patch_test id="spt-11" comment="Patch 109147-07 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">109147</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">07</version>
      </data>
    </patch_test>
    <patch_test id="spt-10" comment="Patch 106950-14 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">106950</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">14</version>
      </data>
    </patch_test>
    <compound_test id="cmp-54" comment="Solaris 9 OR Patch 106950-14+ OR Patch 109147-07+ installed" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="spt-10"/>
      <subtest negate="false" test_ref="spt-11"/>
      <subtest negate="false" test_ref="uut-6"/>
    </compound_test>
    <registry_test id="wrt-609" comment="Webview is  Enabled" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_CURRENT_USER</hive>
        <key operator="equals">SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced</key>
        <name operator="equals">WebView</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="not equal">1</value>
      </data>
    </registry_test>
    <registry_test id="wrt-608" comment="the patch KB894320 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">SOFTWARE\Microsoft\Updates\Windows 2000\SP5\KB894320\Filelist</key>
        <name operator="pattern match">^.*$</name>
      </object>
    </registry_test>
    <file_test id="wft-613" comment="the version of webvw.dll is less than 5.0.3900.7036" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\webvw.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>3900</build>
          <private>7036</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-395" comment="the version of Llssrv.exe is less than 5.2.3790.242" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\llssrv.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>2</minor>
          <build>3790</build>
          <private>242</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-483" comment="the version of msadco.dll is less than 2.12.5118.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir</component>
          <component type="literal">\Common Files\System\msadc\msadco.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>2</major>
          <minor>12</minor>
          <build>5118</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-183" comment="MDAC 2.1 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">SOFTWARE\Microsoft\DataAccess</key>
        <name operator="equals">FullInstallVer</name>
      </object>
      <data operation="AND">
        <value operator="pattern match">^2\.1.*$</value>
      </data>
    </registry_test>
    <textfilecontent_test id="tft-3" comment="/etc/system has BSM enabled" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/etc/system</component>
        </path>
        <line operator="pattern match">^[^\*]*set.*c2audit.*</line>
      </object>
    </textfilecontent_test>
    <patch_test id="spt-85" comment="Patch 114332-10 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">114332</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">10</version>
      </data>
    </patch_test>
    <patch_test id="spt-84" comment="Patch 114332-08 installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">114332</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="equals">08</version>
      </data>
    </patch_test>
    <registry_test id="wrt-144" comment="Is the KB886904 patch installed for .NET Framework v1.1 Gold?" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">SOFTWARE\Microsoft\Updates\.NETFramework Setup\1.1\M886904</key>
        <name operator="equals">Installed</name>
      </object>
      <data operation="AND">
        <value operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-456" comment="the version of System.web.dll is less than 1.1.4322.1085" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\Microsoft.NET\Framework\System.web.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>1</major>
          <minor>1</minor>
          <build>4322</build>
          <private>1085</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-251" comment="A vulnerable version of .NET Framework v1.1 (Gold) is installed." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="true" test_ref="wrt-118"/>
      <subtest negate="false" test_ref="wft-456"/>
      <subtest negate="true" test_ref="wrt-144"/>
    </compound_test>
    <registry_test id="wrt-143" comment="Is the KB886903 patch installed for .NET Framework v1.1 sp 1?" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">SOFTWARE\Microsoft\Updates\.NETFramework Setup\1.1\M886903</key>
        <name operator="equals">Installed</name>
      </object>
      <data operation="AND">
        <value operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-460" comment="the version of System.web.dll is less than 1.1.4322.2037" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\Microsoft.NET\Framework\System.web.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>1</major>
          <minor>1</minor>
          <build>4322</build>
          <private>2037</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-118" comment="Is Service Pack 1 for .NET Framework 1.1 installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals"/>
        <name operator="equals">Version</name>
      </object>
      <data operation="AND">
        <value operator="equals">1,0,4322,0</value>
      </data>
    </registry_test>
    <compound_test id="cmp-249" comment="A vulnerable version of .NET Framework v1.1 (SP 1) is installed." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-118"/>
      <subtest negate="false" test_ref="wft-460"/>
      <subtest negate="true" test_ref="wrt-143"/>
    </compound_test>
    <compound_test id="cmp-253" comment="A vulnerable version of .NET Framework v1.1 is installed." operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-249"/>
      <subtest negate="false" test_ref="cmp-251"/>
    </compound_test>
    <registry_test id="wrt-117" comment="Is the .NET Framework 1.1 installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">SOFTWARE\Microsoft\.NETFramework\policy\v1.1</key>
        <name operator="equals"/>
      </object>
    </registry_test>
    <file_test id="wft-580" comment="The version of Ntoskrnl.exe is less than 5.1.2600.1634" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\System32\Ntoskrnl.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>1634</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-327" comment="Windows No Service Pack or Service Pack 1" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-4"/>
      <subtest negate="true" test_ref="wrt-410"/>
    </compound_test>
    <compound_test id="cmp-328" comment="Windows No Service Pack or Service Pack 1 and Ntoskrnl.exe version less than 5.1.2600.1634" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-327"/>
      <subtest negate="false" test_ref="wft-580"/>
    </compound_test>
    <file_test id="wft-449" comment="the version of shell32.dll is less than 6.0.2600.151" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\shell32.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>2600</build>
          <private>151</private>
        </version>
      </data>
    </file_test>
    <textfilecontent_test id="tft-2" comment="/etc/ssh/sshd_config has 0.0.0.0 as ListenAddress" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/etc/ssh/sshd_config</component>
        </path>
        <line operator="pattern match">^[^#]*ListenAddress.*0\.0\.0\.0</line>
      </object>
    </textfilecontent_test>
    <patch_test id="spt-83" comment="Patch 113273-05 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">113273</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">05</version>
      </data>
    </patch_test>
    <package_test id="sat-41" comment="Secure Shell Server - Usr (SUNWsshdu) installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <pkginst operator="equals">SUNWsshdu</pkginst>
      </object>
    </package_test>
    <registry_test id="wrt-184" comment="the patch Q890175 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\Q890175</key>
        <name operator="equals">Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-464" comment="the version of netbt.sys is less than 5.1.2600.1243" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\drivers\netbt.sys</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>1243</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-1096" comment="XP SP1 and netbt.sys is less than 5.1.2600.1243" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wft-464"/>
      <subtest negate="false" test_ref="wrt-4"/>
    </compound_test>
    <file_test id="wft-463" comment="the version of netbt.sys is less than 5.1.2600.117" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\drivers\netbt.sys</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>117</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-1086" comment="Pre Service Pack XP and netbt.sys is less than 5.1.2600.117" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wft-463"/>
      <subtest negate="false" test_ref="wrt-410"/>
    </compound_test>
    <compound_test id="cmp-1097" comment="XP SP1 or Pre SP1 with correct netbt.sys version" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-1086"/>
      <subtest negate="false" test_ref="cmp-1096"/>
    </compound_test>
    <registry_test id="wrt-476" comment=" Patch WindowsXP-KB824105-x86-ENU.exe installed on XP SP1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">SOFTWARE\Microsoft\Updates\Windows XP\SP2\KB824105\Filelist</key>
        <name operator="equals">installed</name>
      </object>
      <data operation="AND">
        <value operator="equals">1</value>
      </data>
    </registry_test>
    <registry_test id="wrt-475" comment=" Patch WindowsXP-KB824105-x86-ENU.exe installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">SOFTWARE\Microsoft\Updates\Windows XP\SP1\KB824105\Filelist</key>
        <name operator="equals">installed</name>
      </object>
      <data operation="AND">
        <value operator="equals">1</value>
      </data>
    </registry_test>
    <compound_test id="cmp-1051" comment="Patch WindowsXP-KB824105-x86-ENU.exe installed on XP or XP SP1" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-475"/>
      <subtest negate="false" test_ref="wrt-476"/>
    </compound_test>
    <textfilecontent_test id="tft-9" comment="/etc/vfstab is configured with SVM devices" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/etc/vfstab</component>
        </path>
        <line operator="equals">^/dev/md/</line>
      </object>
    </textfilecontent_test>
    <file_test id="uft-24" comment="svm.init init script exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="pattern match">
          <component type="literal">/etc/rc[2-4].d/S[0-9][0-9]svm.init</component>
        </path>
      </object>
    </file_test>
    <package_test id="sat-4" comment="Solaris Volume Manager package installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <pkginst>SUNWlvmr</pkginst>
      </object>
    </package_test>
    <patch_test id="spt-241" comment="Patch 113073-13 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">113073</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">13</version>
      </data>
    </patch_test>
    <file_test id="wft-375" comment="the version of dhtmled.ocx is less than 6.1.0.9232" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir</component>
          <component type="literal">\microsoft shared\triedit\dhtmled.ocx</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>1</minor>
          <build>0</build>
          <private>9232</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-180" comment="Windows XP 32-bit edition is installed  with service pack 2 (or earlier)" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-2"/>
      <subtest negate="false" test_ref="wrt-72"/>
      <subtest negate="false" test_ref="wrt-79"/>
    </compound_test>
    <registry_test id="wrt-544" comment="the patch WindowsServer2003-KB885881-ia64-enu.exe is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key datatype="string" operator="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB885881</key>
        <name datatype="string" operator="equals">Installed</name>
      </object>
      <data operation="AND">
        <value datatype="string" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-445" comment="the version of mstask.dll is less than 4.71.2195.6920" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mstask.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>4</major>
          <minor>71</minor>
          <build>2195</build>
          <private>6920</private>
        </version>
      </data>
    </file_test>
    <patch_test id="spt-73" comment="Patch 116774-03 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">116774</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">03</version>
      </data>
    </patch_test>
    <patch_test id="spt-72" comment="Patch 116986-02 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">116986</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">02</version>
      </data>
    </patch_test>
    <patch_test id="spt-71" comment="Patch 118313-01 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">118313</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">01</version>
      </data>
    </patch_test>
    <package_test id="sat-39" comment="Solaris Basic IP Commands (SUNWbip) installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <pkginst operator="equals">SUNWbip</pkginst>
      </object>
    </package_test>
    <compound_test id="cmp-88" comment="Solaris 9 and Solaris Basic IP Commands (SUNWbip) installed" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="uut-6"/>
      <subtest negate="false" test_ref="sat-39"/>
    </compound_test>
    <compound_test id="cmp-96" comment="Solaris 7 or 8 OR Solaris 9 and Solaris Basic IP Commands (SUNWbip) installed" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-43"/>
      <subtest negate="false" test_ref="cmp-88"/>
    </compound_test>
    <file_test id="wft-466" comment="File %windir%system32DriversSRV.SYS is less than 5.1.2600.1193" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\Drivers\SRV.SYS</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>1193</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-1093" comment="XP SP1 and srv.sys is less than 5.1.2600.1193" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wft-466"/>
      <subtest negate="false" test_ref="wrt-4"/>
    </compound_test>
    <file_test id="wft-465" comment="File %windir%system32DriversSRV.SYS is less than 5.1.2600.112" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\Drivers\SRV.SYS</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>112</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-1092" comment="XP Pre- SP1 with Srv.sys is less than 5.1.2600.112" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wft-465"/>
      <subtest negate="false" test_ref="wrt-410"/>
    </compound_test>
    <compound_test id="cmp-1094" comment="XP SP1 or pre SP1 with version check on Srv.sys" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-1092"/>
      <subtest negate="false" test_ref="cmp-1093"/>
    </compound_test>
    <file_test id="wft-447" comment="the version of shell32.dll is less than 5.0.3900.6922" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\shell32.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>3900</build>
          <private>6922</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-461" comment="the version of inetcomm.dll is less than 6.0.2742.200" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\inetcomm.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>2742</build>
          <private>200</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-495" comment="the version of gdiplus.dll is less than 6.0.3264.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir</component>
          <component type="literal">\Microsoft Shared\OFFICE11\GDIPLUS.DLL</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>3264</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-527" comment="Visio Professional 2003 is Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>Software\Microsoft\Windows\CurrentVersion\Uninstall\{90510409-6000-11D3-8CFE-0150048383C9}</key>
        <name>DisplayVersion</name>
      </object>
      <data operation="AND">
        <value operator="equals">11.0.3216.5614</value>
      </data>
    </registry_test>
    <registry_test id="wrt-516" comment="Patch KB873378 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Patches\9FEC06657760FC84499ED532196D45EE2</key>
        <name operator="equals">Security Update for Office 2003: Wordperfect 5.x Converter (KB873378)</name>
      </object>
      <data operation="AND">
        <value operator="equals">Installed</value>
      </data>
    </registry_test>
    <file_test id="wft-710" comment="the version of wordpad.exe is less than 4.0.1381.7312" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir</component>
          <component type="literal">\Windows NT\Accessories\wordpad.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>4</major>
          <minor>0</minor>
          <build>1381</build>
          <private>7312</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-549" comment="the 64-bit WOW version of nddenb32.dll is less than 5.1.2600.1555" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\SysWOW64\nddenb32.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>1555</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-545" comment="the version of nddenb32.dll is less than 5.1.2600.1555" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\inetsrv\nddenb32.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>1555</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-1151" comment="a vulnerable version of nddenb32.dll exists" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wft-545"/>
      <subtest negate="false" test_ref="wft-549"/>
    </compound_test>
    <file_test id="wft-548" comment="the 64-bit WOW version of netdde.exe is less than 5.1.2600.1567" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\SysWOW64\netdde.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>1567</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-544" comment="the version of netdde.exe is less than 5.1.2600.1567" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\inetsrv\netdde.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>1567</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-1152" comment="a vulnerable version of netdde.exe exists" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wft-544"/>
      <subtest negate="false" test_ref="wft-548"/>
    </compound_test>
    <file_test id="wft-353" comment="the version of user32.dll is less than 5.0.2195.7017" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\user32.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>2195</build>
          <private>7017</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-370" comment="machine has followed the QFE update path and hlink.dll is less than 5.2.3790.227" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\hlink.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>2</minor>
          <build>3790</build>
          <private>227</private>
        </version>
        <development_class operator="equals">srv03_qfe</development_class>
      </data>
    </file_test>
    <file_test id="wft-371" comment="machine has followed the GDR update path and hlink.dll is less than 5.2.3790.225" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\hlink.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>2</minor>
          <build>3790</build>
          <private>225</private>
        </version>
        <development_class operator="not equal">srv03_qfe</development_class>
      </data>
    </file_test>
    <compound_test id="cmp-177" comment="a vulnerable version of hlink.dll exists on Server 2003" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wft-371"/>
      <subtest negate="false" test_ref="wft-370"/>
    </compound_test>
    <file_test id="wft-435" comment="The version of Ntoskrnl.exe is less than 5.0.2195.6159" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\System32\Ntoskrnl.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>2195</build>
          <private>6159</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-169" comment="the version of hypertrm.dll is less than 5.2.3790.233" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\hypertrm.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>2</minor>
          <build>3790</build>
          <private>233</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-44" comment="the patch Windows 2003 kb873339 is installed " check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">SOFTWARE\Microsoft\Updates\Windows Server 2003\SP1\KB873339\ Filelist</key>
        <name operator="pattern match">^.*$</name>
      </object>
    </registry_test>
    <file_test id="wft-528" comment="the version of nddenb32.dll is less than 5.0.2195.6922" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\netdde.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>2195</build>
          <private>6922</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-527" comment="the version of netdde.exe is less than 5.0.2195.6952" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\netdde.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>2195</build>
          <private>6952</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-352" comment="the version of user32.dll is less than 4.0.1381.33630" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\user32.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>4</major>
          <minor>0</minor>
          <build>1381</build>
          <private>33630</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-459" comment="the version of shell32.dll is less than 6.0.2600.115 " check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\shell32.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>2600</build>
          <private>115</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-1073" comment="XP no Service Pack installed and version of Shell32.dll is less than 6.0.2600.115" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wft-459"/>
      <subtest negate="false" test_ref="wrt-410"/>
    </compound_test>
    <file_test id="wft-458" comment="the version of shell32.dll is less than 6.0.2800.1233 " check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\shell32.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>2800</build>
          <private>1233</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-1072" comment="XP Service Pack 1 and version of Shell32.dll is less than 6.0.2800.1233 " operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wft-458"/>
      <subtest negate="false" test_ref="wrt-4"/>
    </compound_test>
    <compound_test id="cmp-1074" comment="Version check for XP SP1 and XP no service pack for shell32.dll" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-1072"/>
      <subtest negate="false" test_ref="cmp-1073"/>
    </compound_test>
    <registry_test id="wrt-493" comment="Patch KB821557 Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB821557</key>
        <name>Installed</name>
      </object>
      <data operation="AND">
        <value datatype="binary" operator="equals">1</value>
      </data>
    </registry_test>
    <patch_test id="spt-106" comment="Patch 108219-01 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">108219</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">01</version>
      </data>
    </patch_test>
    <package_test id="sat-32" comment="CDE application basic runtime environment (SUNWdtbas/SUNWdtbax) installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <pkginst operator="pattern match">SUNWdtba[sx]</pkginst>
      </object>
    </package_test>
    <file_test id="wft-524" comment="the version of grpconv.exe (system32) is less than 4.0.1381.33577" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\grpconv.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>4</major>
          <minor>0</minor>
          <build>1381</build>
          <private>33577</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-1127" comment="NT Terminal Server and grpconv.exe less than 4.0.1381.33577" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-43"/>
      <subtest negate="false" test_ref="wft-524"/>
    </compound_test>
    <file_test id="wft-523" comment="the version of grpconv.exe (system32) is less than 4.0.1381.7286" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\grpconv.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>4</major>
          <minor>0</minor>
          <build>1381</build>
          <private>7286</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-1126" comment="NT Server and grpconv.exe less than 4.0.1381.7286" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-50"/>
      <subtest negate="false" test_ref="wft-523"/>
    </compound_test>
    <compound_test id="cmp-1128" comment="a vulnerable version of grpconv.exe exists on NT" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-1126"/>
      <subtest negate="false" test_ref="cmp-1127"/>
    </compound_test>
    <file_test id="wft-372" comment="the version of srvsvc.dll is less than 5.1.2600.1613" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\srvsvc.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>1613</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-496" comment="the version of mso.dll is less than 10.0.6714.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir</component>
          <component type="literal">\Microsoft Shared\OFFICE11\MSO.DLL</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>10</major>
          <minor>0</minor>
          <build>6714</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <patch_test id="spt-240" comment="Patch 113575-05 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">113575</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">05</version>
      </data>
    </patch_test>
    <patch_test id="spt-14" comment="Patch 110615-10 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">110615</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">10</version>
      </data>
    </patch_test>
    <patch_test id="spt-13" comment="Patch 107684-10 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">107684</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">10</version>
      </data>
    </patch_test>
    <patch_test id="spt-79" comment="Patch 117000-03 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">117000</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">03</version>
      </data>
    </patch_test>
    <patch_test id="spt-78" comment="Patch 116895-01 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">116895</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">01</version>
      </data>
    </patch_test>
    <file_test id="wft-603" comment="Adobe Acrobat Reader eBook.api plug-in software installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Adobe\Acrobat Reader\6.0\Installer\Path</component>
          <component type="literal">Reader\plug_ins\eBook.api</component>
        </path>
      </object>
    </file_test>
    <registry_test id="wrt-579" comment="the software Adobe Acrobat Reader 6, minor version less than 3 is installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">SOFTWARE\Adobe\Acrobat Reader\6.0\Installer</key>
        <name operator="equals">VersionMin</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="less than">3</value>
      </data>
    </registry_test>
    <registry_test id="wrt-578" comment="the software Adobe Acrobat Reader 6, major version 6 is installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">SOFTWARE\Adobe\Acrobat Reader\6.0\Installer</key>
        <name operator="equals">VersionMax</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">6</value>
      </data>
    </registry_test>
    <compound_test id="cmp-301" comment="the software Adobe Acrobat Reader major version 6, minor version less than 3 is installed" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-578"/>
      <subtest negate="false" test_ref="wrt-579"/>
    </compound_test>
    <file_test id="wft-387" comment="the version of ole32.dll is less than 5.1.2600.1619" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\ole32.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>1619</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-441" comment="the version of psxss.exe is less than 5.0.2195.6929" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\psxss.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>2195</build>
          <private>6929</private>
        </version>
      </data>
    </file_test>
    <rpmversioncompare_test id="rvt-367" comment="kernel-smp rpm older than 2.4.21-15.0.2.EL Epoch 0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">kernel-smp</name>
        <tested_epoch datatype="string" operator="equals">0</tested_epoch>
        <tested_version datatype="string" operator="equals">2.4.21</tested_version>
        <tested_release datatype="string" operator="equals">15.0.2.EL</tested_release>
      </object>
      <data operation="AND">
        <installed_version datatype="string" operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <rpmversioncompare_test id="rvt-366" comment="kernel-hugemem rpm older than 2.4.21-15.0.2.EL Epoch 0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">kernel-hugemem</name>
        <tested_epoch datatype="string" operator="equals">0</tested_epoch>
        <tested_version datatype="string" operator="equals">2.4.21</tested_version>
        <tested_release datatype="string" operator="equals">15.0.2.EL</tested_release>
      </object>
      <data operation="AND">
        <installed_version datatype="string" operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <rpmversioncompare_test id="rvt-364" comment="kernel rpm older than 2.4.21-15.0.2.EL Epoch 0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name>kernel</name>
        <tested_epoch>0</tested_epoch>
        <tested_version>2.4.21</tested_version>
        <tested_release>15.0.2.EL</tested_release>
      </object>
      <data operation="AND">
        <installed_version>earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <compound_test id="cmp-1100" comment="kernel, kernel-hugemem or kernel-smp rpm older than 2.4.21-15.0.2EL Epoch 0" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="rvt-364"/>
      <subtest negate="false" test_ref="rvt-366"/>
      <subtest negate="false" test_ref="rvt-367"/>
    </compound_test>
    <patch_test id="spt-42" comment="Patch 113923-02 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">113923</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">02</version>
      </data>
    </patch_test>
    <package_test id="sat-21" comment="X Window System Font Server (SUNWxwfs) installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <pkginst operator="equals">SUNWxwfs</pkginst>
      </object>
    </package_test>
    <file_test id="wft-519" comment="the version of grpconv.exe (system32) is less than 5.0.2195.6966" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\grpconv.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>2195</build>
          <private>6966</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-89" comment="Patch KB873354 installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90510409-6D54-11D4-BEE3-00C04F990354}</key>
        <name operator="equals">WindowsInstaller</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <registry_test id="wrt-525" comment="Visio Professional 2002 with service pack 2" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>Software\Microsoft\Windows\CurrentVersion\Uninstall\{90510409-6D54-11D4-BEE3-00C04F990354}</key>
        <name>DisplayVersion</name>
      </object>
      <data operation="AND">
        <value operator="equals">10.2.5110</value>
      </data>
    </registry_test>
    <file_test id="wft-165" comment="the version of wins.exe is less than 4.0.1381.33618" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\wins.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>4</major>
          <minor>0</minor>
          <build>1381</build>
          <private>33618</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-482" comment="the version of msadco.dll is less than 2.53.6202.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir</component>
          <component type="literal">\Common Files\System\msadc\msadco.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>2</major>
          <minor>53</minor>
          <build>6202</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <process_test id="uct-16" comment="sshd running" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <command operator="pattern match">^.*sshd.*</command>
      </object>
    </process_test>
    <patch_test id="spt-19" comment="Patch 113273-04 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">113273</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">04</version>
      </data>
    </patch_test>
    <file_test id="wft-715" comment="the version of Gdiplus.dll for Microsoft Office is less than 6.0.3264.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\11.0\Common\InstallRoot\Path</component>
          <component type="literal">GDIPLUS.DLL</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>3264</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-515" comment="Microsoft Office 2003 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90110409-6000-11D3-8CFE-0150048383C9}</key>
        <name>DisplayVersion</name>
      </object>
      <data operation="AND">
        <value>11.0.6252.7</value>
      </data>
    </registry_test>
    <registry_test id="wrt-413" comment="Windows XP or Windows Server 2003 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion</key>
        <name>CurrentVersion</name>
      </object>
      <data operation="AND">
        <value operator="pattern match">^5\.[1-2]$</value>
      </data>
    </registry_test>
    <registry_test id="wrt-535" comment="Microsoft Office 2000 Professional Service Pack 3 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{00010409-78E1-11D2-B60F-006097C998E7}</key>
        <name>DisplayVersion</name>
      </object>
      <data operation="AND">
        <value>9.00.9327</value>
      </data>
    </registry_test>
    <registry_test id="wrt-529" comment="Microsoft Office 2000 Premium Service Pack 3 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{00000409-78E1-11D2-B60F-006097C998E7}</key>
        <name>DisplayVersion</name>
      </object>
      <data operation="AND">
        <value>9.00.9327</value>
      </data>
    </registry_test>
    <compound_test id="cmp-1103" comment="Microsoft Office 2000 (Premium or Professional) Service Pack 3 is installed" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-529"/>
      <subtest negate="false" test_ref="wrt-535"/>
    </compound_test>
    <registry_test id="wrt-530" comment="the patch kb873380 for Office 2000 SP3 is installed " check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Patches\A1334AC428B43BF4E9547C55D3DFE977</key>
        <name operator="pattern match">.*</name>
      </object>
      <data operation="AND">
        <value>Installed</value>
      </data>
    </registry_test>
    <file_test id="wft-489" comment="the version of msconv97.dll is less than 2003.1100.6252.0 " check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir</component>
          <component type="literal">\Microsoft Shared\TextConv\MSCONV97.DLL</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>2003</major>
          <minor>1100</minor>
          <build>6252</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <unknown_test id="ukn-2" comment="Lance Ethernet interface in use" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <oval:notes>
        <oval:note/>
      </oval:notes>
    </unknown_test>
    <file_test id="uft-30" comment="Lance Ethernet (le) interface configured to start" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="pattern match">
          <component type="literal">hostname6?\.le.*</component>
        </path>
      </object>
    </file_test>
    <patch_test id="spt-18" comment="Patch 115172-01 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">115172</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">01</version>
      </data>
    </patch_test>
    <patch_test id="spt-17" comment="Patch 112609-02 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">112609</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">02</version>
      </data>
    </patch_test>
    <patch_test id="spt-16" comment="Patch 112604-02 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">112604</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">02</version>
      </data>
    </patch_test>
    <file_test id="wft-468" comment="machine has followed the QFE update path and inetcomm.dll is less than 6.0.3790.185" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\inetcomm.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>3790</build>
          <private>185</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-462" comment="machine has followed the GDR update path and inetcomm.dll is less than 6.0.3790.181" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\inetcomm.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>3790</build>
          <private>181</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-1098" comment="a vulnerable version of inetcomm.dll exisits" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wft-462"/>
      <subtest negate="false" test_ref="wft-468"/>
    </compound_test>
    <package_test id="sat-2" comment="Sun Crypto Accelerator 4000 software installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <pkginst datatype="string" operator="equals">SUNWkcl2r</pkginst>
      </object>
    </package_test>
    <patch_test id="spt-243" comment="Patch 114796-04 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">114796</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">04</version>
      </data>
    </patch_test>
    <patch_test id="spt-22" comment="Patch 111400-02 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">111400</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">02</version>
      </data>
    </patch_test>
    <patch_test id="spt-21" comment="Patch 107337-03 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">107337</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">03</version>
      </data>
    </patch_test>
    <patch_test id="spt-20" comment="Patch 114636-01 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">114636</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">01</version>
      </data>
    </patch_test>
    <package_test id="sat-18" comment="Kodak Color Managment Server (KCMS) Runtime Environment (SUNWkcsrt/SUNWkcsrx) installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <pkginst operator="pattern match">SUNWkcsr[tx]</pkginst>
      </object>
    </package_test>
    <process_test id="uct-13" comment="Apache running with SunPlex Manager config" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <command datatype="string" operator="pattern match">^/usr/apache/bin/httpd.*SUNWscvw/conf/httpd.conf.*</command>
      </object>
    </process_test>
    <package_test id="sat-8" comment="SunCluster Component SUNWscvw installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <pkginst datatype="string" operator="equals">SUNWscvw</pkginst>
      </object>
    </package_test>
    <patch_test id="spt-269" comment="Patch 115055-01 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">115055</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">01</version>
      </data>
    </patch_test>
    <patch_test id="spt-268" comment="Patch 115054-01 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">115054</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">01</version>
      </data>
    </patch_test>
    <patch_test id="spt-267" comment="Patch 113508-02 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">113508</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">02</version>
      </data>
    </patch_test>
    <patch_test id="spt-266" comment="Patch 113505-02 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">113505</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">02</version>
      </data>
    </patch_test>
    <file_test id="wft-355" comment="the version of user32.dll is less than 5.2.3790.245" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\user32.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>2</minor>
          <build>3790</build>
          <private>245</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-62" comment="Windows Server 2003 or Windows Server 2003 64-bit Edition is installed" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-61"/>
      <subtest negate="false" test_ref="cmp-34"/>
    </compound_test>
    <file_test id="wft-394" comment="the version of Llssrv.exe is less than 5.0.2195.7021" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\llssrv.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>2195</build>
          <private>7021</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-438" comment="the patch kb890923 is installed (Hotfix key)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">SOFTWARE\Microsoft\Updates\Windows Server 2003\SP1\KB890923 \Filelist</key>
        <name operator="pattern match">^.*$</name>
      </object>
    </registry_test>
    <file_test id="wft-594" comment="the version of mshtml.dll is less than 6.0.3790.279" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mshtml.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>3790</build>
          <private>279</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-176" comment="the version of hypertrm.dll is less than 5.1.2600.2563" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\hypertrm.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>2563</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-163" comment="the version of wins.exe is less than 5.0.2195.7005" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\wins.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>2195</build>
          <private>7005</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-560" comment="the patch kb834707-ie501sp4 is installed (Hotfix key)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB834707-ie501sp4-20040929.111451</key>
        <name>Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-561" comment="the version of mshtml.dll is less than 5.0.3534.2800" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mshtml.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>3534</build>
          <private>2800</private>
        </version>
      </data>
    </file_test>
    <patch_test id="spt-59" comment="Patch 112908-10 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">112908</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">10</version>
      </data>
    </patch_test>
    <patch_test id="spt-58" comment="Patch 112921-02 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">112921</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">02</version>
      </data>
    </patch_test>
    <patch_test id="spt-57" comment="Patch 112923-03 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">112923</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">03</version>
      </data>
    </patch_test>
    <patch_test id="spt-56" comment="Patch 112925-03 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">112925</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">03</version>
      </data>
    </patch_test>
    <compound_test id="cmp-81" comment="Patches 112925-03,112923-03,112921-02, and 112908-10 or later installed" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="spt-56"/>
      <subtest negate="false" test_ref="spt-57"/>
      <subtest negate="false" test_ref="spt-58"/>
      <subtest negate="false" test_ref="spt-59"/>
    </compound_test>
    <patch_test id="spt-55" comment="Patch 112390-08 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">112390</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">08</version>
      </data>
    </patch_test>
    <patch_test id="spt-54" comment="Patch 112237-09 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">112237</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">09</version>
      </data>
    </patch_test>
    <compound_test id="cmp-79" comment="Patches 112237-09 and 112390-08 or later installed" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="spt-54"/>
      <subtest negate="false" test_ref="spt-55"/>
    </compound_test>
    <package_test id="sat-31" comment="Kerberos v5 - Usr (SUNWkrbu/SUNWkrbux) installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <oval:notes>
        <oval:note>SUNWkrbu - 32bit, SUNWkrbux - 64bit</oval:note>
      </oval:notes>
      <object>
        <pkginst operator="pattern match">SUNWkrbux?</pkginst>
      </object>
    </package_test>
    <package_test id="sat-30" comment="Kerberos v5 - Root (SUNWkrbr) installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <pkginst operator="equals">SUNWkrbr</pkginst>
      </object>
    </package_test>
    <compound_test id="cmp-74" comment="Kerberos v5 (any SUNWkrbr/SUNWkrbu/SUNWkrbux) installed" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="sat-30"/>
      <subtest negate="false" test_ref="sat-31"/>
    </compound_test>
    <file_test id="wft-365" comment="the version of dplayx.dll is less than 5.2.3790.163" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\dplayx.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>2</minor>
          <build>3790</build>
          <private>163</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-968" comment="DirectX 8.1 without WindowsServer2003-KB839643-x86-ENU.EXE Installed" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wft-365"/>
      <subtest negate="false" test_ref="wrt-404"/>
      <subtest negate="true" test_ref="wrt-407"/>
    </compound_test>
    <compound_test id="cmp-969" comment="DirectX without KB839643 Installed on Windows Server 2003" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-962"/>
      <subtest negate="false" test_ref="cmp-964"/>
      <subtest negate="false" test_ref="cmp-968"/>
    </compound_test>
    <registry_test id="wrt-558" comment="Patch KB873350 Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key datatype="string" operator="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB873350</key>
        <name datatype="string" operator="equals">File</name>
      </object>
      <data operation="AND">
        <value datatype="binary" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-552" comment="the version of rpcrt4.dll is less than 4.0.1381.7299" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\rpcrt4.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>4</major>
          <minor>0</minor>
          <build>1381</build>
          <private>7299</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-481" comment="the patch kb842526 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB842526</key>
        <name>Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals"/>
      </data>
    </registry_test>
    <file_test id="wft-442" comment="the version of Umandlg.dll is less than 1.0.0.5" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\Umandlg.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>1</major>
          <minor>0</minor>
          <build>0</build>
          <private>5</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-439" comment="the version of Sp3res.dll is less than 5.0.2195.6928" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\Sp3res.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>2195</build>
          <private>6928</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-557" comment="the patch kb834707 is installed (Hotfix key)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB834707</key>
        <name>Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-558" comment="the version of mshtml.dll is less than 6.0.3790.219" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mshtml.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>3790</build>
          <private>219</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-74" comment="the patch Windows XP KB871250 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">SOFTWARE\Microsoft\Updates\Windows XP\SP2\KB871250\Filelist</key>
        <name operator="pattern match">^.*$</name>
      </object>
    </registry_test>
    <file_test id="wft-357" comment="Indexing Service ciodm.dll is less than 5.1.2600.1596" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\ciodm.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>1596</private>
        </version>
      </data>
    </file_test>
    <unknown_test id="ukn-27" comment="Auditing Administrative or System-Wide Administrative audit classes" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <oval:notes>
        <oval:note>egrep ^flags:.*a[sd] /etc/security/audit_control True if any lines returned</oval:note>
      </oval:notes>
    </unknown_test>
    <unknown_test id="ukn-26" comment="Basic Security Module enabled" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <oval:notes>
        <oval:note>grep c2audit /etc/system True if "set c2audit:audit_load = 1" or similiar</oval:note>
      </oval:notes>
    </unknown_test>
    <patch_test id="spt-235" comment="Patch 114332-12 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">114332</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">12</version>
      </data>
    </patch_test>
    <patch_test id="spt-234" comment="Patch 109007-18 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="not equal">109007</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">18</version>
      </data>
    </patch_test>
    <patch_test id="spt-233" comment="Patch 106541-33 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">106541</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">33</version>
      </data>
    </patch_test>
    <process_test id="uct-17" comment="ypxfrd running" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <command operator="pattern match">^.*ypxfrd.*</command>
      </object>
    </process_test>
    <patch_test id="spt-35" comment="Patch 113579-01 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">113579</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">01</version>
      </data>
    </patch_test>
    <patch_test id="spt-34" comment="Patch 109328-03 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">109328</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">03</version>
      </data>
    </patch_test>
    <patch_test id="spt-33" comment="Patch 106541-24 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">106541</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">24</version>
      </data>
    </patch_test>
    <package_test id="sat-20" comment="NIS Server - User (SUNWypu) installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <oval:notes>
        <oval:note>Package which contains /usr/lib/netsvc/yp/ypxfrd</oval:note>
      </oval:notes>
      <object>
        <pkginst operator="equals">SUNWypu</pkginst>
      </object>
    </package_test>
    <file_test id="wft-364" comment="the version of dplayx.dll is less than 5.2.3790.163 on 64-bit edition" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\SysWOW64\dplayx.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>2</minor>
          <build>3790</build>
          <private>163</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-967" comment="DirectX 8.1 without kb839643 installed" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wft-364"/>
      <subtest negate="false" test_ref="wrt-404"/>
      <subtest negate="true" test_ref="wrt-407"/>
    </compound_test>
    <file_test id="wft-522" comment="the version of netdde.exe is less than 4.0.1381.7280" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\netdde.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>4</major>
          <minor>0</minor>
          <build>1381</build>
          <private>7280</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-518" comment="the version of nddenb32.dll is less than 4.0.1381.7268" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\nddenb32.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>4</major>
          <minor>0</minor>
          <build>1381</build>
          <private>7268</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-448" comment="the version of shell32.dll is less than 6.0.3790.168" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\shell32.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>3790</build>
          <private>168</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-85" comment="The patch KB885492 is installed on Windows 2000" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">SOFTWARE\Microsoft\Updates\Windows Media Player 9\KB885492</key>
        <name operator="equals">PackageVersion</name>
      </object>
      <data operation="AND">
        <value operator="equals">1.1</value>
      </data>
    </registry_test>
    <registry_test id="wrt-94" comment="Patch KB873355 installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{903B0409-6000-11D3-8CFE-0050048383C9}}</key>
        <name operator="equals">DisplayVersion</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">10.0.8326.0</value>
      </data>
    </registry_test>
    <file_test id="wft-377" comment="the version of mso.dll is less than 10.0.6735.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir</component>
          <component type="literal">\Microsoft Shared\OFFICE10\MSO.DLL</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>10</major>
          <minor>0</minor>
          <build>6735</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-523" comment="Windows Project Professional 2002 Service Pack 1 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{903B0409-6000-11D3-8CFE-0050048383C9}</key>
        <name>DisplayVersion</name>
      </object>
      <data operation="AND">
        <value operator="equals">10.0.8326.0</value>
      </data>
    </registry_test>
    <compound_test id="cmp-311" comment="SP1 is installed and the version of rpcrt4.dll is less than 5.1.2600.1254" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-4"/>
      <subtest negate="false" test_ref="wft-366"/>
    </compound_test>
    <file_test id="wft-359" comment="the version of rpcrt4.dll is less than 5.1.2600.109" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\rpcrt4.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>109</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-306" comment="no service pack is installed and rpcrt4.dll is less than 5.1.2600.109" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="true" test_ref="wrt-3"/>
      <subtest negate="false" test_ref="wft-359"/>
    </compound_test>
    <compound_test id="cmp-312" comment="A vulnerable version of rpcrt4.dll exists depending on service pack level" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-306"/>
      <subtest negate="false" test_ref="cmp-311"/>
    </compound_test>
    <compound_test id="cmp-310" comment="Windows XP 32-bit OR Windows XP 64-bit is installed" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-1058"/>
      <subtest negate="false" test_ref="cmp-1112"/>
    </compound_test>
    <registry_test id="wrt-542" comment="the patch WindowsServer2003-KB885881-x86-enu.exe is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key datatype="string" operator="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB885881</key>
        <name datatype="string" operator="equals">Installed</name>
      </object>
      <data operation="AND">
        <value datatype="string" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-502" comment="The version of smtpsvc.dll is less than 6.0.3790.211" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\inetsrv\smtpsvc.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>3790</build>
          <private>211</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-81" comment="the patch kb888302 is installed (Hotfix key)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB888302</key>
        <name operator="equals">Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-373" comment="the version of srvsvc.dll is less than 5.1.2600.2577" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\srvsvc.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>2577</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-37" comment="the patch KB885249 is installed (Hotfix key)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB885249</key>
        <name operator="equals">Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-156" comment="the version of Dhcpssvc.dll is less than 4.0.1381.7304" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\Dhcpssvc.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>4</major>
          <minor>0</minor>
          <build>1381</build>
          <private>7304</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-410" comment="the version of msmsgs.exe is less than 5.1.0.639" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir</component>
          <component type="literal">\Messengermsmsgs.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>0</build>
          <private>639</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-179" comment="Windows Messenger 5.1 is installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">\SOFTWARE\Microsoft\CurrentVersion\Uninstall\{C3A6819F-62D3-4750-AF1C-28206DDF2C2E}</key>
        <name operator="equals">Windows Messenger 5.1</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">5.1.0639</value>
      </data>
    </registry_test>
    <file_test id="wft-437" comment="The version of Ntoskrnl.exe is less than 4.0.1381.33545" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\System32\Ntoskrnl.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>4</major>
          <minor>0</minor>
          <build>1381</build>
          <private>33545</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-442" comment="the patch kb890923 is installed (Win2K SP4  Hotfix key)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">SSOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB890923 -ie501sp4-20050225.100310</key>
        <name datatype="int" operator="equals">Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-599" comment="the version of mshtml.dll is less than 5.0.3826.2400" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mshtml.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>3826</build>
          <private>2400</private>
        </version>
      </data>
    </file_test>
    <process_test id="uct-21" comment="rpcbind running" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <command operator="pattern match">.*rpcbind.*</command>
      </object>
    </process_test>
    <patch_test id="spt-142" comment="Patch 108764-01 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <oval:notes>
        <oval:note>CVE-2002-1265</oval:note>
      </oval:notes>
      <object>
        <base datatype="int" operator="equals">108764</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">01</version>
      </data>
    </patch_test>
    <patch_test id="spt-141" comment="Patch 108762-01 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <oval:notes>
        <oval:note>CVE-2002-1265</oval:note>
      </oval:notes>
      <object>
        <base datatype="int" operator="equals">108762</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">01</version>
      </data>
    </patch_test>
    <patch_test id="spt-140" comment="Patch 108760-01 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <oval:notes>
        <oval:note>CVE-2002-1265</oval:note>
      </oval:notes>
      <object>
        <base datatype="int" operator="equals">108760</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">01</version>
      </data>
    </patch_test>
    <patch_test id="spt-139" comment="Patch 108758-01 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <oval:notes>
        <oval:note>CVE-2002-1265</oval:note>
      </oval:notes>
      <object>
        <base datatype="int" operator="equals">108758</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">01</version>
      </data>
    </patch_test>
    <patch_test id="spt-138" comment="Patch 108756-01 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <oval:notes>
        <oval:note>CVE-2002-1265</oval:note>
      </oval:notes>
      <object>
        <base datatype="int" operator="equals">108756</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">01</version>
      </data>
    </patch_test>
    <patch_test id="spt-137" comment="Patch 108754-01 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <oval:notes>
        <oval:note>CVE-2002-1265</oval:note>
      </oval:notes>
      <object>
        <base datatype="int" operator="equals">108754</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">01</version>
      </data>
    </patch_test>
    <patch_test id="spt-136" comment="Patch 108551-03 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <oval:notes>
        <oval:note>CVE-2002-1265</oval:note>
      </oval:notes>
      <object>
        <base datatype="int" operator="equals">108551</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">03</version>
      </data>
    </patch_test>
    <patch_test id="spt-135" comment="Patch 107477-03 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <oval:notes>
        <oval:note>CVE-2002-1265</oval:note>
      </oval:notes>
      <object>
        <base datatype="int" operator="equals">107477</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">03</version>
      </data>
    </patch_test>
    <patch_test id="spt-134" comment="Patch 106942-09 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <oval:notes>
        <oval:note>CVE-2002-1265</oval:note>
      </oval:notes>
      <object>
        <base datatype="int" operator="equals">106942</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">09</version>
      </data>
    </patch_test>
    <patch_test id="spt-133" comment="Patch 106541-14 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <oval:notes>
        <oval:note>CVE-2002-1265</oval:note>
      </oval:notes>
      <object>
        <base datatype="int" operator="equals">106541</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">14</version>
      </data>
    </patch_test>
    <patch_test id="spt-132" comment="Patch 108752-01 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <oval:notes>
        <oval:note>CVE-2002-1265</oval:note>
      </oval:notes>
      <object>
        <base datatype="int" operator="equals">108752</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">01</version>
      </data>
    </patch_test>
    <compound_test id="cmp-285" comment="Patches 108752-01 or 106541-14 installed" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="spt-132"/>
      <subtest negate="false" test_ref="spt-133"/>
    </compound_test>
    <patch_test id="spt-131" comment="Patch 108750-01 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <oval:notes>
        <oval:note>CVE-2002-1265</oval:note>
      </oval:notes>
      <object>
        <base datatype="int" operator="equals">108750</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">01</version>
      </data>
    </patch_test>
    <patch_test id="spt-130" comment="Patch 108748-01 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <oval:notes>
        <oval:note>CVE-2002-1265</oval:note>
      </oval:notes>
      <object>
        <base datatype="int" operator="equals">108748</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">01</version>
      </data>
    </patch_test>
    <compound_test id="cmp-287" comment="All RPC w/TCP patches installed - CVE-2002-1265" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="spt-130"/>
      <subtest negate="false" test_ref="spt-131"/>
      <subtest negate="false" test_ref="cmp-285"/>
      <subtest negate="false" test_ref="spt-134"/>
      <subtest negate="false" test_ref="spt-135"/>
      <subtest negate="false" test_ref="spt-136"/>
      <subtest negate="false" test_ref="spt-137"/>
      <subtest negate="false" test_ref="spt-138"/>
      <subtest negate="false" test_ref="spt-139"/>
      <subtest negate="false" test_ref="spt-140"/>
      <subtest negate="false" test_ref="spt-141"/>
      <subtest negate="false" test_ref="spt-142"/>
    </compound_test>
    <file_test id="wft-450" comment="the version of shell32.dll is less than 6.0.2800.1556" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\shell32.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>2800</build>
          <private>1556</private>
        </version>
      </data>
    </file_test>
    <process_test id="uct-11" comment="Sendmail running" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <command operator="pattern match">.*sendmail .*</command>
      </object>
    </process_test>
    <patch_test id="spt-65" comment="Patch 113575-03 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">113575</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">03</version>
      </data>
    </patch_test>
    <patch_test id="spt-64" comment="Patch 110615-08 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">110615</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">08</version>
      </data>
    </patch_test>
    <patch_test id="spt-63" comment="Patch 107684-08 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">107684</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">08</version>
      </data>
    </patch_test>
    <package_test id="sat-14" comment="Sendmail - user (SUNWsndmu) installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <pkginst operator="equals">SUNWsndmu</pkginst>
      </object>
    </package_test>
    <registry_test id="wrt-567" comment="Users not saving encrypted pages to disk  (DisableCachingOfSSLPages)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_CURRENT_USER</hive>
        <key operator="pattern match">^Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings$</key>
        <name>DisableCachingOfSSLPages</name>
      </object>
      <data operation="AND">
        <value operator="not equal">1</value>
      </data>
    </registry_test>
    <registry_test id="wrt-562" comment="the patch kb834707 is installed (Installed Components key)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key datatype="string" operator="equals">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB834707-ie6-20040929.115007</key>
        <name datatype="string" operator="equals">IsInstalled</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-563" comment="the version of mshtml.dll is less than 6.0.2745.2800" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mshtml.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>2745</build>
          <private>2800</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-608" comment="the version of winword.exe is less than 9.0.0.8929" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Winword.exe\Path</component>
          <component type="literal">winword.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>9</major>
          <minor>0</minor>
          <build>0</build>
          <private>8929</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-485" comment="MaxClientRequestBufferData less than or equal to 16384" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>System\CurrentControlSet\Services\w3svc\parameters</key>
        <name>MaxClientRequestBufferData</name>
      </object>
      <data operation="AND">
        <value operator="less than or equal">16384</value>
      </data>
    </registry_test>
    <metabase_test id="wmt-207" comment="Permanent redirects enabled" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <key datatype="string" operator="pattern match">LM\\W3SVC\\/d*\\ROOT</key>
        <id datatype="int">6011</id>
      </object>
      <data operation="AND">
        <name>HttpRedirect</name>
        <data operator="pattern match">^http:*,PERMANENT,*</data>
      </data>
    </metabase_test>
    <file_test id="wft-446" comment="the version of w3svc.dll is less than 4.2.788.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\inetsrv\w3svc.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>4</major>
          <minor>2</minor>
          <build>788</build>
          <private>1</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-484" comment="the patch q841373 is installed (Hotfix key)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q841373</key>
        <name>Installed</name>
      </object>
      <data operation="AND">
        <value datatype="binary" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-361" comment="the version of dplayx.dll is less than 5.1.2600.1517" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\dplayx.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>1517</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-963" comment="DirectX 8.1 without WindowsXP-KB839643-x86-ENU.EXE Installed on XP SP1" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wft-361"/>
      <subtest negate="false" test_ref="wrt-404"/>
      <subtest negate="false" test_ref="wrt-407"/>
      <subtest negate="true" test_ref="wrt-410"/>
    </compound_test>
    <registry_test id="wrt-407" comment="the patch kb839643 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB839643</key>
        <name>Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <registry_test id="wrt-404" comment="DirectX 8.1x Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\DirectX</key>
        <name>Version</name>
      </object>
      <data operation="AND">
        <value operator="pattern match">^4\.08\.01.*$</value>
      </data>
    </registry_test>
    <file_test id="wft-360" comment="the version of dplayx.dll is less than 5.1.2600.148" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\dplayx.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>148</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-961" comment="DirectX 8.1 without WindowsXP-KB839643-x86-ENU.EXE Installed on XP Gold" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wft-360"/>
      <subtest negate="false" test_ref="wrt-3"/>
      <subtest negate="false" test_ref="wrt-404"/>
      <subtest negate="true" test_ref="wrt-407"/>
    </compound_test>
    <compound_test id="cmp-965" comment="DirectX 8.1 without WindowsXP-KB839643-x86-ENU.EXE Installed" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-961"/>
      <subtest negate="false" test_ref="cmp-963"/>
    </compound_test>
    <registry_test id="wrt-409" comment="Patch DirectX90-KB839643-x86-ENU Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB839643-DirectX9</key>
        <name>Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <registry_test id="wrt-406" comment="DirectX 9.0x Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\DirectX</key>
        <name>Version</name>
      </object>
      <data operation="AND">
        <value operator="pattern match">^4\.09.*$</value>
      </data>
    </registry_test>
    <file_test id="wft-363" comment="the version of dplayx.dll is less than 5.3.0.903" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\dplayx.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>3</minor>
          <build>0</build>
          <private>903</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-964" comment="DirectX 9.0 without DirectX9-KB839643-x86-ENU.EXE Installed" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wft-363"/>
      <subtest negate="false" test_ref="wrt-406"/>
      <subtest negate="true" test_ref="wrt-409"/>
    </compound_test>
    <registry_test id="wrt-408" comment="Patch DirectX82-KB839643-x86-ENU Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB839643-DirectX82</key>
        <name>Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <registry_test id="wrt-405" comment="DirectX 8.2 Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\DirectX</key>
        <name>Version</name>
      </object>
      <data operation="AND">
        <value operator="pattern match">^4\.08\.02.*$</value>
      </data>
    </registry_test>
    <file_test id="wft-362" comment="the version of dplayx.dll is less than 5.2.3677.144" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\dplayx.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>2</minor>
          <build>3677</build>
          <private>144</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-962" comment="DirectX 8.2 without DirectX82-KB839643-x86-ENU.EXE Installed" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wft-362"/>
      <subtest negate="false" test_ref="wrt-405"/>
      <subtest negate="true" test_ref="wrt-408"/>
    </compound_test>
    <compound_test id="cmp-966" comment="DirectX without KB839643 Installed" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-962"/>
      <subtest negate="false" test_ref="cmp-964"/>
      <subtest negate="false" test_ref="cmp-965"/>
    </compound_test>
    <file_test id="wft-590" comment="the version of shell32.dll is less than 6.0.2800.1643" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\shell32.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>2800</build>
          <private>1643</private>
        </version>
      </data>
    </file_test>
    <patch_test id="spt-2" comment="Patch 113575-01 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">113575</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">01</version>
      </data>
    </patch_test>
    <package_test id="sat-3" comment="Sendmail - root (SUNWsndmr) installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <pkginst operator="equals">SUNWsndmr</pkginst>
      </object>
    </package_test>
    <registry_test id="wrt-479" comment="POSIX is enabled" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">SYSTEM\CurrentControlSet\Control\Session Manager\Subsystem</key>
        <name operator="equals">Posix</name>
      </object>
    </registry_test>
    <file_test id="wft-443" comment="the version of psxss.exe is less than 4.0.1381.7269" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\psxss.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>4</major>
          <minor>0</minor>
          <build>1381</build>
          <private>7269</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-1062" comment="This is an NT Workstation or Windows NT Server 4.0 is installed" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-44"/>
      <subtest negate="false" test_ref="wrt-40"/>
    </compound_test>
    <compound_test id="cmp-1063" comment="The version of psxss.exe is less than 4.0.1381.7269 on either NT Workstation or NT Server 4.0" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-1062"/>
      <subtest negate="false" test_ref="wft-443"/>
    </compound_test>
    <file_test id="wft-440" comment="the version of psxss.exe is less than 4.0.1381.33567" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\psxss.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>4</major>
          <minor>0</minor>
          <build>1381</build>
          <private>33567</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-1060" comment="This is an NT Terminal Server and the version of psxss.exe is less than 4.0.1381.33567" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wft-440"/>
      <subtest negate="false" test_ref="wrt-43"/>
    </compound_test>
    <compound_test id="cmp-1064" comment="Version check for psxss.exe on NT Workstation, Server 4.0 and NT Terminal Server" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-1060"/>
      <subtest negate="false" test_ref="cmp-1063"/>
    </compound_test>
    <registry_test id="wrt-480" comment="the patch kb841872 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB841872</key>
        <name>Installed</name>
      </object>
      <data operation="AND">
        <value datatype="binary" operator="equals">1</value>
      </data>
    </registry_test>
    <inetd_test id="sit-2" comment="inetd.conf contains smbd" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <server_program operator="pattern match">^.*smbd.*</server_program>
      </object>
    </inetd_test>
    <compound_test id="cmp-56" comment="Inetd running and inetd.conf contains smbd" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="uct-4"/>
      <subtest negate="false" test_ref="sit-2"/>
    </compound_test>
    <patch_test id="spt-15" comment="Patch 114684-02 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">114684</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">02</version>
      </data>
    </patch_test>
    <package_test id="sat-15" comment="Samba (SUNWsmbar) installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <pkginst operator="equals">SUWNsmbar</pkginst>
      </object>
    </package_test>
    <patch_test id="spt-250" comment="Patch 112908-15 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">112908</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">15</version>
      </data>
    </patch_test>
    <file_test id="wft-469" comment="the version of inetcomm.dll is less than 5.50.4942.400" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\inetcomm.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>50</minor>
          <build>4942</build>
          <private>400</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-69" comment="the patch Windows 2003 KB871250 is installed " check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">SOFTWARE\Microsoft\Updates\Windows Server 2003\SP1\KB871250\Filelist</key>
        <name operator="pattern match">^.*$</name>
      </object>
    </registry_test>
    <file_test id="wft-356" comment="Indexing Service ciodm.dll is less than 5.2.3790.220" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\ciodm.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>2</minor>
          <build>3790</build>
          <private>220</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-507" comment="the version of gdi32.dll is less than 5.0.2195.6945" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\gdi32.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>2195</build>
          <private>6945</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-609" comment="the version of winword.exe is less than 10.0.6754.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Winword.exe\Path</component>
          <component type="literal">winword.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>10</major>
          <minor>0</minor>
          <build>6754</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <patch_test id="spt-25" comment="Patch 109326-10 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">109326</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">10</version>
      </data>
    </patch_test>
    <patch_test id="spt-24" comment="Patch 106938-07 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">106938</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">07</version>
      </data>
    </patch_test>
    <registry_test id="wrt-559" comment="the patch kb834707-ie501sp3 is installed (Hotfix key)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB834707-ie501sp3-20040929.121357</key>
        <name>Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-560" comment="the version of mshtml.dll is less than 5.0.3821.2800" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mshtml.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>3821</build>
          <private>2800</private>
        </version>
      </data>
    </file_test>
    <textfilecontent_test id="tft-8" comment="/etc/syslog.conf is configured to log &quot;debug&quot; level messages for at least daemon" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/etc/syslog.conf</component>
        </path>
        <line operator="pattern match">^[^#]*(\*|daemon)\.debug</line>
      </object>
    </textfilecontent_test>
    <textfilecontent_test id="tft-7" comment="/etc/pam.conf is configured to use pam_krb5 as an 'auth' module and the debug feature of pam_krb5 is enabled" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/etc/pam.conf</component>
        </path>
        <line operator="pattern match">[^#]*pam_krb5.*debug</line>
      </object>
    </textfilecontent_test>
    <patch_test id="spt-236" comment="Patch 112908-12 installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">112908</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="equals">12</version>
      </data>
    </patch_test>
    <patch_test id="spt-248" comment="Patch 112908-13 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">112908</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">13</version>
      </data>
    </patch_test>
    <file_test id="wft-349" comment="the version of lsasrv.dll is less than 5.1.2600.1597" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\lsasrv.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>1597</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-400" comment="the version of shell32.dll is less than 5.0.3900.7009" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\shell32.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>3900</build>
          <private>7009</private>
        </version>
      </data>
    </file_test>
    <patch_test id="spt-7" comment="Patch 111085-02 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">112085</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">02</version>
      </data>
    </patch_test>
    <patch_test id="spt-6" comment="Patch 112300-01 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">112300</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">01</version>
      </data>
    </patch_test>
    <registry_test id="wrt-506" comment="Outlook Web Access exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SYSTEM\CurrentControlSet\Services\MSExchangeweb</key>
        <name operator="pattern match">.*</name>
      </object>
    </registry_test>
    <registry_test id="wrt-505" comment="the  patch kb842436 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Updates\Exchange Server 5.5\SP5\842436a</key>
        <name>IsInstalled</name>
      </object>
      <data operation="AND">
        <value>2</value>
      </data>
    </registry_test>
    <file_test id="wft-485" comment="the version of cdo.dll is less than 5.5.2558.10" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\cdo.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>5</minor>
          <build>2558</build>
          <private>10</private>
        </version>
      </data>
    </file_test>
    <package_test id="sat-10" comment="Core Solaris (SUNWcsu/SUNWcsxu) installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <oval:notes>
        <oval:note>SUNWcsu = 32bit, SUNWcsxu = 64bit</oval:note>
      </oval:notes>
      <object>
        <pkginst operator="pattern match">SUNWcsx?u</pkginst>
      </object>
    </package_test>
    <patch_test id="spt-272" comment="Patch 112970-06 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">112970</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">06</version>
      </data>
    </patch_test>
    <patch_test id="spt-271" comment="Patch 109326-13 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">109326</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">13</version>
      </data>
    </patch_test>
    <patch_test id="spt-270" comment="Patch 106938-08 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">106938</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">08</version>
      </data>
    </patch_test>
    <textfilecontent_test id="tft-6" comment="/etc/krb5/krb5.conf is configured with explicit or rules-based mapping" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/etc/krb5/krb5.conf</component>
        </path>
        <line operator="pattern match">^[^#]auth_to_local.*</line>
      </object>
    </textfilecontent_test>
    <patch_test id="spt-245" comment="Patch 112390-09 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">112390</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">09</version>
      </data>
    </patch_test>
    <patch_test id="spt-244" comment="Patch 112237-11 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">112237</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">11</version>
      </data>
    </patch_test>
    <compound_test id="cmp-1104" comment="Patches 112237-11 and 112390-09 or greater installed" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="spt-244"/>
      <subtest negate="false" test_ref="spt-245"/>
    </compound_test>
    <patch_test id="spt-247" comment="Patch 112536-05 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">112536</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">05</version>
      </data>
    </patch_test>
    <patch_test id="spt-246" comment="Patch 112908-16 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">112908</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">16</version>
      </data>
    </patch_test>
    <file_test id="uft-25" comment="Kerberos 5 installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component">
          <component type="literal">/etc/krb5/krb5.conf</component>
        </path>
      </object>
    </file_test>
    <compound_test id="cmp-948" comment="64 bit version of windows with service pack 1 installed and the version of Ipnathlp.dll is less than 5.1.2600.1364" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-947"/>
      <subtest negate="false" test_ref="wrt-70"/>
    </compound_test>
    <file_test id="wft-347" comment="The version of Ipnathlp.dll is less than 5.1.2600.1364" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\System32\Ipnathlp.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>1364</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-947" comment="The version of Ipnathlp.dll is less than 5.1.2600.1364 and windows service pack 1 is installed" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wft-347"/>
      <subtest negate="false" test_ref="wrt-4"/>
    </compound_test>
    <file_test id="wft-346" comment="The version of Ipnathlp.dll is less than 5.1.2600.137" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\System32\Ipnathlp.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>137</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-946" comment="No service pack is installed and the version of Ipnathlp.dll is less than 5.1.2600.137" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wft-346"/>
      <subtest negate="false" test_ref="wrt-3"/>
    </compound_test>
    <compound_test id="cmp-1095" comment="Version checks on XP for Ipnathlp.dll" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-946"/>
      <subtest negate="false" test_ref="cmp-947"/>
      <subtest negate="false" test_ref="cmp-948"/>
    </compound_test>
    <package_test id="sat-5" comment="Apache (SUNWapchu) installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <pkginst datatype="string" operator="equals">SUNWapchu</pkginst>
      </object>
    </package_test>
    <process_test id="uct-10" comment="Apache running (httpd)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <command datatype="string" operator="pattern match">.*httpd</command>
      </object>
    </process_test>
    <patch_test id="spt-254" comment="Patch 113146-05 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">113146</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">05</version>
      </data>
    </patch_test>
    <patch_test id="spt-253" comment="Patch 116973-01 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">116973</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">01</version>
      </data>
    </patch_test>
    <inetd_test id="sit-3" comment="inetd.conf contains in.ftpd" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <server_program operator="equals">/usr/sbin/in.ftpd</server_program>
      </object>
    </inetd_test>
    <patch_test id="spt-60" comment="Patch 114564-02 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">114564</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">02</version>
      </data>
    </patch_test>
    <package_test id="sat-34" comment="FTP Server - Usr (SUNWftpu) installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <pkginst operator="equals">SUNWftpu</pkginst>
      </object>
    </package_test>
    <file_test id="wft-454" comment="the version of mstask.dll is less than 5.1.2600.1564" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mstask.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>1564</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-1069" comment="service pack 1 is installed and mstask.dll is less than 5.1.2600.1564" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wft-454"/>
      <subtest negate="false" test_ref="wrt-4"/>
    </compound_test>
    <file_test id="wft-453" comment="the version of mstask.dll is less than 5.1.2600.155" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mstask.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>155</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-1068" comment="no service pack is installed and mstask.dll is less than 5.1.2600.155" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wft-453"/>
      <subtest negate="false" test_ref="wrt-3"/>
    </compound_test>
    <compound_test id="cmp-1070" comment="Affected mstask.dll file versions based on service pack levels" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-1068"/>
      <subtest negate="false" test_ref="cmp-1069"/>
    </compound_test>
    <file_test id="wft-391" comment="the version of hhctrl.ocx is less than 5.2.3790.1280" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\hhctrl.ocx</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>2</minor>
          <build>3790</build>
          <private>1280</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-241" comment="Windows XP SP2 or later and version of hhctrl.ocx is less than 5.2.3790.1280" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-29"/>
      <subtest negate="false" test_ref="wft-391"/>
    </compound_test>
    <compound_test id="cmp-237" comment="Windows XP SP1 or earlier and version of hhctrl.ocx is less than 5.2.3790.233" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="true" test_ref="wrt-29"/>
      <subtest negate="false" test_ref="wft-390"/>
    </compound_test>
    <compound_test id="cmp-242" comment="A vulnerable version of hhctrl.ocx exists on Windows XP" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-237"/>
      <subtest negate="false" test_ref="cmp-241"/>
    </compound_test>
    <compound_test id="cmp-951" comment="The version of Ipnathlp.dll is less than 5.2.3790.142 and a 32-bit version of Windows is installed" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wft-348"/>
      <subtest negate="false" test_ref="wrt-72"/>
    </compound_test>
    <file_test id="wft-348" comment="The version of ipnathlp.dll is less than 5.2.3790.142" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\System32\Ipnathlp.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>2</minor>
          <build>3790</build>
          <private>142</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-949" comment="The version of ipnathlp.dll is less than 5.2.3790.142 and a 64 bit version of Windows is installed" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wft-348"/>
      <subtest negate="false" test_ref="wrt-70"/>
    </compound_test>
    <compound_test id="cmp-952" comment="The version of ipnathlp.dll is less than 5.2.3790.142 and 64-bit or 32-bit version of Windows is installed" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-949"/>
      <subtest negate="false" test_ref="cmp-951"/>
    </compound_test>
    <file_test id="wft-123" comment="the version of wordpad.exe is less than 5.1.2600.1606" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir</component>
          <component type="literal">\Windows NT\Accessories\wordpad.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>1606</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-495" comment="all users have the preview pane disabled" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_USERS</hive>
        <key operator="pattern match">^S-[-0-9]+\\Identities\\\{[-0-9A-Z]+\}\\Software\\Microsoft\\Outlook\ Express\\5\.0\\Mail$</key>
        <name>ShowHybridView</name>
      </object>
      <data operation="AND">
        <value>0</value>
      </data>
    </registry_test>
    <registry_test id="wrt-494" comment="the patch kb823353 is installed " check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_CLASSES_ROOT</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\kb823353</key>
        <name>Installed</name>
      </object>
      <data operation="AND">
        <value>1</value>
      </data>
    </registry_test>
    <file_test id="wft-467" comment="the version of inetcomm.dll is less than 6.0.2800.1441" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\inetcomm.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>2800</build>
          <private>1441</private>
        </version>
      </data>
    </file_test>
    <patch_test id="spt-102" comment="Patch 114497-01 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">114497</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">01</version>
      </data>
    </patch_test>
    <patch_test id="spt-101" comment="Patch 109354-19 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">109354</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">19</version>
      </data>
    </patch_test>
    <patch_test id="spt-100" comment="Patch 107702-12 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">107702</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">12</version>
      </data>
    </patch_test>
    <package_test id="sat-47" comment="CDE Desktop Window Manager (SUNWdtwm) installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <pkginst operator="equals">SUNWdtwm</pkginst>
      </object>
    </package_test>
    <file_test id="wft-382" comment="the version of mrxsmb.sys is less than 5.1.2600.1620" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\drivers\mrxsmb.sys</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>1620</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-154" comment="The version of Ntoskrnl.exe is less than 5.1.2600.1605" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\Ntoskrnl.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>1605</private>
        </version>
      </data>
    </file_test>
    <patch_test id="spt-107" comment="Patch 108221-01 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">108221</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">01</version>
      </data>
    </patch_test>
    <package_test id="sat-49" comment="CDE Daemons (SUNWdtdmn) installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <pkginst operator="equals">SUNWdtdmn</pkginst>
      </object>
    </package_test>
    <file_test id="wft-535" comment="the version of vdmdbg.dll is less than 5.1.2600.1560" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\vdmdbg.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>1560</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-551" comment="the patch KB841533 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key datatype="string" operator="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB841533</key>
        <name datatype="string" operator="equals">Installed</name>
      </object>
      <data operation="AND">
        <value datatype="string" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-521" comment="the version of netdde.exe is less than 4.0.1381.33574" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\netdde.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>4</major>
          <minor>0</minor>
          <build>1381</build>
          <private>33574</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-520" comment="the version of nddenb32.dll is less than 4.0.1381.33565" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\nddenb32.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>4</major>
          <minor>0</minor>
          <build>1381</build>
          <private>33565</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-381" comment="the version of mrxsmb.sys is less than 5.2.3790.252" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\drivers\mrxsmb.sys</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>2</minor>
          <build>3790</build>
          <private>252</private>
        </version>
      </data>
    </file_test>
    <process_test id="uct-3" comment="ypbind running" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <command operator="pattern match">^.*ypbind.*</command>
      </object>
    </process_test>
    <patch_test id="spt-9" comment="Patch 110322-01 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">110322</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">01</version>
      </data>
    </patch_test>
    <patch_test id="spt-8" comment="Patch 108750-02 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">108750</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">02</version>
      </data>
    </patch_test>
    <package_test id="sat-13" comment="NIS/NIS+ Utilities installed (SUNWnisu)" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <pkginst operator="equals">SUNWnisu</pkginst>
      </object>
    </package_test>
    <compound_test id="cmp-1135" comment="service pack 1 is installed and a vulnerable version of grpconv.exe exists" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-4"/>
      <subtest negate="false" test_ref="wft-530"/>
    </compound_test>
    <file_test id="wft-529" comment="the version of grpconv.exe is less than 5.1.2600.166" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\grpconv.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>166</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-1134" comment="no service pack is installed and a vulnerable version of grpconv.exe exists" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="true" test_ref="wrt-3"/>
      <subtest negate="false" test_ref="wft-529"/>
    </compound_test>
    <compound_test id="cmp-1136" comment="a vulnerable version of grpconv.exe exists" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-1134"/>
      <subtest negate="false" test_ref="cmp-1135"/>
    </compound_test>
    <patch_test id="spt-310" comment="Patch 121322-01 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">121322</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="equals">01</version>
      </data>
    </patch_test>
    <patch_test id="spt-309" comment="Patch 115678-02 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">115678</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="equals">02</version>
      </data>
    </patch_test>
    <compound_test id="cmp-859" comment="Solaris 9 (x86) meets Sun Alert ID 102113 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-6"/>
      <subtest test_ref="uut-10002"/>
      <subtest negate="true" test_ref="spt-309"/>
      <subtest negate="true" test_ref="spt-310"/>
    </compound_test>
    <patch_test id="spt-308" comment="Patch 108994-51 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">108994</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="equals">51</version>
      </data>
    </patch_test>
    <patch_test id="spt-307" comment="Patch 108994-14 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">108994</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="equals">14</version>
      </data>
    </patch_test>
    <compound_test id="cmp-858" comment="Solaris 8 (x86) meets Sun Alert ID 102113 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-4"/>
      <subtest test_ref="uut-10002"/>
      <subtest test_ref="spt-307"/>
      <subtest negate="true" test_ref="spt-308"/>
    </compound_test>
    <patch_test id="spt-306" comment="Patch 121321-01 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">121321</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="equals">01</version>
      </data>
    </patch_test>
    <patch_test id="spt-305" comment="Patch 115677-02 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">115677</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="equals">02</version>
      </data>
    </patch_test>
    <compound_test id="cmp-857" comment="Solaris 9 (SPARC) meets Sun Alert ID 102113 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-6"/>
      <subtest test_ref="uut-10003"/>
      <subtest negate="true" test_ref="spt-305"/>
      <subtest negate="true" test_ref="spt-306"/>
    </compound_test>
    <patch_test id="spt-304" comment="Patch 108993-51 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">108993</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="equals">51</version>
      </data>
    </patch_test>
    <patch_test id="spt-303" comment="Patch 108993-14 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">108993</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="equals">14</version>
      </data>
    </patch_test>
    <compound_test id="cmp-856" comment="Solaris 8 (SPARC) meets Sun Alert ID 102113 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-4"/>
      <subtest test_ref="uut-10003"/>
      <subtest test_ref="spt-303"/>
      <subtest negate="true" test_ref="spt-304"/>
    </compound_test>
    <file_test id="wft-531" comment="the version of grpconv.exe (syswow64) is less than 5.1.2600.1580" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\syswow64\shell32.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>1580</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-530" comment="the version of grpconv.exe is less than 5.1.2600.1580" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\grpconv.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>1580</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-1133" comment="a vulnerable version of grpconv.exe exists" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wft-530"/>
      <subtest negate="false" test_ref="wft-531"/>
    </compound_test>
    <file_test id="wft-366" comment="the version of rpcrt4.dll is less than 5.1.2600.1254" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\rpcrt4.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>1254</private>
        </version>
      </data>
    </file_test>
    <metabase_test id="wmt-206" comment="Negotiate is enabled" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <key>LM\W3SVC</key>
        <id datatype="int">6032</id>
      </object>
      <data operation="AND"/>
    </metabase_test>
    <file_test id="wft-345" comment="The version of Ipnathlp.dll is less than 5.0.2195.6902" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\Ipnathlp.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>2195</build>
          <private>6902</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-612" comment="the version of winword.exe is less than 11.0.6502.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Winword.exe\Path</component>
          <component type="literal">winword.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>11</major>
          <minor>0</minor>
          <build>6502</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-483" comment="Patch Windows2000-kb841873-x86-enu.exe Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB841873</key>
        <name>Installed</name>
      </object>
      <data operation="AND">
        <value datatype="binary" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-455" comment="the version of mstask.dll is less than 5.1.2600.1555" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mstask.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>1555</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-793" comment="the version of inetcomm.dll is less than 5.50.4963.1700" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\inetcomm.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>50</minor>
          <build>4963</build>
          <private>1700</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-10001" comment="Outlook Express 5.5 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Outlook Express\Version Info</key>
        <name>Current</name>
      </object>
      <data operation="AND">
        <value operator="pattern match">5\.50\..*</value>
      </data>
    </registry_test>
    <file_test id="wft-783" comment="the version of msadco.dll is less than 2.81.1124.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir</component>
          <component type="literal">\Common Files\System\msadc\msadco.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>2</major>
          <minor>81</minor>
          <build>1124</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-10032" comment="MDAC 2.8 (SP1) is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\DataAccess</key>
        <name>FullInstallVer</name>
      </object>
      <data operation="AND">
        <value operator="pattern match">^2\.81.*$</value>
      </data>
    </registry_test>
    <compound_test id="cmp-835" comment="MDAC 2.8,SP1 with msadco.dll version less than 2.81.1124.0" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="wrt-10032"/>
      <subtest test_ref="wft-783"/>
    </compound_test>
    <file_test id="wft-782" comment="the version of msadco.dll is less than 2.80.1062.0000" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir</component>
          <component type="literal">\Common Files\System\msadc\msadco.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>2</major>
          <minor>80</minor>
          <build>1062</build>
          <private>0000</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-834" comment="MDAC 2.8 with msadco.dll version less than 2.80.1062.0000" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="wrt-104"/>
      <subtest test_ref="wft-782"/>
    </compound_test>
    <file_test id="wft-781" comment="the version of msadco.dll is less than 2.71.9053.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir</component>
          <component type="literal">\Common Files\System\msadc\msadco.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>2</major>
          <minor>71</minor>
          <build>9053</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-828" comment="MDAC 2.7,SP1 with msadco.dll version less than 2.71.9053.0" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="wrt-103"/>
      <subtest test_ref="wft-781"/>
    </compound_test>
    <file_test id="wft-780" comment="the version of msadco.dll is less than 2.53.6306.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir</component>
          <component type="literal">\Common Files\System\msadc\msadco.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>2</major>
          <minor>53</minor>
          <build>6306</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-10038" comment="MDAC 2.5 (SP3) is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\DataAccess</key>
        <name>FullInstallVer</name>
      </object>
      <data operation="AND">
        <value operator="pattern match">^2\.53.*$</value>
      </data>
    </registry_test>
    <compound_test id="cmp-827" comment="MDAC 2.5,SP3 with msadco.dll version less than 2.53.6306.0" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="wrt-10038"/>
      <subtest test_ref="wft-780"/>
    </compound_test>
    <compound_test id="cmp-836" comment="MDAC 2.5(SP3), 2.7(SP1), 2.8, or 2.8(SP1) is installed without patches for MS06-014" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="cmp-827"/>
      <subtest test_ref="cmp-828"/>
      <subtest test_ref="cmp-834"/>
      <subtest test_ref="cmp-835"/>
    </compound_test>
    <file_test id="wft-798" comment="the version of inetcomm.dll is less than 6.0.3790.504" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\inetcomm.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>3790</build>
          <private>504</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-796" comment="the version of inetcomm.dll is less than 6.0.3790.2663" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\inetcomm.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>3790</build>
          <private>2663</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-791" comment="the version of shell32.dll is less than 6.0.3790.503" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\shell32.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>3790</build>
          <private>503</private>
        </version>
      </data>
    </file_test>
    <swlist_test id="hst-83" comment="WUFTP-26.INETSVCS-FTP with version less than B.11.11.01.008 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <swlist operator="equals">WUFTP-26.INETSVCS-FTP</swlist>
      </object>
      <data>
        <version operator="pattern match">B\.11\.11\.(00.*|01\.00[0-7])</version>
      </data>
    </swlist_test>
    <patch_test id="hpt-64" comment="Patch PHNE_34544 or subsequent is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <area_patched>PHNE</area_patched>
        <patch_number operator="greater than or equal">34544</patch_number>
      </object>
    </patch_test>
    <compound_test id="cmp-820" comment="INETSVCS-RUN without patch PHNE_34544 or later" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="hst-62"/>
      <subtest negate="true" test_ref="hpt-64"/>
    </compound_test>
    <compound_test id="cmp-824" comment="INETSVCS-RUN without patch PHNE_34544 or later, OR WUFTP-26.INETSVCS-FTP with version less than B.11.11.01.008 is installed" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="cmp-820"/>
      <subtest test_ref="hst-83"/>
    </compound_test>
    <patch_test id="hpt-62" comment="Patch PHCO_34545 or subsequent is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <area_patched>PHCO</area_patched>
        <patch_number operator="greater than or equal">34545</patch_number>
      </object>
    </patch_test>
    <compound_test id="cmp-1113" comment="Windows 2003 Server or Windows XP 64-bit" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-1112"/>
      <subtest negate="false" test_ref="wrt-61"/>
    </compound_test>
    <file_test id="wft-508" comment="the version of win32k.sys is less than 5.2.3790.198" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\win32k.sys</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>2</minor>
          <build>3790</build>
          <private>198</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-537" comment="the patch q841356 is installed (Hotfix key)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key datatype="string" operator="equals">Software\Microsoft\Windows NT\CurrentVersion\Hotfix\KB841356</key>
        <name datatype="string" operator="equals">Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-517" comment="the version of shell32.dll is less than 4.0.1381.3356" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\shell32.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>4</major>
          <minor>0</minor>
          <build>1381</build>
          <private>3356</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-1123" comment="a vulnerable version of shell32.dll exists on NT Terminal Server" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-43"/>
      <subtest negate="false" test_ref="wft-517"/>
    </compound_test>
    <file_test id="wft-471" comment="the version of shell32.dll is less than 4.0.1381.7267" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\shell32.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>4</major>
          <minor>0</minor>
          <build>1381</build>
          <private>7267</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-1119" comment="Active Desktop is not installed and shell32.dll is less than 4.0.1381.7267" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="true" test_ref="wrt-490"/>
      <subtest negate="false" test_ref="wft-471"/>
    </compound_test>
    <file_test id="wft-516" comment="the version of shell32.dll is less than 4.72.3843.3100" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\shell32.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>4</major>
          <minor>72</minor>
          <build>3843</build>
          <private>3100</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-490" comment="Active Desktop  is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key datatype="string" operator="equals">SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4395}</key>
        <name datatype="string" operator="equals">IsInstalled</name>
      </object>
      <data operation="AND">
        <value datatype="string" operator="equals">1</value>
      </data>
    </registry_test>
    <compound_test id="cmp-1120" comment="Active Desktop is installed and shell32.dll is less than 4.72.3843.3100" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-490"/>
      <subtest negate="false" test_ref="wft-516"/>
    </compound_test>
    <compound_test id="cmp-1122" comment="a vulnerable version of shell32.dll exists" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-1120"/>
      <subtest negate="false" test_ref="cmp-1119"/>
    </compound_test>
    <compound_test id="cmp-1121" comment="a vulnerable version of shell32.dll exists on NT Server" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-50"/>
      <subtest negate="false" test_ref="cmp-1122"/>
    </compound_test>
    <compound_test id="cmp-1124" comment="a vulnerable version of shell32.dll exists" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-1121"/>
      <subtest negate="false" test_ref="cmp-1123"/>
    </compound_test>
    <file_test id="wft-799" comment="the version of fpadmdll.dll is less than 10.0.6790.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\SharedFilesDir</component>
          <component type="literal">\web server extensions\50\isapi\_vti_adm\fpadmdll.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>10</major>
          <minor>0</minor>
          <build>6790</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-792" comment="the version of shell32.dll is less than 6.0.3790.2662" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\shell32.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>3790</build>
          <private>2662</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-787" comment="the version of msadco.dll is less than 2.82.2644.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir</component>
          <component type="literal">\Common Files\System\msadc\msadco.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>2</major>
          <minor>82</minor>
          <build>2644</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-841" comment="S03,SP1 is installed" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="wrt-61"/>
      <subtest test_ref="wrt-4"/>
    </compound_test>
    <compound_test id="cmp-842" comment="Windows XP 64-bit or S03,SP1 is installed" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="cmp-646"/>
      <subtest test_ref="cmp-841"/>
    </compound_test>
    <file_test id="wft-406" comment="the version of mshtml.dll is less than 5.0.3528.700" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mshtml.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>3528</build>
          <private>700</private>
        </version>
      </data>
    </file_test>
    <patch_test id="spt-91" comment="Patch 113329-05 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">113329</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">05</version>
      </data>
    </patch_test>
    <patch_test id="spt-90" comment="Patch 109320-09 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">109320</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">09</version>
      </data>
    </patch_test>
    <patch_test id="spt-89" comment="Patch 107115-14 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">107115</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">14</version>
      </data>
    </patch_test>
    <package_test id="sat-43" comment="SunSoft Print - Client - Usr (SUNWpcu) installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <pkginst operator="equals">SUNWpcu</pkginst>
      </object>
    </package_test>
    <file_test id="wft-714" comment="the version of Gdiplus.dll for Visual Studio .NET is less than 5.1.3102.1355" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="environment_variable">windir</component>
          <component type="literal">WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.2180_x-ww_522f9f82\Gdiplus.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>3102</build>
          <private>1355</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-519" comment="Microsoft Visual Studio .NET 2003 Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key datatype="string" operator="equals">Software\Microsoft\VisualStudio\7.1</key>
        <name operator="pattern match">.*</name>
      </object>
    </registry_test>
    <file_test id="wft-344" comment="The version of Ntoskrnl.exe is less than 4.0.1381.33563" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\System32\Ntoskrnl.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>4</major>
          <minor>0</minor>
          <build>1381</build>
          <private>33563</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-944" comment="This is an NT Terminal Server and the version of Ntoskrnl.exe is less than 4.0.1381.33563" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wft-344"/>
      <subtest negate="false" test_ref="wrt-43"/>
    </compound_test>
    <file_test id="wft-343" comment="The version of Ntoskrnl.exe is less than 4.0.1381.7265" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\System32\Ntoskrnl.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>4</major>
          <minor>0</minor>
          <build>1381</build>
          <private>7265</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-1084" comment="Version Ntoskrnl.exe is less than 4.0.1381.7265 and this is an NT Workstation" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wft-343"/>
      <subtest negate="false" test_ref="wrt-40"/>
    </compound_test>
    <compound_test id="cmp-1085" comment="Version check of Ntoskrnl for NT Terminal Server or NT Workstation" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-1084"/>
      <subtest negate="false" test_ref="cmp-944"/>
    </compound_test>
    <patch_test id="spt-242" comment="Patch 117367-01 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">117367</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">01</version>
      </data>
    </patch_test>
    <package_test id="sat-1" comment="Sun Enterprise Storage Manager installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <pkginst>SUNWstm</pkginst>
      </object>
    </package_test>
    <shadow_test id="hwt-4" comment="sendmail 8.13.x before 8.13.6 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <application operator="equals">/usr/sbin/sendmail</application>
      </object>
      <data>
        <output operator="pattern match">\s*version\.c\s+8\.13\.[0-5]\D.*</output>
      </data>
    </shadow_test>
    <shadow_test id="hwt-3" comment="sendmail 8.12.x before 8.12.11 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <application operator="equals">/usr/sbin/sendmail</application>
      </object>
      <data>
        <output operator="pattern match">\s*version\.c\s+8\.12\.([0-9]|10)\D.*</output>
      </data>
    </shadow_test>
    <shadow_test id="hwt-2" comment="sendmail before 8.12.x is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <application operator="equals">/usr/sbin/sendmail</application>
      </object>
      <data>
        <output operator="pattern match">\s*version\.c\s+([0-7]|8\.([0-9]|1[01]))\D.*</output>
      </data>
    </shadow_test>
    <file_test id="wft-383" comment="the version of wdhtmled.ocx is less than 6.1.0.9232" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir</component>
          <component type="literal">\microsoft shared\triedit\wdhtmled.ocx</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>1</minor>
          <build>0</build>
          <private>9232</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-1102" comment="Windows XP 64-bit with SP1 (or earlier) installed" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-66"/>
    </compound_test>
    <patch_test id="spt-285" comment="Patch 118966-17 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">118966</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">17</version>
      </data>
    </patch_test>
    <patch_test id="spt-284" comment="Patch 118966-14 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">118966</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">14</version>
      </data>
    </patch_test>
    <compound_test id="cmp-791" comment="Patch 118966-14 through 118966-16 is installed." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="spt-284"/>
      <subtest negate="true" test_ref="spt-285"/>
    </compound_test>
    <registry_test id="wrt-647" comment="Patch WinXP-KB914798 is installed." check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key datatype="string" operator="equals">Software\Microsoft\Updates\Windows XP\SP2\KB914798</key>
        <name datatype="string" operator="pattern match">.*</name>
      </object>
    </registry_test>
    <registry_test id="wrt-439" comment="the patch kb890923  is installed (XP SP2 Hotfix key)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">SOFTWARE\Microsoft\Updates\Windows XP\SP3\KB890923 \Filelist</key>
        <name operator="pattern match">^.*$</name>
      </object>
    </registry_test>
    <file_test id="wft-595" comment="the version of mshtml.dll is less than 6.0.2900.2627" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mshtml.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>2900</build>
          <private>2627</private>
        </version>
      </data>
    </file_test>
    <patch_test id="hpt-61" comment="Patch PHCO_32926 or subsequent is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <area_patched>PHCO</area_patched>
        <patch_number operator="greater than or equal">32926</patch_number>
      </object>
    </patch_test>
    <patch_test id="hpt-60" comment="Patch PHCO_32149 or subsequent is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <area_patched>PHCO</area_patched>
        <patch_number operator="greater than or equal">32149</patch_number>
      </object>
    </patch_test>
    <swlist_test id="hst-82" comment="OS-Core.UX2-CORE is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <swlist operator="equals">OS-Core.UX2-CORE</swlist>
      </object>
    </swlist_test>
    <rpminfo_test id="rrt-13" comment="sendmail 8.13.x before 8.13.6 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name operator="equals">sendmail</name>
      </object>
      <data>
        <version operator="pattern match">8\.13\.[0-5]</version>
      </data>
    </rpminfo_test>
    <rpminfo_test id="rrt-12" comment="sendmail 8.12.x before 8.12.11 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name operator="equals">sendmail</name>
      </object>
      <data>
        <version operator="pattern match">8\.12\.([0-9]|10)</version>
      </data>
    </rpminfo_test>
    <rpminfo_test id="rrt-11" comment="sendmail before 8.12.x is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name operator="equals">sendmail</name>
      </object>
      <data>
        <version operator="pattern match">([0-7]|8\.([0-9]|1[01]))</version>
      </data>
    </rpminfo_test>
    <file_test id="wft-602" comment="the version of Tcpip.sys is less than 5.1.2600.2685" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\tcpip.sys</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>2685</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-297" comment="Service Pack 2 is installed and tcpip.sys is less than 5.1.2600.2685" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-250"/>
      <subtest negate="false" test_ref="wft-602"/>
    </compound_test>
    <file_test id="wft-601" comment="the version of Tcpip.sys is less than 5.1.2600.1693" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\tcpip.sys</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>1693</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-293" comment="Service Pack 1 is installed and tcpip.sys is less than 5.1.2600.1693" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-4"/>
      <subtest negate="false" test_ref="wft-601"/>
    </compound_test>
    <compound_test id="cmp-298" comment="A vulnerable version of tcpip.sys is installed." operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-293"/>
      <subtest negate="false" test_ref="cmp-297"/>
    </compound_test>
    <patch_test id="spt-80" comment="Patch 112233-12 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">112233</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">12</version>
      </data>
    </patch_test>
    <patch_test id="spt-81" comment="Patch 108528-27 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">108528</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">27</version>
      </data>
    </patch_test>
    <file_test id="wft-794" comment="the version of inetcomm.dll is less than 6.0.2800.1807" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\inetcomm.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>2800</build>
          <private>1807</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-837" comment="Windows XP,SP1 32-bit is installed" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="wrt-2"/>
      <subtest test_ref="wrt-4"/>
      <subtest negate="true" test_ref="wrt-70"/>
    </compound_test>
    <compound_test id="cmp-838" comment="Windows XP,SP1 32-bit or Win2K,SP4 is installed" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="cmp-837"/>
      <subtest test_ref="cmp-212"/>
    </compound_test>
    <file_test id="wft-789" comment="the version of shell32.dll is less than 6.0.2800.1816" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\shell32.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>2800</build>
          <private>1816</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-648" comment="Patch S03-KB914798 is installed." check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key datatype="string" operator="equals">Software\Microsoft\Updates\Windows Server 2003\SP1\KB914798</key>
        <name datatype="string" operator="pattern match">.*</name>
      </object>
    </registry_test>
    <file_test id="wft-765" comment="the version of Imekr61.ime is less than 6.1.2600.3 (WinXP)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\Imekr61.ime</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>1</minor>
          <build>2600</build>
          <private>3</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-756" comment="the version of Tcpip.sys is less than 5.1.2600.1792 (XP,SP1)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\drivers\tcpip.sys</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>1792</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-745" comment="the version of Wmp.dll is less than 9.0.0.3344" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\Wmp.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>9</major>
          <minor>0</minor>
          <build>0</build>
          <private>3344</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-10031" comment="Windows Media Player 9 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\MediaPlayer\9.0\Registration</key>
        <name>UDBVersion</name>
      </object>
      <data operation="AND">
        <value operator="pattern match">9.0.*</value>
      </data>
    </registry_test>
    <patch_test id="hpt-59" comment="Patch PHCO_33215 or subsequent is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <area_patched>PHCO</area_patched>
        <patch_number operator="greater than or equal">33215</patch_number>
      </object>
    </patch_test>
    <patch_test id="hpt-58" comment="Patch PHCO_33214 or subsequent is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <area_patched>PHCO</area_patched>
        <patch_number operator="greater than or equal">33214</patch_number>
      </object>
    </patch_test>
    <patch_test id="spt-67" comment="Patch 112668-02 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">112668</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">02</version>
      </data>
    </patch_test>
    <package_test id="sat-36" comment="GNU Zip (gzip, SUNWgzip) installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <pkginst operator="equals">SUNWgzip</pkginst>
      </object>
    </package_test>
    <file_test id="wft-767" comment="the version of Imekr61.ime is less than 6.1.3790.1 (S03-Gold)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\Imekr61.ime</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>1</minor>
          <build>3790</build>
          <private>1</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-742" comment="the version of mshtml.dll is less than 5.0.3837.1200" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mshtml.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>3837</build>
          <private>1200</private>
        </version>
      </data>
    </file_test>
    <patch_test id="hpt-35" comment="Patch PHNE_29462 or later is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <area_patched>PHNE</area_patched>
        <patch_number operator="greater than or equal">29462</patch_number>
      </object>
    </patch_test>
    <swlist_test id="hst-53" comment="InternetSrvcs.INETSVCS2-RUN (B.11.22) is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <swlist operator="equals">InternetSrvcs.INETSVCS2-RUN</swlist>
      </object>
      <data>
        <version operator="equals">B.11.22</version>
      </data>
    </swlist_test>
    <patch_test id="spt-275" comment="Patch 118813-03 or later installed (x86-10)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">118813</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">03</version>
      </data>
    </patch_test>
    <compound_test id="cmp-768" comment="Solaris 10 (x86) meets Sun Alert ID 102161 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-10001"/>
      <subtest test_ref="uut-10002"/>
      <subtest negate="true" test_ref="spt-275"/>
    </compound_test>
    <patch_test id="spt-274" comment="Patch 121995-01 or later installed (x86-9)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">121995</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">01</version>
      </data>
    </patch_test>
    <compound_test id="cmp-767" comment="Solaris 9 (x86) meets Sun Alert ID 102161 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-6"/>
      <subtest test_ref="uut-10002"/>
      <subtest negate="true" test_ref="spt-274"/>
    </compound_test>
    <patch_test id="spt-273" comment="Patch 109765-06 or later installed (x86-8)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">109765</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">06</version>
      </data>
    </patch_test>
    <compound_test id="cmp-766" comment="Solaris 8 (x86) meets Sun Alert ID 102161 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-4"/>
      <subtest test_ref="uut-10002"/>
      <subtest negate="true" test_ref="spt-273"/>
    </compound_test>
    <patch_test id="spt-200" comment="Patch 119596-03 or later installed (SPARC-10)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">119596</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">03</version>
      </data>
    </patch_test>
    <compound_test id="cmp-765" comment="Solaris 10 (SPARC) meets Sun Alert ID 102161 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-10001"/>
      <subtest test_ref="uut-10003"/>
      <subtest negate="true" test_ref="spt-200"/>
    </compound_test>
    <patch_test id="spt-199" comment="Patch 116047-03 or later installed (SPARC-9)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">116047</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">03</version>
      </data>
    </patch_test>
    <compound_test id="cmp-764" comment="Solaris 9 (SPARC) meets Sun Alert ID 102161 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-6"/>
      <subtest test_ref="uut-10003"/>
      <subtest negate="true" test_ref="spt-199"/>
    </compound_test>
    <patch_test id="spt-198" comment="Patch 109764-06 or later installed (SPARC-8)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">109764</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">06</version>
      </data>
    </patch_test>
    <compound_test id="cmp-763" comment="Solaris 8 (SPARC) meets Sun Alert ID 102161 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-4"/>
      <subtest test_ref="uut-10003"/>
      <subtest negate="true" test_ref="spt-198"/>
    </compound_test>
    <patch_test id="spt-283" comment="Patch 118844-29 or later installed (x86-10)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">118844</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">29</version>
      </data>
    </patch_test>
    <compound_test id="cmp-776" comment="Solaris 10 (x86) meets Sun Alert ID 102159 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-10001"/>
      <subtest test_ref="uut-10002"/>
      <subtest negate="true" test_ref="spt-283"/>
    </compound_test>
    <patch_test id="spt-282" comment="Patch 118559-22 or later installed (x86-9)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">118559</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">22</version>
      </data>
    </patch_test>
    <compound_test id="cmp-775" comment="Solaris 9 (x86) meets Sun Alert ID 102159 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-6"/>
      <subtest test_ref="uut-10002"/>
      <subtest negate="true" test_ref="spt-282"/>
    </compound_test>
    <patch_test id="spt-281" comment="Patch 117351-33 or later installed (x86-8)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">117351</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">33</version>
      </data>
    </patch_test>
    <compound_test id="cmp-774" comment="Solaris 8 (x86) meets Sun Alert ID 102159 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-4"/>
      <subtest test_ref="uut-10002"/>
      <subtest negate="true" test_ref="spt-281"/>
    </compound_test>
    <patch_test id="spt-280" comment="Patch 118822-29 or later installed (SPARC-10)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">118822</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">29</version>
      </data>
    </patch_test>
    <compound_test id="cmp-773" comment="Solaris 10 (SPARC) meets Sun Alert ID 102159 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-10001"/>
      <subtest test_ref="uut-10003"/>
      <subtest negate="true" test_ref="spt-280"/>
    </compound_test>
    <patch_test id="spt-279" comment="Patch 118558-22 or later installed (SPARC-9)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">118558</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">22</version>
      </data>
    </patch_test>
    <compound_test id="cmp-772" comment="Solaris 9 (SPARC) meets Sun Alert ID 102159 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-6"/>
      <subtest test_ref="uut-10003"/>
      <subtest negate="true" test_ref="spt-279"/>
    </compound_test>
    <patch_test id="spt-278" comment="Patch 117350-33 or later installed (SPARC-8)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">117350</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">33</version>
      </data>
    </patch_test>
    <compound_test id="cmp-771" comment="Solaris 8 (SPARC) meets Sun Alert ID 102159 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-4"/>
      <subtest test_ref="uut-10003"/>
      <subtest negate="true" test_ref="spt-278"/>
    </compound_test>
    <patch_test id="spt-292" comment="Patch 121092-01 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">121092</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">01</version>
      </data>
    </patch_test>
    <textfilecontent_test id="tft-18" comment="JDS release 2 is installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/share/gnome-about/gnome-version.xml</component>
        </path>
        <line operator="pattern match">\s*&lt;distributor-version>Sun Java Desktop System, Release 2&lt;/distributor-version>\s*</line>
      </object>
    </textfilecontent_test>
    <compound_test id="cmp-798" comment="Solaris 9 (x86) with JDS release 2 meets Sun Alert ID 101776 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-6"/>
      <subtest test_ref="uut-10002"/>
      <subtest test_ref="tft-18"/>
      <subtest negate="true" test_ref="spt-292"/>
    </compound_test>
    <patch_test id="spt-291" comment="Patch 115739-04 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">115739</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">04</version>
      </data>
    </patch_test>
    <compound_test id="cmp-797" comment="GNOME 2.0.2 Solaris 9 (x86) meets Sun Alert ID 101776 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-6"/>
      <subtest test_ref="uut-10002"/>
      <subtest test_ref="tft-17"/>
      <subtest negate="true" test_ref="spt-291"/>
    </compound_test>
    <patch_test id="spt-290" comment="Patch 114687-03 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">114687</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">03</version>
      </data>
    </patch_test>
    <compound_test id="cmp-796" comment="GNOME 2.0 Solaris 9 (x86) meets Sun Alert ID 101776 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-6"/>
      <subtest test_ref="uut-10002"/>
      <subtest test_ref="tft-16"/>
      <subtest negate="true" test_ref="spt-290"/>
    </compound_test>
    <patch_test id="spt-288" comment="Patch 115738-04 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">115738</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">04</version>
      </data>
    </patch_test>
    <textfilecontent_test id="tft-17" comment="Gnome 2.0.2 is installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/share/gnome/gnome-about/gnome-version.xml</component>
        </path>
        <line operator="pattern match">\s*&lt;description>2\.0\.2.*&lt;/description>\s*</line>
      </object>
    </textfilecontent_test>
    <compound_test id="cmp-795" comment="GNOME 2.0.2 Solaris 9 (SPARC) meets Sun Alert ID 101776 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-6"/>
      <subtest test_ref="uut-10003"/>
      <subtest test_ref="tft-17"/>
      <subtest negate="true" test_ref="spt-288"/>
    </compound_test>
    <patch_test id="spt-287" comment="Patch 114686-03 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">114686</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">03</version>
      </data>
    </patch_test>
    <compound_test id="cmp-794" comment="GNOME 2.0 Solaris 9 (SPARC) meets Sun Alert ID 101776 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-6"/>
      <subtest test_ref="uut-10003"/>
      <subtest test_ref="tft-16"/>
      <subtest negate="true" test_ref="spt-287"/>
    </compound_test>
    <patch_test id="spt-289" comment="Patch 114645-03 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">114645</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">03</version>
      </data>
    </patch_test>
    <compound_test id="cmp-793" comment="GNOME 2.0 Solaris 8 (x86) meets Sun Alert ID 101776 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-4"/>
      <subtest test_ref="uut-10002"/>
      <subtest test_ref="tft-16"/>
      <subtest negate="true" test_ref="spt-289"/>
    </compound_test>
    <patch_test id="spt-286" comment="Patch 114644-03 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">114644</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">03</version>
      </data>
    </patch_test>
    <textfilecontent_test id="tft-16" comment="Gnome 2.0.0 is installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/share/gnome/gnome-about/gnome-version.xml</component>
        </path>
        <line operator="pattern match">\s*&lt;description>2\.0\.0.*&lt;/description>\s*</line>
      </object>
    </textfilecontent_test>
    <compound_test id="cmp-792" comment="GNOME 2.0 Solaris 8 (SPARC) meets Sun Alert ID 101776 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-4"/>
      <subtest test_ref="uut-10003"/>
      <subtest test_ref="tft-16"/>
      <subtest negate="true" test_ref="spt-286"/>
    </compound_test>
    <file_test id="wft-721" comment="the version of Gdi32.dll is less than 5.2.3790.462" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\Gdi32.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>2</minor>
          <build>3790</build>
          <private>462</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-795" comment="the version of inetcomm.dll is less than 6.0.2900.2869" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\inetcomm.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>2900</build>
          <private>2869</private>
        </version>
      </data>
    </file_test>
    <patch_test id="spt-164" comment="Patch 118822-24 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">118822</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">24</version>
      </data>
    </patch_test>
    <compound_test id="cmp-715" comment="Solaris 10 (sparc) meets Sun Alert ID 102108 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-10001"/>
      <subtest test_ref="uut-10003"/>
      <subtest negate="true" test_ref="spt-164"/>
    </compound_test>
    <patch_test id="hpt-22" comment="Patch PHNE_33159 or later is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <area_patched>PHNE</area_patched>
        <patch_number operator="greater than or equal">33159</patch_number>
      </object>
    </patch_test>
    <registry_test id="wrt-90" comment="the patch KB885250 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB885250</key>
        <name operator="equals">Installed</name>
      </object>
      <data operation="AND">
        <value operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-380" comment="the version of mrxsmb.sys is less than 5.1.2600.2598" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\drivers\mrxsmb.sys</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>2598</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-67" comment="If the Hyperterminal client is registered as the default telnet client" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_CLASSES_ROOT</hive>
        <key operator="equals">telnet\shell\open</key>
        <name operator="equals">command</name>
      </object>
      <data operation="AND">
        <value operator="equals">C:\Program Files\Windows NT\hypertrm.exe /t %1</value>
      </data>
    </registry_test>
    <registry_test id="wrt-39" comment="If key present hyperterminal will automatically open session files" check="none exist" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_CLASSES_ROOT</hive>
        <key operator="equals">htfile</key>
        <name operator="pattern match">^.*$</name>
      </object>
    </registry_test>
    <registry_test id="wrt-45" comment="the patch WindowsXP-KB87339-x86-ENU.exe is installed " check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_CLASSES_ROOT</hive>
        <key operator="equals">SOFTWARE\Microsoft\Updates\Windows XP\SP3\KB873339\Filelist</key>
        <name operator="pattern match">^.*$</name>
      </object>
    </registry_test>
    <file_test id="wft-175" comment="the version of hypertrm.dll is less than 5.1.2600.1609" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\hypertrm.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>1609</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-761" comment="the version of webclnt.dll is less than 5.1.2600.2821 (XP,SP2)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\webclnt.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>2821</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-550" comment="Windows ME Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key datatype="string" operator="equals">SOFTWARE\Microsoft\Windows\CurrentVersion</key>
        <name datatype="string" operator="equals">Version</name>
      </object>
      <data operation="AND">
        <value datatype="string" operator="equals">Windows ME</value>
      </data>
    </registry_test>
    <file_test id="wft-746" comment="the version of Wmp.dll is less than 10.0.0.3990" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\Wmp.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>10</major>
          <minor>0</minor>
          <build>0</build>
          <private>3990</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-646" comment="Windows Media Player 10 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\MediaPlayer\10.0\Registration</key>
        <name>UDBVersion</name>
      </object>
      <data operation="AND">
        <value operator="pattern match">10\.0\.*</value>
      </data>
    </registry_test>
    <file_test id="wft-766" comment="the version of Imekr61.ime is less than 6.2.2551.0 (64-bit)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\Imekr61.ime</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>2</minor>
          <build>2551</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <patch_test id="hpt-37" comment="Patch PHCO_32280 or later is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <area_patched>PHCO</area_patched>
        <patch_number operator="greater than or equal">32280</patch_number>
      </object>
    </patch_test>
    <file_test id="wft-709" comment="The version of Ntkrnlpa.exe is less than 5.0.2195.7071" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\System32\Ntkrnlpa.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>2195</build>
          <private>7071</private>
        </version>
      </data>
    </file_test>
    <swlist_test id="hst-56" comment="SysMgmtServer.MX-PORTAL (C.04.01.00.00) is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <swlist operator="equals">SysMgmtServer.MX-PORTAL</swlist>
      </object>
      <data>
        <version operator="equals">C.04.01.00.00</version>
      </data>
    </swlist_test>
    <swlist_test id="hst-55" comment="SysMgmtServer.MX-PORTAL (C.04.00.00.00) is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <swlist operator="equals">SysMgmtServer.MX-PORTAL</swlist>
      </object>
      <data>
        <version operator="equals">C.04.00.00.00</version>
      </data>
    </swlist_test>
    <file_test id="wft-160" comment="the version of lsasrv.dll is less than 5.2.3790.220" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\lsasrv.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>2</minor>
          <build>3790</build>
          <private>220</private>
        </version>
      </data>
    </file_test>
    <textfilecontent_test id="tft-15" comment="Target is configured to reference pam_krb5" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/etc/pam.conf</component>
        </path>
        <line operator="pattern match">^other.*krb5.*</line>
      </object>
    </textfilecontent_test>
    <patch_test id="spt-197" comment="Patch 120330-02 or later installed (SPARC-10)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">120330</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">02</version>
      </data>
    </patch_test>
    <compound_test id="cmp-759" comment="Solaris 10 (x86) meets Sun Alert ID 102186 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-10001"/>
      <subtest test_ref="uut-10002"/>
      <subtest negate="true" test_ref="spt-197"/>
    </compound_test>
    <patch_test id="spt-196" comment="Patch 120329-02 or later installed (SPARC-10)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">120329</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">02</version>
      </data>
    </patch_test>
    <compound_test id="cmp-758" comment="Solaris 10 (SPARC) meets Sun Alert ID 102186 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-10001"/>
      <subtest test_ref="uut-10003"/>
      <subtest negate="true" test_ref="spt-196"/>
    </compound_test>
    <file_test id="wft-743" comment="the version of Wmpui.dll is less than 7.10.0.3077" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\Wmpui.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>7</major>
          <minor>10</minor>
          <build>0</build>
          <private>3077</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-10030" comment="Windows Media Player 7.1 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\MediaPlayer\7.1\Registration</key>
        <name>UDBVersion</name>
      </object>
      <data operation="AND">
        <value operator="pattern match">7.1.*</value>
      </data>
    </registry_test>
    <patch_test id="hpt-36" comment="Patch PHCO_29249 or later is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <area_patched>PHCO</area_patched>
        <patch_number operator="greater than or equal">29249</patch_number>
      </object>
    </patch_test>
    <patch_test id="hpt-14" comment="Patch PHNE_33792 or later is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <area_patched>PHNE</area_patched>
        <patch_number operator="greater than or equal">33792</patch_number>
      </object>
    </patch_test>
    <swlist_test id="hst-27" comment="InternetSrvcs.INET-ENG-A-MAN is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <swlist operator="equals">InternetSrvcs.INET-ENG-A-MAN</swlist>
      </object>
      <data>
        <version operator="equals">B.11.23</version>
      </data>
    </swlist_test>
    <compound_test id="cmp-683" comment="InternetSrvcs.INETSVCS2-RUN or InternetSrvcs.INET-ENG-A-MAN (B.11.23) is installed" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="hst-26"/>
      <subtest test_ref="hst-27"/>
    </compound_test>
    <patch_test id="hpt-10" comment="Patch PHCO_33967 or later is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <area_patched>PHCO</area_patched>
        <patch_number operator="greater than or equal">33967</patch_number>
      </object>
    </patch_test>
    <swlist_test id="hst-23" comment="OS-Core.UX-CORE is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <swlist operator="equals">OS-Core.UX-CORE</swlist>
      </object>
      <data>
        <version operator="equals">B.11.11</version>
      </data>
    </swlist_test>
    <swlist_test id="hst-22" comment="OS-Core.CORE-ENG-A-MAN is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <swlist operator="equals">OS-Core.CORE-ENG-A-MAN</swlist>
      </object>
      <data>
        <version operator="equals">B.11.11</version>
      </data>
    </swlist_test>
    <compound_test id="cmp-678" comment="OS-Core.CORE-ENG-A-MAN or OS-Core.UX-CORE (B.11.11) is installed" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="hst-22"/>
      <subtest test_ref="hst-23"/>
    </compound_test>
    <registry_test id="wrt-167" comment="The patch KB885492 is installed on Windows Server 2003" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">SOFTWARE\Microsoft\Updates\Windows Media Player 9\KB885492</key>
        <name operator="equals">PackageVersion</name>
      </object>
      <data operation="AND">
        <value operator="equals">1.1</value>
      </data>
    </registry_test>
    <file_test id="wft-719" comment="the version of Gdi32.dll is less than 5.1.2600.1789" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\Gdi32.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>1789</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-561" comment="the patch kb834707 is installed (Installed Components key)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Active Setup\Installed Components\{ 3e7bb08a-a7a3-4692-8eac-ac5e7895755b}</key>
        <name>IsInstalled</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-564" comment="the version of mshtml.dll is less than 6.0.2800.1476   " check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mshtml.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>2800</build>
          <private>1476</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-148" comment="The version of Ntoskrnl.exe is less than 5.0.2195.6992" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\System32\Ntoskrnl.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>2195</build>
          <private>6992</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-755" comment="the version of Npdsplay.dll is less than 3.0.2.629" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir</component>
          <component type="literal">\Windows Media Player\Npdsplay.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>3</major>
          <minor>0</minor>
          <build>2</build>
          <private>629</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-768" comment="the version of PowerPnt.exe is less than 9.0.0.8936" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\PowerPnt.exe\Path</component>
          <component type="literal">PowerPnt.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>9</major>
          <minor>0</minor>
          <build>0</build>
          <private>8936</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-644" comment="PowerPoint 2000 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Office\9.0\PowerPoint\InstallRoot</key>
        <name operator="pattern match">.*</name>
      </object>
    </registry_test>
    <file_test id="wft-770" comment="the version of Winword.exe is less than 9.0.0.8938" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Winword.exe\Path</component>
          <component type="literal">winword.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>9</major>
          <minor>0</minor>
          <build>0</build>
          <private>8938</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-10014" comment="Microsoft Office 2000 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key operator="pattern match">Software\Microsoft\Office\9.0\Registration</key>
        <name>ProductID</name>
      </object>
      <data>
        <value>.*-OEM-.*</value>
      </data>
    </registry_test>
    <file_test id="wft-688" comment="shell32.dll is less than 6.0.3790.2534" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\shell32.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>3790</build>
          <private>2534</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-38" comment="the patch KB870763 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB870763</key>
        <name operator="equals">Installed</name>
      </object>
      <data operation="AND">
        <value datatype="binary" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-350" comment="the version of wins.exe is less than 5.2.3790.239" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\wins.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>2</minor>
          <build>3790</build>
          <private>239</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-763" comment="the version of webclnt.dll is less than 5.2.3790.453 (S03-Gold)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\webclnt.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>2</minor>
          <build>3790</build>
          <private>453</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-672" comment="nwwks.dll is less than 5.2.3790.386" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\nwwks.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>2</minor>
          <build>3790</build>
          <private>386</private>
        </version>
      </data>
    </file_test>
    <swlist_test id="hst-34" comment="Secure_Shell.SECURE_SHELL with version less than A.04.20.004 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <swlist operator="equals">Secure_Shell.SECURE_SHELL</swlist>
      </object>
      <data>
        <version operator="pattern match">A(\.0[0-3]\..*|\.04\.[0-1].*|\.04\.20\.00[0-3])</version>
      </data>
    </swlist_test>
    <compound_test id="cmp-706" comment="700 Series or 800 Series OS Release 11.00 or 11.11" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="cmp-618"/>
      <subtest test_ref="cmp-619"/>
    </compound_test>
    <file_test id="wft-664" comment="machine has followed the QFE update path and mshtml.dll is less than 6.0.2800.1523" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mshtml.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>2800</build>
          <private>1523</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-663" comment="machine has followed the GDR update path and mshtml.dll is less than 6.0.2800.1522" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mshtml.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>2800</build>
          <private>1522</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-610" comment="a vulnerable version of mshtml.dll exists GDR/QFE" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wft-663"/>
      <subtest negate="false" test_ref="wft-664"/>
    </compound_test>
    <file_test id="wft-687" comment="shell32.dll is less than 6.0.3790.413" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\shell32.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>3790</build>
          <private>413</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-669" comment="nwwks.dll is less than 5.0.2195.7065" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\nwwks.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>2195</build>
          <private>7065</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-665" comment="mshtml.dll is less than 5.0.3833.200" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mshtml.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>3833</build>
          <private>200</private>
        </version>
      </data>
    </file_test>
    <patch_test id="spt-158" comment="Patch 115880-02 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">115880</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">02</version>
      </data>
    </patch_test>
    <compound_test id="cmp-612" comment="Solaris 9 (x86) meets Sun Alert ID 101933 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-6"/>
      <subtest test_ref="uut-10002"/>
      <subtest negate="true" test_ref="spt-158"/>
    </compound_test>
    <patch_test id="spt-156" comment="Patch 113322-03 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">113322</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">03</version>
      </data>
    </patch_test>
    <compound_test id="cmp-705" comment="Solaris 9 (SPARC) meets Sun Alert ID 101933 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-6"/>
      <subtest test_ref="uut-10003"/>
      <subtest negate="true" test_ref="spt-156"/>
    </compound_test>
    <patch_test id="spt-157" comment="Patch 111571-04 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">111571</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">04</version>
      </data>
    </patch_test>
    <compound_test id="cmp-704" comment="Solaris 8 (x86) meets Sun Alert ID 101933 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-4"/>
      <subtest test_ref="uut-10002"/>
      <subtest negate="true" test_ref="spt-157"/>
    </compound_test>
    <patch_test id="spt-155" comment="Patch 111570-04 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">111570</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">04</version>
      </data>
    </patch_test>
    <compound_test id="cmp-703" comment="Solaris 8 (SPARC) meets Sun Alert ID 101933 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-4"/>
      <subtest test_ref="uut-10003"/>
      <subtest negate="true" test_ref="spt-155"/>
    </compound_test>
    <compound_test id="cmp-760" comment="IPSec.IPSEC2-KRN version is under A.2.00.01 or TOUR version is under 3.0" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="hst-59"/>
      <subtest test_ref="hst-45"/>
    </compound_test>
    <file_test id="wft-694" comment="netman.dll is less than 5.1.2600.2743" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\netman.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>2743</private>
        </version>
      </data>
    </file_test>
    <patch_test id="spt-95" comment="Patch 110943-02 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">110943</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">02</version>
      </data>
    </patch_test>
    <file_test id="wft-774" comment="Xlview.exe is installed with a version less than 11.0.8012.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90840409-6000-11D3-8CFE-0150048383C9}\InstallLocation</component>
          <component type="literal">OFFICE11\xlview.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>11</major>
          <minor>0</minor>
          <build>8012</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-611" comment="An unsupported version of Windows XP is installed" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-2"/>
      <subtest negate="true" test_ref="wrt-10026"/>
    </compound_test>
    <file_test id="wft-676" comment="umpnpmgr.dll is less than 5.1.2600.2744" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\umpnpmgr.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>2744</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-685" comment="shell32.dll is less than 6.0.2900.2763" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\shell32.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>2900</build>
          <private>2763</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-679" comment="cdosys.dll is less than 6.2.4.0" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\cdosys.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>2</minor>
          <build>4</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-342" comment="The version of Ntoskrnl.exe is less than 5.0.2195.6902" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\System32\Ntoskrnl.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>2195</build>
          <private>6902</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-784" comment="the version of msadco.dll is less than 2.71.9053.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir</component>
          <component type="literal">\Common Files\System\msadc\msadco.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>2</major>
          <minor>71</minor>
          <build>9053</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-773" comment="the version of excel.exe is less than 11.0.8012.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Excel.exe\Path</component>
          <component type="literal">excel.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>11</major>
          <minor>0</minor>
          <build>8012</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-650" comment="Excel 2003 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Office\11.0\Excel\InstallRoot</key>
        <name operator="pattern match">Path</name>
      </object>
      <data operation="AND">
        <value operator="pattern match">.*</value>
      </data>
    </registry_test>
    <patch_test id="hpt-40" comment="Patch PHSS_34163 or later is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <area_patched>PHSS</area_patched>
        <patch_number operator="greater than or equal">34163</patch_number>
      </object>
    </patch_test>
    <swlist_test id="hst-70" comment="Webproxy is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <swlist operator="equals">HP_Webproxy.HPWEB-PX-CORE</swlist>
      </object>
    </swlist_test>
    <file_test id="wft-725" comment="the version of T2embed.dll is less than 5.1.2600.1762" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\T2embed.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>1762</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-724" comment="the version of Fontsub.dll is less than 5.1.2600.1762" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\Fontsub.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>1762</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-708" comment="Fontsub.dll &lt; 5.1.2600.1762 or T2embed.dll &lt;5.1.2600.1762 (WinXP,SP1)" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="wft-724"/>
      <subtest test_ref="wft-725"/>
    </compound_test>
    <file_test id="wft-704" comment="the version of mshtml.dll is less than 5.0.3835.2200" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mshtml.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>3835</build>
          <private>2200</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-733" comment="the version of msmapi32.dll is less than 5.5.3201.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir</component>
          <component type="literal">\Common Files\System\MAPI\1033\NT\msmapi32.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="greater than">
          <major>5</major>
          <minor>5</minor>
          <build>3201</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-632" comment="Outlook 2000 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key datatype="string" operator="equals">SOFTWARE\Microsoft\Office\9.0\Outlook\InstallRoot</key>
        <name>Path</name>
      </object>
      <data operation="AND">
        <value operator="pattern match">.*OFFICE9.*</value>
      </data>
    </registry_test>
    <process_test id="uct-20" comment="smcboot running" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <oval:notes>
        <oval:note>Solaris Management Console web interface</oval:note>
      </oval:notes>
      <object>
        <command operator="pattern match">.*smcboot</command>
      </object>
    </process_test>
    <patch_test id="spt-77" comment="Patch 116807-01 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">116807</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">01</version>
      </data>
    </patch_test>
    <patch_test id="spt-76" comment="Patch 111313-02 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">111313</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">02</version>
      </data>
    </patch_test>
    <package_test id="sat-40" comment="Solaris Management Console Web Components (SUNWwbmc) installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <pkginst operator="equals">SUNWwbmc</pkginst>
      </object>
    </package_test>
    <package_test id="sat-11" comment="Netscape installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <pkginst operator="equals">SUNWnsb</pkginst>
      </object>
    </package_test>
    <patch_test id="hpt-7" comment="Patch PHNE_23948 or later is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <area_patched>PHNE</area_patched>
        <patch_number operator="greater than or equal">23948</patch_number>
      </object>
    </patch_test>
    <swlist_test id="hst-14" comment="InternetSrvcs.INET-ENG-A-MAN is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <swlist operator="equals">InternetSrvcs.INET-ENG-A-MAN</swlist>
      </object>
      <data>
        <version operator="equals">B.10.20</version>
      </data>
    </swlist_test>
    <swlist_test id="hst-13" comment="InternetSrvcs.INETSVCS-RUN is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <swlist operator="equals">InternetSrvcs.INETSVCS-RUN</swlist>
      </object>
      <data>
        <version operator="equals">B.10.20</version>
      </data>
    </swlist_test>
    <compound_test id="cmp-668" comment="InternetSrvcs.INETSVCS-RUN or InternetSrvcs.INET-ENG-A-MAN (B.10.20) is installed" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="hst-13"/>
      <subtest test_ref="hst-14"/>
    </compound_test>
    <compound_test id="cmp-624" comment="800 Series OS Release 10.20" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-11"/>
      <subtest test_ref="uut-12"/>
    </compound_test>
    <uname_test id="uut-12" comment="HP Release B.10.20" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <data operation="AND">
        <os_name operator="equals">HP-UX</os_name>
        <os_release operator="equals">B.10.20</os_release>
      </data>
    </uname_test>
    <compound_test id="cmp-623" comment="700 Series OS Release 10.20" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-10"/>
      <subtest test_ref="uut-12"/>
    </compound_test>
    <compound_test id="cmp-633" comment="700 Series or 800 Series OS Release 10.20" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="cmp-623"/>
      <subtest test_ref="cmp-624"/>
    </compound_test>
    <patch_test id="spt-296" comment="Patch 120239-01 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">120239</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="equals">01</version>
      </data>
    </patch_test>
    <compound_test id="cmp-817" comment="Solaris 9 (x86) meets Sun Alert ID 102215 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-6"/>
      <subtest test_ref="uut-10002"/>
      <subtest negate="true" test_ref="spt-296"/>
    </compound_test>
    <patch_test id="spt-295" comment="Patch 109024-05 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">109024</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="equals">05</version>
      </data>
    </patch_test>
    <compound_test id="cmp-814" comment="Solaris 8 (x86) meets Sun Alert ID 102215 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-4"/>
      <subtest test_ref="uut-10002"/>
      <subtest negate="true" test_ref="spt-295"/>
    </compound_test>
    <patch_test id="spt-294" comment="Patch 120240-01 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">120240</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="equals">01</version>
      </data>
    </patch_test>
    <compound_test id="cmp-813" comment="Solaris 9 (SPARC) meets Sun Alert ID 102215 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-6"/>
      <subtest test_ref="uut-10003"/>
      <subtest negate="true" test_ref="spt-294"/>
    </compound_test>
    <patch_test id="spt-293" comment="Patch 109023-05 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">109023</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="equals">05</version>
      </data>
    </patch_test>
    <compound_test id="cmp-812" comment="Solaris 8 (SPARC) meets Sun Alert ID 102215 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-4"/>
      <subtest test_ref="uut-10003"/>
      <subtest negate="true" test_ref="spt-293"/>
    </compound_test>
    <file_test id="wft-667" comment="mshtml.dll is less than 6.0.2900.2769" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mshtml.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>2900</build>
          <private>2769</private>
        </version>
      </data>
    </file_test>
    <process_test id="uct-15" comment="smbd running" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <command operator="pattern match">^.*smbd.*</command>
      </object>
    </process_test>
    <patch_test id="spt-48" comment="Patch 114684-01 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">114684</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">01</version>
      </data>
    </patch_test>
    <package_test id="sat-28" comment="Samba - Usr (SUNWsmbau) installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <pkginst operator="equals">SUNWsmbau</pkginst>
      </object>
    </package_test>
    <patch_test id="hpt-24" comment="Patch PHSS_34102 or later is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <area_patched>PHSS</area_patched>
        <patch_number operator="greater than or equal">34102</patch_number>
      </object>
    </patch_test>
    <file_test id="wft-718" comment="the version of Gdi32.dll is less than 5.2.3790.2606" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\Gdi32.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>2</minor>
          <build>3790</build>
          <private>2606</private>
        </version>
      </data>
    </file_test>
    <swlist_test id="hst-40" comment="CIFS-Server.CIFS-LIB with version less than A.01.11.04 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <swlist operator="equals">CIFS-Server.CIFS-LIB</swlist>
      </object>
      <data>
        <version operator="pattern match">A\.01\.(0.*|10.*|11[^\.]|11\.0[0-3])</version>
      </data>
    </swlist_test>
    <swlist_test id="hst-39" comment="CIFS-Server.CIFS-ADMIN with version less than A.01.11.04 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <swlist operator="equals">CIFS-Server.CIFS-ADMIN</swlist>
      </object>
      <data>
        <version operator="pattern match">A\.01\.(0.*|10.*|11[^\.]|11\.0[0-3])</version>
      </data>
    </swlist_test>
    <swlist_test id="hst-38" comment="CIFS-Server.CIFS-UTIL with version less than A.01.11.04 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <swlist operator="equals">CIFS-Server.CIFS-UTIL</swlist>
      </object>
      <data>
        <version operator="pattern match">A\.01\.(0.*|10.*|11[^\.]|11\.0[0-3])</version>
      </data>
    </swlist_test>
    <swlist_test id="hst-37" comment="CIFS-Server.CIFS-RUN with version less than A.01.11.04 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <swlist operator="equals">CIFS-Server.CIFS-RUN</swlist>
      </object>
      <data>
        <version operator="pattern match">A\.01\.(0.*|10.*|11[^\.]|11\.0[0-3])</version>
      </data>
    </swlist_test>
    <compound_test id="cmp-717" comment="Any of the CIFS components has a version less than A.01.11.04" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="hst-37"/>
      <subtest test_ref="hst-38"/>
      <subtest test_ref="hst-39"/>
      <subtest test_ref="hst-40"/>
    </compound_test>
    <file_test id="wft-732" comment="the version of msmapi32.dll is greater than 11.0.6566.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir</component>
          <component type="literal">\Common Files\System\MSMAPI\1033\msmapi32.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="greater than">
          <major>11</major>
          <minor>0</minor>
          <build>6566</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-630" comment="Outlook 2003 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key datatype="string" operator="equals">SOFTWARE\Microsoft\Office\11.0\Outlook\InstallRoot</key>
        <name>Path</name>
      </object>
      <data operation="AND">
        <value operator="pattern match">.*OFFICE11.*</value>
      </data>
    </registry_test>
    <file_test id="wft-666" comment="mshtml.dll is less than 6.0.3790.418" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mshtml.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>3790</build>
          <private>418</private>
        </version>
      </data>
    </file_test>
    <patch_test id="hpt-38" comment="Patch PHCO_30402 or later is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <area_patched>PHCO</area_patched>
        <patch_number operator="greater than or equal">30402</patch_number>
      </object>
    </patch_test>
    <file_test id="wft-790" comment="the version of shell32.dll is less than 6.0.2900.2869" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\shell32.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>2900</build>
          <private>2869</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-775" comment="the version of mshtml.dll is less than 5.0.3839.2200" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mshtml.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>3839</build>
          <private>2200</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-651" comment="Internet Explorer 5.01 (any patch level) is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Internet Explorer</key>
        <name>Version</name>
      </object>
      <data>
        <value operator="pattern match">5\.0\..*</value>
      </data>
    </registry_test>
    <patch_test id="spt-153" comment="Patch 121309-01 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">121309</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">01</version>
      </data>
    </patch_test>
    <compound_test id="cmp-700" comment="Solaris 10 (x86) meets Sun Alert ID 102016 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-10001"/>
      <subtest test_ref="uut-10002"/>
      <subtest negate="true" test_ref="spt-153"/>
    </compound_test>
    <patch_test id="spt-150" comment="Patch 121308-01 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">121308</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">01</version>
      </data>
    </patch_test>
    <compound_test id="cmp-699" comment="Solaris 10 (SPARC) meets Sun Alert ID 102016 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-10001"/>
      <subtest test_ref="uut-10003"/>
      <subtest negate="true" test_ref="spt-150"/>
    </compound_test>
    <patch_test id="spt-152" comment="Patch 116808-02 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">116808</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">02</version>
      </data>
    </patch_test>
    <compound_test id="cmp-698" comment="Solaris 9 (x86) meets Sun Alert ID 102016 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-6"/>
      <subtest test_ref="uut-10002"/>
      <subtest negate="true" test_ref="spt-152"/>
    </compound_test>
    <patch_test id="spt-149" comment="Patch 116807-02 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">116807</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">02</version>
      </data>
    </patch_test>
    <compound_test id="cmp-697" comment="Solaris 9 (SPARC) meets Sun Alert ID 102016 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-6"/>
      <subtest test_ref="uut-10003"/>
      <subtest negate="true" test_ref="spt-149"/>
    </compound_test>
    <patch_test id="spt-151" comment="Patch 111314-03 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">111314</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">03</version>
      </data>
    </patch_test>
    <compound_test id="cmp-696" comment="Solaris 8 (x86) meets Sun Alert ID 102016 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-4"/>
      <subtest test_ref="uut-10002"/>
      <subtest negate="true" test_ref="spt-151"/>
    </compound_test>
    <patch_test id="spt-148" comment="Patch 111313-03 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">111313</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">03</version>
      </data>
    </patch_test>
    <compound_test id="cmp-695" comment="Solaris 8 (SPARC) meets Sun Alert ID 102016 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-4"/>
      <subtest test_ref="uut-10003"/>
      <subtest negate="true" test_ref="spt-148"/>
    </compound_test>
    <patch_test id="hpt-6" comment="Patch PHNE_23950 or later is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <area_patched>PHNE</area_patched>
        <patch_number operator="greater than or equal">23950</patch_number>
      </object>
    </patch_test>
    <patch_test id="spt-249" comment="Patch 107180-31 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">107180</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">31</version>
      </data>
    </patch_test>
    <patch_test id="spt-232" comment="Patch 112807-09 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">112807</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">09</version>
      </data>
    </patch_test>
    <patch_test id="spt-231" comment="Patch 108919-21 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="binary" operator="equals">108919</base>
      </object>
      <data operation="AND">
        <version datatype="binary" operator="greater than or equal">21</version>
      </data>
    </patch_test>
    <process_test id="uct-9" comment="dtlogin running" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <command datatype="string" operator="pattern match">^.*dtlogin.*</command>
      </object>
    </process_test>
    <file_test id="uft-23" comment="File /usr/dt/bin/dtlogin exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/dt/bin/dtlogin</component>
        </path>
      </object>
    </file_test>
    <file_test id="wft-646" comment="the version of Quartz.dll is less than 6.4.2600.1738" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\Quartz.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>4</minor>
          <build>2600</build>
          <private>1738</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-645" comment="the version of Quartz.dll is greater than or equal to 6.4.2600.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\Quartz.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="greater than or equal">
          <major>6</major>
          <minor>4</minor>
          <build>2600</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-601" comment="DirectX packaged with Windows XP,SP1 has DirectShow Vulnerability" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="wrt-2"/>
      <subtest test_ref="wrt-4"/>
      <subtest test_ref="wft-645"/>
      <subtest test_ref="wft-646"/>
    </compound_test>
    <file_test id="wft-720" comment="the version of Gdi32.dll is less than 5.1.2600.2818" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\Gdi32.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>2818</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-717" comment="the version of Gdi32.dll is less than 5.0.2195.7073" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\Gdi32.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>2195</build>
          <private>7073</private>
        </version>
      </data>
    </file_test>
    <patch_test id="hpt-11" comment="Patch PHCO_33989 or later is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <area_patched>PHCO</area_patched>
        <patch_number operator="greater than or equal">33989</patch_number>
      </object>
    </patch_test>
    <swlist_test id="hst-25" comment="OS-Core.UX-CORE is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <swlist operator="equals">OS-Core.UX-CORE</swlist>
      </object>
      <data>
        <version operator="equals">B.11.00</version>
      </data>
    </swlist_test>
    <swlist_test id="hst-24" comment="OS-Core.CORE-ENG-A-MAN is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <swlist operator="equals">OS-Core.CORE-ENG-A-MAN</swlist>
      </object>
      <data>
        <version operator="equals">B.11.00</version>
      </data>
    </swlist_test>
    <compound_test id="cmp-679" comment="OS-Core.CORE-ENG-A-MAN or OS-Core.UX-CORE (B.11.00) is installed" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="hst-24"/>
      <subtest test_ref="hst-25"/>
    </compound_test>
    <file_test id="wft-503" comment="the version of httpext.dll is less than 6.0.2600.165" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\inetsrv\httpext.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>2600</build>
          <private>165</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-1109" comment="no service pack and the version of httpext.dll is less than 6.0.2600.165" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="true" test_ref="wrt-3"/>
      <subtest negate="false" test_ref="wft-503"/>
    </compound_test>
    <file_test id="wft-504" comment="the version of httpext.dll is less than 6.0.2600.1579" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\inetsrv\httpext.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>2600</build>
          <private>1579</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-1108" comment="Service pack 1 and the version of httpext.dll is less than 6.0.2600.1579" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-4"/>
      <subtest negate="false" test_ref="wft-504"/>
    </compound_test>
    <compound_test id="cmp-1110" comment="a vulnerable version of httpext.dll exists" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-1108"/>
      <subtest negate="false" test_ref="cmp-1109"/>
    </compound_test>
    <file_test id="wft-757" comment="the version of Tcpip.sys is less than 5.1.2600.2827 (XP,SP2)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\drivers\tcpip.sys</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>2827</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-650" comment="the version of Quartz.dll is less than 6.4.3790.399" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\Quartz.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>4</minor>
          <build>3790</build>
          <private>399</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-649" comment="the version of Quartz.dll is greater than or equal to 6.4.3790.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\Quartz.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="greater than or equal">
          <major>6</major>
          <minor>4</minor>
          <build>3790</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-603" comment="DirectX packaged with Windows Server 2003 has DirectShow Vulnerability" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="wrt-61"/>
      <subtest negate="true" test_ref="wrt-3"/>
      <subtest test_ref="wft-649"/>
      <subtest test_ref="wft-650"/>
    </compound_test>
    <file_test id="wft-677" comment="cdosys.dll is less than 6.1.3940.42" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\cdosys.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>1</minor>
          <build>3940</build>
          <private>42</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-711" comment="the version of wordpad.exe is less than 4.0.1381.33598" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir</component>
          <component type="literal">\Windows NT\Accessories\wordpad.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>4</major>
          <minor>0</minor>
          <build>1381</build>
          <private>33598</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-690" comment="msieftp.dll is less than 6.0.2800.1724" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\msieftp.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>2800</build>
          <private>1724</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-662" comment="the version of rpcss.dll is less than 5.2.3790.374" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\rpcss.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>2</minor>
          <build>3790</build>
          <private>374</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-661" comment="the version of ole32.dll is less than 5.2.3790.374" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\ole32.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>2</minor>
          <build>3790</build>
          <private>374</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-609" comment="Either ole32.dll or rpcss.dll has a version less than 5.2.3790.374" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="wft-661"/>
      <subtest test_ref="wft-662"/>
    </compound_test>
    <patch_test id="hpt-57" comment="Patch PHCO_33219 or subsequent is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <area_patched>PHCO</area_patched>
        <patch_number operator="greater than or equal">33219</patch_number>
      </object>
    </patch_test>
    <swlist_test id="hst-81" comment="OS-Core.UX-CORE is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <swlist operator="equals">OS-Core.UX-CORE</swlist>
      </object>
    </swlist_test>
    <patch_test id="spt-154" comment="Patch 121332-01 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">121332</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">01</version>
      </data>
    </patch_test>
    <package_test id="sat-51" comment="the SUNWlzas package (for slsadmin) is installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <pkginst operator="equals">SUNWlzas</pkginst>
      </object>
    </package_test>
    <swlist_test id="hst-45" comment="TOUR_PRODUCT.T-NET2-KRN with version less than A.03.00 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <swlist operator="equals">TOUR_PRODUCT.T-NET2-KRN</swlist>
      </object>
      <data>
        <version operator="pattern match">A\.0[12]\..*</version>
      </data>
    </swlist_test>
    <swlist_test id="hst-59" comment="IPSec.IPSEC2-KRN with version less than A.2.00.01 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <swlist operator="equals">IPSec.IPSEC2-KRN</swlist>
      </object>
      <data>
        <version operator="pattern match">A\.([01].*|2\.00\.00)</version>
      </data>
    </swlist_test>
    <compound_test id="cmp-761" comment="IPSec.IPSEC2-KRN version is under A.2.00.01 or TOUR version is under 3.0 or patch PHNE_32606 is not installed" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="hst-59"/>
      <subtest test_ref="hst-45"/>
      <subtest negate="true" test_ref="hpt-23"/>
    </compound_test>
    <swlist_test id="hst-58" comment="IPSec.IPSEC2-KRN is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <swlist operator="equals">IPSec.IPSEC2-KRN</swlist>
      </object>
    </swlist_test>
    <file_test id="wft-678" comment="cdosys.dll is less than 6.1.1002.0" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\cdosys.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>1</minor>
          <build>1002</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-632" comment="the version of Spoolsv.exe is less than 5.2.3790.346" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\spoolsv.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>2</minor>
          <build>3790</build>
          <private>346</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-410" comment="Win2K/XP/2003 service pack 1 (or later) is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion</key>
        <name>CSDVersion</name>
      </object>
      <data operation="AND">
        <value operator="pattern match">^Service Pack [1-9]|\d{2,}$</value>
      </data>
    </registry_test>
    <file_test id="wft-740" comment="the version of winamp is less than or equal 5.12" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Media\Winamp\shell\open\command</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than or equal">
          <major>5</major>
          <minor>1</minor>
          <build>2</build>
          <private>275</private>
        </version>
      </data>
    </file_test>
    <activedirectory_test id="wat-1941" comment="apply sender filters" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <naming_context>configuration</naming_context>
        <relative_dn operator="pattern match">^CN=[^,]+,CN=SMTP,CN=Protocols,CN=[^,]+,CN=Servers,CN=[^,]+,CN=Administrative Groups,CN=[^,]+,CN=Microsoft Exchange,CN=Services$</relative_dn>
        <attribute>msExchServerBindingsTurflist</attribute>
      </object>
      <data>
        <adstype>ADSTYPE_PRINTABLE_STRING</adstype>
        <value operator="pattern match">.+</value>
      </data>
    </activedirectory_test>
    <activedirectory_test id="wat-1940" comment="apply recipient and connection filters" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <naming_context>configuration</naming_context>
        <relative_dn operator="pattern match">^CN=[^,]+,CN=SMTP,CN=Protocols,CN=[^,]+,CN=Servers,CN=[^,]+,CN=Administrative Groups,CN=[^,]+,CN=Microsoft Exchange,CN=Services$</relative_dn>
        <attribute>msExchServerBindingsFiltering</attribute>
      </object>
      <data>
        <adstype>ADSTYPE_PRINTABLE_STRING</adstype>
        <value operator="pattern match">\:3$</value>
      </data>
    </activedirectory_test>
    <activedirectory_test id="wat-1930" comment="use port 25 for inbound SMTP connections" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <naming_context>configuration</naming_context>
        <relative_dn operator="pattern match">^CN=[^,]+,CN=SMTP,CN=Protocols,CN=[^,]+,CN=Servers,CN=[^,]+,CN=Administrative Groups,CN=[^,]+,CN=Microsoft Exchange,CN=Services$</relative_dn>
        <attribute>msExchServerBindings</attribute>
      </object>
      <data>
        <adstype>ADSTYPE_INTEGER</adstype>
        <value datatype="int" operator="equals">25</value>
      </data>
    </activedirectory_test>
    <activedirectory_test id="wat-1920" comment="enable logging of connections between SMTP hosts" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <naming_context>configuration</naming_context>
        <relative_dn operator="pattern match">^CN=[^,]+,CN=SMTP,CN=Protocols,CN=[^,]+,CN=Servers,CN=[^,]+,CN=Administrative Groups,CN=[^,]+,CN=Microsoft Exchange,CN=Services$</relative_dn>
        <attribute>msExchLogType</attribute>
      </object>
      <data>
        <adstype>ADSTYPE_INTEGER</adstype>
        <value datatype="int" operator="bitwise and">1</value>
      </data>
    </activedirectory_test>
    <activedirectory_test id="wat-1910" comment="use only basic authentication with TLS encryption for outbound SMTP connections" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <naming_context>configuration</naming_context>
        <relative_dn operator="pattern match">^CN=[^,]+,CN=SMTP,CN=Protocols,CN=[^,]+,CN=Servers,CN=[^,]+,CN=Administrative Groups,CN=[^,]+,CN=Microsoft Exchange,CN=Services$</relative_dn>
        <attribute>msExchSmtpOutboundSecurityFlag</attribute>
      </object>
      <data>
        <adstype>ADSTYPE_INTEGER</adstype>
        <value datatype="int" operator="equals">268</value>
      </data>
    </activedirectory_test>
    <activedirectory_test id="wat-1900" comment="use port 25 for outbound SMTP connections" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <naming_context>configuration</naming_context>
        <relative_dn operator="pattern match">^CN=[^,]+,CN=SMTP,CN=Protocols,CN=[^,]+,CN=Servers,CN=[^,]+,CN=Administrative Groups,CN=[^,]+,CN=Microsoft Exchange,CN=Services$</relative_dn>
        <attribute>msExchSmtpOutgoingPort</attribute>
      </object>
      <data>
        <adstype>ADSTYPE_INTEGER</adstype>
        <value datatype="int" operator="equals">25</value>
      </data>
    </activedirectory_test>
    <activedirectory_test id="wat-1890" comment="perform reverse DNS lookups on incoming messages" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <naming_context>configuration</naming_context>
        <relative_dn operator="pattern match">^CN=[^,]+,CN=SMTP,CN=Protocols,CN=[^,]+,CN=Servers,CN=[^,]+,CN=Administrative Groups,CN=[^,]+,CN=Microsoft Exchange,CN=Services$</relative_dn>
        <attribute>msExchSmtpPerformReverseDnsLookup</attribute>
      </object>
      <data>
        <adstype>ADSTYPE_INTEGER</adstype>
        <value datatype="int" operator="bitwise and">1</value>
      </data>
    </activedirectory_test>
    <activedirectory_test id="wat-1880" comment="use a smart host to relay SMTP messages" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <naming_context>configuration</naming_context>
        <relative_dn operator="pattern match">^CN=[^,]+,CN=SMTP,CN=Protocols,CN=[^,]+,CN=Servers,CN=[^,]+,CN=Administrative Groups,CN=[^,]+,CN=Microsoft Exchange,CN=Services$</relative_dn>
        <attribute>msExchSmtpSmartHost</attribute>
      </object>
      <data>
        <adstype>ADSTYPE_PRINTABLE_STRING</adstype>
        <value operator="pattern match">.+</value>
      </data>
    </activedirectory_test>
    <activedirectory_test id="wat-1875" comment="only allow explicitly listed hosts to relay messages through this sever" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <naming_context>configuration</naming_context>
        <relative_dn operator="pattern match">^CN=[^,]+,CN=SMTP,CN=Protocols,CN=[^,]+,CN=Servers,CN=[^,]+,CN=Administrative Groups,CN=[^,]+,CN=Microsoft Exchange,CN=Services$</relative_dn>
        <attribute>msExchSmtpRelayForAuth</attribute>
      </object>
      <data>
        <adstype>ADSTYPE_INTEGER</adstype>
        <value datatype="int" operator="equals">0</value>
      </data>
    </activedirectory_test>
    <activedirectory_test id="wat-1830" comment="resolve anonymous email" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <naming_context>configuration</naming_context>
        <relative_dn operator="pattern match">^CN=[^,]+,CN=SMTP,CN=Protocols,CN=[^,]+,CN=Servers,CN=[^,]+,CN=Administrative Groups,CN=[^,]+,CN=Microsoft Exchange,CN=Services$</relative_dn>
        <attribute>msExchAuthMailDisposition</attribute>
      </object>
      <data>
        <adstype>ADSTYPE_INTEGER</adstype>
        <value datatype="int" operator="bitwise and">1</value>
      </data>
    </activedirectory_test>
    <activedirectory_test id="wat-1821" comment="require TSL encryption to connect to the SMTP server" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <naming_context>configuration</naming_context>
        <relative_dn operator="pattern match">^CN=[^,]+,CN=SMTP,CN=Protocols,CN=[^,]+,CN=Servers,CN=[^,]+,CN=Administrative Groups,CN=[^,]+,CN=Microsoft Exchange,CN=Services$</relative_dn>
        <attribute>msExchSmtpInboundCommandSupportOptions</attribute>
      </object>
      <data>
        <adstype>ADSTYPE_INTEGER</adstype>
        <value datatype="int" operator="bitwise and">131072</value>
      </data>
    </activedirectory_test>
    <activedirectory_test id="wat-1820" comment="only allow basic authentication to connect to the SMTP server" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <naming_context>configuration</naming_context>
        <relative_dn operator="pattern match">^CN=[^,]+,CN=SMTP,CN=Protocols,CN=[^,]+,CN=Servers,CN=[^,]+,CN=Administrative Groups,CN=[^,]+,CN=Microsoft Exchange,CN=Services$</relative_dn>
        <attribute>msExchAuthenticationFlags</attribute>
      </object>
      <data>
        <adstype>ADSTYPE_INTEGER</adstype>
        <value datatype="int" operator="equals">2</value>
      </data>
    </activedirectory_test>
    <activedirectory_test id="wat-1810" comment="have any SMTP connectors use a smart host" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <naming_context>configuration</naming_context>
        <relative_dn operator="pattern match">^CN=[^,]*,CN=Connections,CN=[^,]*,CN=Routing Groups,CN=[^,]*,CN=Administrative Groups,CN=[^,]*,CN=Microsoft Exchange,CN=Services$</relative_dn>
        <attribute>msExchSmtpSmartHost</attribute>
      </object>
      <data>
        <adstype>ADSTYPE_PRINTABLE_STRING</adstype>
        <value operator="pattern match">.+</value>
      </data>
    </activedirectory_test>
    <activedirectory_test id="wat-1790" comment="force outbound connections to use only basic authentication with TLS encryption" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <naming_context>configuration</naming_context>
        <relative_dn operator="pattern match">^CN=[^,]*,CN=Connections,CN=[^,]*,CN=Routing Groups,CN=[^,]*,CN=Administrative Groups,CN=[^,]*,CN=Microsoft Exchange,CN=Services$</relative_dn>
        <attribute>msExchSmtpOutboundSecurityFlag</attribute>
      </object>
      <data>
        <adstype>ADSTYPE_INTEGER</adstype>
        <value datatype="int" operator="equals">270</value>
      </data>
    </activedirectory_test>
    <activedirectory_test id="wat-1780" comment="allow unauthenticated entities to relay through this SMTP connector" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <naming_context>configuration</naming_context>
        <relative_dn operator="pattern match">^CN=[^,]*,CN=Connections,CN=[^,]*,CN=Routing Groups,CN=[^,]*,CN=Administrative Groups,CN=[^,]*,CN=Microsoft Exchange,CN=Services$</relative_dn>
        <attribute>msExchSmtpOutboundSecurityFlag</attribute>
      </object>
      <data>
        <adstype>ADSTYPE_INTEGER</adstype>
        <value datatype="int" operator="bitwise and">4096</value>
      </data>
    </activedirectory_test>
    <activedirectory_test id="wat-1771" comment="SMTP connector object exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <naming_context>configuration</naming_context>
        <relative_dn operator="pattern match">^CN=[^,]*,CN=Connections,CN=[^,]*,CN=Routing Groups,CN=[^,]*,CN=Administrative Groups,CN=[^,]*,CN=Microsoft Exchange,CN=Services$</relative_dn>
        <attribute operator="pattern match">.*</attribute>
      </object>
    </activedirectory_test>
    <activedirectory_test id="wat-1770" comment="limit SMTP connector scope to the routing group" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <naming_context>configuration</naming_context>
        <relative_dn operator="pattern match">^CN=[^,]*,CN=Connections,CN=[^,]*,CN=Routing Groups,CN=[^,]*,CN=Administrative Groups,CN=[^,]*,CN=Microsoft Exchange,CN=Services$</relative_dn>
        <attribute>routingList</attribute>
      </object>
      <data>
        <adstype>ADSTYPE_PRINTABLE_STRING</adstype>
        <value operator="pattern match">^local\:</value>
      </data>
    </activedirectory_test>
    <activedirectory_test id="wat-1737" comment="change state to critical when any basic Exchange service stops" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <naming_context>configuration</naming_context>
        <relative_dn operator="pattern match">^CN=[^,]*,CN=Servers,CN=[^,]*,CN=Administrative Groups,CN=[^,]*,CN=Microsoft Exchange,CN=Services$</relative_dn>
        <attribute>msExchMonitoringResources</attribute>
      </object>
      <data>
        <adstype>ADSTYPE_PRINTABLE_STRING</adstype>
        <value operator="pattern match">^\d+\:1\:</value>
      </data>
    </activedirectory_test>
    <activedirectory_test id="wat-1720" comment="disable all monitoring on this server" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <naming_context>configuration</naming_context>
        <relative_dn operator="pattern match">^CN=[^,]*,CN=Servers,CN=[^,]*,CN=Administrative Groups,CN=[^,]*,CN=Microsoft Exchange,CN=Services$</relative_dn>
        <attribute>msExchMonitoringMode</attribute>
      </object>
      <data>
        <adstype>ADSTYPE_INTEGER</adstype>
        <value datatype="int" operator="not equal">0</value>
      </data>
    </activedirectory_test>
    <activedirectory_test id="wat-1690" comment="disable automatic log removal" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <naming_context>configuration</naming_context>
        <relative_dn operator="pattern match">^CN=[^,]*,CN=Servers,CN=[^,]*,CN=Administrative Groups,CN=[^,]*,CN=Microsoft Exchange,CN=Services$</relative_dn>
        <attribute>msExchTrkLogCleaningInterval</attribute>
      </object>
      <data>
        <adstype>ADSTYPE_INTEGER</adstype>
        <value datatype="int" operator="equals">0</value>
      </data>
    </activedirectory_test>
    <activedirectory_test id="wat-1680" comment="enable message tracking" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <naming_context>configuration</naming_context>
        <relative_dn operator="pattern match">^CN=[^,]*,CN=Servers,CN=[^,]*,CN=Administrative Groups,CN=[^,]*,CN=Microsoft Exchange,CN=Services$</relative_dn>
        <attribute>msExchMessageTrackLogFilter</attribute>
      </object>
      <data>
        <adstype>ADSTYPE_INTEGER</adstype>
        <value datatype="int" operator="equals">1</value>
      </data>
    </activedirectory_test>
    <activedirectory_test id="wat-1670" comment="enable subject logging and display" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <naming_context>configuration</naming_context>
        <relative_dn operator="pattern match">^CN=[^,]*,CN=Servers,CN=[^,]*,CN=Administrative Groups,CN=[^,]*,CN=Microsoft Exchange,CN=Services$</relative_dn>
        <attribute>messageTrackingEnabled</attribute>
      </object>
      <data>
        <adstype>ADSTYPE_INTEGER</adstype>
        <value datatype="int" operator="bitwise and">262144</value>
      </data>
    </activedirectory_test>
    <activedirectory_test id="wat-1590" comment="don't have mailbox store clients support S/MIME signatures" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <naming_context>configuration</naming_context>
        <relative_dn operator="pattern match">^CN=Public Folder Store \([^\)]+\),CN=[^,]*,CN=InformationStore,CN=[^,]*,CN=Servers,CN=[^,]*,CN=Administrative Groups,CN=[^,]*,CN=Microsoft Exchange,CN=Services$</relative_dn>
        <attribute>msExchDownGradeMultipartSigned</attribute>
      </object>
      <data>
        <adstype>ADSTYPE_INTEGER</adstype>
        <value datatype="int" operator="bitwise and">1</value>
      </data>
    </activedirectory_test>
    <activedirectory_test id="wat-1581" comment="use TCP port 995 for the secure POP3 service" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <naming_context>configuration</naming_context>
        <relative_dn operator="pattern match">^CN=[^,]+,CN=POP3,CN=Protocols,CN=[^,]+,CN=Servers,CN=[^,]+,CN=Administrative Groups,CN=[^,]+,CN=Microsoft Exchange,CN=Services$</relative_dn>
        <attribute>msExchSecureBindings</attribute>
      </object>
      <data>
        <adstype>ADSTYPE_INTEGER</adstype>
        <value datatype="int" operator="equals">995</value>
      </data>
    </activedirectory_test>
    <activedirectory_test id="wat-1580" comment="use TCP port 110 for the POP3 service" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <naming_context>configuration</naming_context>
        <relative_dn operator="pattern match">^CN=[^,]+,CN=POP3,CN=Protocols,CN=[^,]+,CN=Servers,CN=[^,]+,CN=Administrative Groups,CN=[^,]+,CN=Microsoft Exchange,CN=Services$</relative_dn>
        <attribute>msExchServerBindings</attribute>
      </object>
      <data>
        <adstype>ADSTYPE_INTEGER</adstype>
        <value datatype="int" operator="equals">110</value>
      </data>
    </activedirectory_test>
    <activedirectory_test id="wat-1570" comment="use SSL when downloading meeting requests using POP3" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <naming_context>configuration</naming_context>
        <relative_dn operator="pattern match">^CN=[^,]+,CN=POP3,CN=Protocols,CN=[^,]+,CN=Servers,CN=[^,]+,CN=Administrative Groups,CN=[^,]+,CN=Microsoft Exchange,CN=Services$</relative_dn>
        <attribute>oWAServer</attribute>
      </object>
      <data>
        <adstype>ADSTYPE_PRINTABLE_STRING</adstype>
        <value operator="pattern match">^https\:\/\/</value>
      </data>
    </activedirectory_test>
    <activedirectory_test id="wat-1532" comment="allow simple authentication and security layer (SASL) to connect to the POP3 service" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <naming_context>configuration</naming_context>
        <relative_dn operator="pattern match">^CN=[^,]+,CN=POP3,CN=Protocols,CN=[^,]+,CN=Servers,CN=[^,]+,CN=Administrative Groups,CN=[^,]+,CN=Microsoft Exchange,CN=Services$</relative_dn>
        <attribute>msExchAuthenticationFlags</attribute>
      </object>
      <data>
        <adstype>ADSTYPE_INTEGER</adstype>
        <value datatype="int" operator="bitwise and">4</value>
      </data>
    </activedirectory_test>
    <activedirectory_test id="wat-1531" comment="require TSL encryption to connect to the POP3 service" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <naming_context>configuration</naming_context>
        <relative_dn operator="pattern match">^CN=[^,]+,CN=POP3,CN=Protocols,CN=[^,]+,CN=Servers,CN=[^,]+,CN=Administrative Groups,CN=[^,]+,CN=Microsoft Exchange,CN=Services$</relative_dn>
        <attribute>attribute>msExchAuthenticationFlags</attribute>
      </object>
      <data>
        <adstype>ADSTYPE_INTEGER</adstype>
        <value datatype="int" operator="bitwise and">1</value>
      </data>
    </activedirectory_test>
    <activedirectory_test id="wat-1530" comment="allow basic authentication to connect to the POP3 service" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <naming_context>configuration</naming_context>
        <relative_dn operator="pattern match">^CN=[^,]+,CN=POP3,CN=Protocols,CN=[^,]+,CN=Servers,CN=[^,]+,CN=Administrative Groups,CN=[^,]+,CN=Microsoft Exchange,CN=Services$</relative_dn>
        <attribute>msExchAuthenticationFlags</attribute>
      </object>
      <data>
        <adstype>ADSTYPE_INTEGER</adstype>
        <value datatype="int" operator="bitwise and">2</value>
      </data>
    </activedirectory_test>
    <activedirectory_test id="wat-1480" comment="disable ActiveSync" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <naming_context>configuration</naming_context>
        <relative_dn operator="pattern match">^CN=Outlook Mobile Access,CN=Global Settings,CN=Labtop Organization,CN=Microsoft Exchange,CN=Services$</relative_dn>
        <attribute>msExchMoaAdminWirelessEnable</attribute>
      </object>
      <data>
        <adstype>ADSTYPE_INTEGER</adstype>
        <value datatype="int" operator="bitwise and">4</value>
      </data>
    </activedirectory_test>
    <activedirectory_test id="wat-1470" comment="disable Outlook Mobile Access" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <naming_context>configuration</naming_context>
        <relative_dn operator="pattern match">^CN=Outlook Mobile Access,CN=Global Settings,CN=Labtop Organization,CN=Microsoft Exchange,CN=Services$</relative_dn>
        <attribute>msExchMoaAdminWirelessEnable</attribute>
      </object>
      <data>
        <adstype>ADSTYPE_INTEGER</adstype>
        <value datatype="int" operator="bitwise and">2</value>
      </data>
    </activedirectory_test>
    <activedirectory_test id="wat-1450" comment="accept messages without notifying the sender of filtering" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <naming_context>configuration</naming_context>
        <relative_dn operator="pattern match">^CN=[^,]+,CN=Message Delivery,CN=Global Settings,CN=[^,]+,CN=Microsoft Exchange,CN=Services$</relative_dn>
        <attribute>msExchTurfListOptions</attribute>
      </object>
      <data>
        <adstype>ADSTYPE_INTEGER</adstype>
        <value datatype="int" operator="bitwise and">1</value>
      </data>
    </activedirectory_test>
    <activedirectory_test id="wat-1440" comment="do not drop connections if the address matches filters" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <naming_context>configuration</naming_context>
        <relative_dn operator="pattern match">^CN=[^,]+,CN=Message Delivery,CN=Global Settings,CN=[^,]+,CN=Microsoft Exchange,CN=Services$</relative_dn>
        <attribute>msExchTurfListOptions</attribute>
      </object>
      <data>
        <adstype>ADSTYPE_INTEGER</adstype>
        <value datatype="int" operator="bitwise and">8</value>
      </data>
    </activedirectory_test>
    <activedirectory_test id="wat-1430" comment="filter messages with a blank sender" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <naming_context>configuration</naming_context>
        <relative_dn operator="pattern match">^CN=[^,]+,CN=Message Delivery,CN=Global Settings,CN=[^,]+,CN=Microsoft Exchange,CN=Services$</relative_dn>
        <attribute>msExchTurfListOptions</attribute>
      </object>
      <data>
        <adstype>ADSTYPE_INTEGER</adstype>
        <value datatype="int" operator="bitwise and">2</value>
      </data>
    </activedirectory_test>
    <activedirectory_test id="wat-1420" comment="archive filtered messages" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <naming_context>configuration</naming_context>
        <relative_dn operator="pattern match">^CN=Message Delivery,CN=Global Settings,CN=[^,]+,CN=Microsoft Exchange,CN=Services$</relative_dn>
        <attribute>msExchTurfListAction</attribute>
      </object>
      <data>
        <adstype>ADSTYPE_PRINTABLE_STRING</adstype>
        <value operator="pattern match">Filter</value>
      </data>
    </activedirectory_test>
    <activedirectory_test id="wat-1390" comment="disable the filtering of recipients who are not in Active Directory" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <naming_context>configuration</naming_context>
        <relative_dn operator="pattern match">^CN=[^,]+,CN=Message Delivery,CN=Global Settings,CN=[^,]+,CN=Microsoft Exchange,CN=Services$</relative_dn>
        <attribute operator="not equal">msExchRecipTurfListOptions</attribute>
      </object>
    </activedirectory_test>
    <activedirectory_test id="wat-1380" comment="limit the number of recipients in outbound messages to 5000" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <naming_context>configuration</naming_context>
        <relative_dn operator="pattern match">^CN=Message Delivery,CN=Global Settings,CN=[^,]+,CN=Microsoft Exchange,CN=Services$</relative_dn>
        <attribute>msExchRecipLimit</attribute>
      </object>
      <data>
        <adstype>ADSTYPE_INTEGER</adstype>
        <value datatype="int" operator="less than or equal">5000</value>
      </data>
    </activedirectory_test>
    <activedirectory_test id="wat-1371" comment="limit the size of messages from the server to 30MB" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <naming_context>configuration</naming_context>
        <relative_dn operator="pattern match">^CN=Message Delivery,CN=Global Settings,CN=[^,]+,CN=Microsoft Exchange,CN=Services$</relative_dn>
        <attribute>submissionContLength</attribute>
      </object>
      <data>
        <adstype>ADSTYPE_INTEGER</adstype>
        <value datatype="int" operator="less than or equal">30720</value>
      </data>
    </activedirectory_test>
    <activedirectory_test id="wat-1370" comment="limit the size of messages to the server to 30MB" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <naming_context>configuration</naming_context>
        <relative_dn operator="pattern match">^CN=Message Delivery,CN=Global Settings,CN=[^,]+,CN=Microsoft Exchange,CN=Services$</relative_dn>
        <attribute>delivContLength</attribute>
      </object>
      <data>
        <adstype>ADSTYPE_INTEGER</adstype>
        <value datatype="int" operator="less than or equal">30720</value>
      </data>
    </activedirectory_test>
    <activedirectory_test id="wat-1350" comment="subscribe to a block list to block spam" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <naming_context>configuration</naming_context>
        <relative_dn operator="pattern match">^CN=[^,]+,CN=[^,]+,CN=[^,]+,CN=Message Delivery,CN=Global Settings,CN=[^,]+,CN=Microsoft Exchange,CN=Services$</relative_dn>
        <attribute operator="pattern match">.*</attribute>
      </object>
    </activedirectory_test>
    <activedirectory_test id="wat-1300" comment="delete mailboxes without waiting for the store to be backed up" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <naming_context>configuration</naming_context>
        <relative_dn operator="pattern match">^CN=Mailbox Store \([^\)]*\),CN=[^,]*,CN=InformationStore,CN=[^,]*,CN=Servers,CN=[^,]*,CN=Administrative Groups,CN=[^,]*,CN=Microsoft Exchange,CN=Services$</relative_dn>
        <attribute>deletedItemFlags</attribute>
      </object>
      <data>
        <adstype>ADSTYPE_INTEGER</adstype>
        <value datatype="int" operator="bitwise and">2</value>
      </data>
    </activedirectory_test>
    <activedirectory_test id="wat-1290" comment="have clients support S/MIME" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <naming_context>configuration</naming_context>
        <relative_dn operator="pattern match">^CN=Mailbox Store \([^\)]*\),CN=[^,]*,CN=InformationStore,CN=[^,]*,CN=Servers,CN=[^,]*,CN=Administrative Groups,CN=[^,]*,CN=Microsoft Exchange,CN=Services$</relative_dn>
        <attribute>msExchDownGradeMultipartSigned</attribute>
      </object>
      <data>
        <adstype>ADSTYPE_INTEGER</adstype>
        <value datatype="int" operator="equals">0</value>
      </data>
    </activedirectory_test>
    <activedirectory_test id="wat-1280" comment="archive all messages received by mailboxes on this store" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <naming_context>configuration</naming_context>
        <relative_dn operator="pattern match">^CN=Mailbox Store \([^\)]*\),CN=[^,]*,CN=InformationStore,CN=[^,]*,CN=Servers,CN=[^,]*,CN=Administrative Groups,CN=[^,]*,CN=Microsoft Exchange,CN=Services$</relative_dn>
        <attribute>msExchMessageJournalRecipient</attribute>
      </object>
      <data>
        <adstype>ADSTYPE_DN_STRING</adstype>
        <value operator="pattern match">.+</value>
      </data>
    </activedirectory_test>
    <activedirectory_test id="wat-1251" comment="use TCP 993 for the secure IMAP4 service" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <naming_context>configuration</naming_context>
        <relative_dn operator="pattern match">^CN=[^,]+,CN=IMAP4,CN=Protocols,CN=[^,]+,CN=Servers,CN=[^,]+,CN=Administrative Groups,CN=[^,]+,CN=Microsoft Exchange,CN=Services$</relative_dn>
        <attribute>msExchSecureBindings</attribute>
      </object>
      <data>
        <adstype>ADSTYPE_INTEGER</adstype>
        <value datatype="int" operator="equals">993</value>
      </data>
    </activedirectory_test>
    <activedirectory_test id="wat-1250" comment="use TCP 143 for the IMAP4 service" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <naming_context>configuration</naming_context>
        <relative_dn operator="pattern match">^CN=[^,]+,CN=IMAP4,CN=Protocols,CN=[^,]+,CN=Servers,CN=[^,]+,CN=Administrative Groups,CN=[^,]+,CN=Microsoft Exchange,CN=Services$</relative_dn>
        <attribute>msExchServerBindings</attribute>
      </object>
      <data>
        <adstype>ADSTYPE_INTEGER</adstype>
        <value datatype="int" operator="equals">143</value>
      </data>
    </activedirectory_test>
    <activedirectory_test id="wat-1240" comment="use SSL when downloading meeting requests using IMAP4" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <naming_context>configuration</naming_context>
        <relative_dn operator="pattern match">^CN=[^,]+,CN=IMAP4,CN=Protocols,CN=[^,]+,CN=Servers,CN=[^,]+,CN=Administrative Groups,CN=[^,]+,CN=Microsoft Exchange,CN=Services$</relative_dn>
        <attribute>oWAServer</attribute>
      </object>
      <data>
        <adstype>ADSTYPE_PRINTABLE_STRING</adstype>
        <value operator="pattern match">^https\:\/\/</value>
      </data>
    </activedirectory_test>
    <activedirectory_test id="wat-1202" comment="allow simple authentication and security layer (SASL) to connect to the IMAP4 service" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <naming_context>configuration</naming_context>
        <relative_dn operator="pattern match">^CN=[^,]+,CN=IMAP4,CN=Protocols,CN=[^,]+,CN=Servers,CN=[^,]+,CN=Administrative Groups,CN=[^,]+,CN=Microsoft Exchange,CN=Services$</relative_dn>
        <attribute>msExchAuthenticationFlags</attribute>
      </object>
      <data>
        <adstype>ADSTYPE_INTEGER</adstype>
        <value datatype="int" operator="bitwise and">4</value>
      </data>
    </activedirectory_test>
    <activedirectory_test id="wat-1201" comment="require TSL encryption to connect to the IMAP4 service" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <naming_context>configuration</naming_context>
        <relative_dn operator="pattern match">^CN=[^,]+,CN=IMAP4,CN=Protocols,CN=[^,]+,CN=Servers,CN=[^,]+,CN=Administrative Groups,CN=[^,]+,CN=Microsoft Exchange,CN=Services$</relative_dn>
        <attribute>attribute>msExchOtherAuthenticationFlags</attribute>
      </object>
      <data>
        <adstype>ADSTYPE_INTEGER</adstype>
        <value datatype="int" operator="bitwise and">1</value>
      </data>
    </activedirectory_test>
    <activedirectory_test id="wat-1200" comment="allow basic authentication to connect to the IMAP4 service" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <naming_context>configuration</naming_context>
        <relative_dn operator="pattern match">^CN=[^,]+,CN=IMAP4,CN=Protocols,CN=[^,]+,CN=Servers,CN=[^,]+,CN=Administrative Groups,CN=[^,]+,CN=Microsoft Exchange,CN=Services$</relative_dn>
        <attribute>msExchAuthenticationFlags</attribute>
      </object>
      <data>
        <adstype>ADSTYPE_INTEGER</adstype>
        <value datatype="int" operator="bitwise and">2</value>
      </data>
    </activedirectory_test>
    <activedirectory_test id="wat-1190" comment="disable all automated message generation on the default domain" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <naming_context>configuration</naming_context>
        <relative_dn operator="pattern match">^CN=Default,CN=Internet Message Formats,CN=Global Settings,CN=[^,]+,CN=Microsoft Exchange,CN=Services$</relative_dn>
        <attribute>msExchRoutingAcceptMessageType</attribute>
      </object>
      <data>
        <adstype>ADSTYPE_INTEGER</adstype>
        <value datatype="int" operator="equals">0</value>
      </data>
    </activedirectory_test>
    <activedirectory_test id="wat-1185" comment="zero out deleted database pages" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <naming_context>configuration</naming_context>
        <relative_dn operator="pattern match">^CN=[^,]*,CN=InformationStore,CN=[^,]*,CN=Servers,CN=[^,]*,CN=Administrative Groups,CN=[^,]*,CN=Microsoft Exchange,CN=Services$</relative_dn>
        <attribute>msExchESEParamZeroDatabaseDuringBackup</attribute>
      </object>
      <data>
        <adstype>ADSTYPE_INTEGER</adstype>
        <value datatype="int" operator="bitwise and">1</value>
      </data>
    </activedirectory_test>
    <activedirectory_test id="wat-1173" comment="allow directory browsing in the Public HTTP virtual directories" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <naming_context>configuration</naming_context>
        <relative_dn operator="pattern match">^Public,CN=[^,]+,CN=HTTP,CN=Protocols,CN=[^,]+,CN=Servers,CN=[^,]+,CN=Administrative Groups,CN=[^,]+,CN=Microsoft Exchange,CN=Services$</relative_dn>
        <attribute>msExchDirBrowseFlags</attribute>
      </object>
      <data>
        <adstype>ADSTYPE_INTEGER</adstype>
        <value datatype="int" operator="bitwise and">2147483648</value>
      </data>
    </activedirectory_test>
    <activedirectory_test id="wat-1172" comment="allow script source access to the Public HTTP virtual directories" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <naming_context>configuration</naming_context>
        <relative_dn operator="pattern match">^Public,CN=[^,]+,CN=HTTP,CN=Protocols,CN=[^,]+,CN=Servers,CN=[^,]+,CN=Administrative Groups,CN=[^,]+,CN=Microsoft Exchange,CN=Services$</relative_dn>
        <attribute>msExchAccessFlags</attribute>
      </object>
      <data>
        <adstype>ADSTYPE_INTEGER</adstype>
        <value datatype="int" operator="bitwise and">16</value>
      </data>
    </activedirectory_test>
    <activedirectory_test id="wat-1171" comment="allow write access to the Public HTTP virtual directories" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <naming_context>configuration</naming_context>
        <relative_dn operator="pattern match">^Public,CN=[^,]+,CN=HTTP,CN=Protocols,CN=[^,]+,CN=Servers,CN=[^,]+,CN=Administrative Groups,CN=[^,]+,CN=Microsoft Exchange,CN=Services$</relative_dn>
        <attribute>msExchAccessFlags</attribute>
      </object>
      <data>
        <adstype>ADSTYPE_INTEGER</adstype>
        <value datatype="int" operator="bitwise and">2</value>
      </data>
    </activedirectory_test>
    <activedirectory_test id="wat-1170" comment="allow read access to the Public HTTP virtual directories" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <naming_context>configuration</naming_context>
        <relative_dn operator="pattern match">^Public,CN=[^,]+,CN=HTTP,CN=Protocols,CN=[^,]+,CN=Servers,CN=[^,]+,CN=Administrative Groups,CN=[^,]+,CN=Microsoft Exchange,CN=Services$</relative_dn>
        <attribute>msExchAccessFlags</attribute>
      </object>
      <data>
        <adstype>ADSTYPE_INTEGER</adstype>
        <value datatype="int" operator="bitwise and">1</value>
      </data>
    </activedirectory_test>
    <activedirectory_test id="wat-1160" comment="allow script execute permissions to the Public HTTP virtual directory" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <naming_context>configuration</naming_context>
        <relative_dn operator="pattern match">^CN=Public,CN=[^,]+,CN=HTTP,CN=Protocols,CN=[^,]*,CN=Servers,CN=[^,]*,CN=Administrative Groups,CN=[^,]*,CN=Microsoft Exchange,CN=Services$</relative_dn>
        <attribute>msExchAccessFlags</attribute>
      </object>
      <data>
        <adstype>ADSTYPE_INTEGER</adstype>
        <value datatype="int" operator="bitwise and">512</value>
      </data>
    </activedirectory_test>
    <activedirectory_test id="wat-1150" comment="only allow integrated windows authentication (NTLM) to connect to the Public HTTP virtual directories" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <naming_context>configuration</naming_context>
        <relative_dn operator="pattern match">^Public,CN=[^,]+,CN=HTTP,CN=Protocols,CN=[^,]+,CN=Servers,CN=[^,]+,CN=Administrative Groups,CN=[^,]+,CN=Microsoft Exchange,CN=Services$</relative_dn>
        <attribute>msExchAuthenticationFlags</attribute>
      </object>
      <data>
        <adstype>ADSTYPE_INTEGER</adstype>
        <value datatype="int" operator="equals">4</value>
      </data>
    </activedirectory_test>
    <activedirectory_test id="wat-1140" comment="enable forms based authentication" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <naming_context>configuration</naming_context>
        <relative_dn operator="pattern match">^CN=[^,]+,CN=HTTP,CN=Protocols,CN=[^,]+,CN=Servers,CN=[^,]+,CN=Administrative Groups,CN=[^,]+,CN=Microsoft Exchange,CN=Services$</relative_dn>
        <attribute>msExchDS2MBOptions</attribute>
      </object>
      <data>
        <adstype>ADSTYPE_INTEGER</adstype>
        <value datatype="int" operator="bitwise and">64</value>
      </data>
    </activedirectory_test>
    <activedirectory_test id="wat-1040" comment="Display the administrative groups in the Exchange System Manager" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <naming_context>configuration</naming_context>
        <relative_dn operator="pattern match">^CN=[^,]*,CN=Microsoft Exchange,CN=Services$</relative_dn>
        <attribute>msExchAdminGroupsEnabled</attribute>
      </object>
      <data>
        <adstype>ADSTYPE_INTEGER</adstype>
        <value datatype="int" operator="equals">1</value>
      </data>
    </activedirectory_test>
    <activedirectory_test id="wat-1030" comment="Display the routing groups in the Exchange System Manager" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <naming_context>configuration</naming_context>
        <relative_dn operator="pattern match">^CN=[^,]+,CN=Microsoft Exchange,CN=Services$</relative_dn>
        <attribute>msExchRoutingEnabled</attribute>
      </object>
      <data>
        <adstype>ADSTYPE_INTEGER</adstype>
        <value datatype="int" operator="equals">1</value>
      </data>
    </activedirectory_test>
    <activedirectory_test id="wat-863" comment="allow directory browsing in the Exchange HTTP virtual directories" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <naming_context>configuration</naming_context>
        <relative_dn operator="pattern match">^Exchange,CN=[^,]+,CN=HTTP,CN=Protocols,CN=[^,]+,CN=Servers,CN=[^,]+,CN=Administrative Groups,CN=[^,]+,CN=Microsoft Exchange,CN=Services$</relative_dn>
        <attribute>msExchDirBrowseFlags</attribute>
      </object>
      <data>
        <adstype>ADSTYPE_INTEGER</adstype>
        <value datatype="int" operator="bitwise and">2147483648</value>
      </data>
    </activedirectory_test>
    <activedirectory_test id="wat-862" comment="allow script source access to the Exchange HTTP virtual directories" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <naming_context>configuration</naming_context>
        <relative_dn operator="pattern match">^Exchange,CN=[^,]+,CN=HTTP,CN=Protocols,CN=[^,]+,CN=Servers,CN=[^,]+,CN=Administrative Groups,CN=[^,]+,CN=Microsoft Exchange,CN=Services$</relative_dn>
        <attribute>msExchAccessFlags</attribute>
      </object>
      <data>
        <adstype>ADSTYPE_INTEGER</adstype>
        <value datatype="int" operator="bitwise and">16</value>
      </data>
    </activedirectory_test>
    <activedirectory_test id="wat-861" comment="allow write access to the Exchange HTTP virtual directories" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <naming_context>configuration</naming_context>
        <relative_dn operator="pattern match">^Exchange,CN=[^,]+,CN=HTTP,CN=Protocols,CN=[^,]+,CN=Servers,CN=[^,]+,CN=Administrative Groups,CN=[^,]+,CN=Microsoft Exchange,CN=Services$</relative_dn>
        <attribute>msExchAccessFlags</attribute>
      </object>
      <data>
        <adstype>ADSTYPE_INTEGER</adstype>
        <value datatype="int" operator="bitwise and">2</value>
      </data>
    </activedirectory_test>
    <activedirectory_test id="wat-860" comment="allow read access to the Exchange HTTP virtual directories" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <naming_context>configuration</naming_context>
        <relative_dn operator="pattern match">^Exchange,CN=[^,]+,CN=HTTP,CN=Protocols,CN=[^,]+,CN=Servers,CN=[^,]+,CN=Administrative Groups,CN=[^,]+,CN=Microsoft Exchange,CN=Services$</relative_dn>
        <attribute>msExchAccessFlags</attribute>
      </object>
      <data>
        <adstype>ADSTYPE_INTEGER</adstype>
        <value datatype="int" operator="bitwise and">1</value>
      </data>
    </activedirectory_test>
    <activedirectory_test id="wat-850" comment="only allow integrated windows authentication (NTLM) to connect to the Exchange HTTP virtual directories" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <naming_context>configuration</naming_context>
        <relative_dn operator="pattern match">^Exchange,CN=[^,]+,CN=HTTP,CN=Protocols,CN=[^,]+,CN=Servers,CN=[^,]+,CN=Administrative Groups,CN=[^,]+,CN=Microsoft Exchange,CN=Services$</relative_dn>
        <attribute>msExchAuthenticationFlags</attribute>
      </object>
      <data>
        <adstype>ADSTYPE_INTEGER</adstype>
        <value datatype="int" operator="equals">4</value>
      </data>
    </activedirectory_test>
    <activedirectory_test id="wat-140" comment="allow script execute permissions to Exchange HTTP virtual directories" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <naming_context>configuration</naming_context>
        <relative_dn operator="pattern match">^CN=Exchange,CN=[^,]+,CN=HTTP,CN=Protocols,CN=[^,]*,CN=Servers,CN=[^,]*,CN=Administrative Groups,CN=[^,]*,CN=Microsoft Exchange,CN=Services$</relative_dn>
        <attribute>msExchAccessFlags</attribute>
      </object>
      <data>
        <adstype>ADSTYPE_INTEGER</adstype>
        <value datatype="int" operator="bitwise and">512</value>
      </data>
    </activedirectory_test>
    <file_test id="wft-390" comment="the version of hhctrl.ocx is less than 5.2.3790.233" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\hhctrl.ocx</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>2</minor>
          <build>3790</build>
          <private>233</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-93" comment="the patch kb890175 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB890175</key>
        <name operator="equals">Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <inetlisteningservers_test id="rlt-5" comment="radiusd is listening on the network" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <program_name operator="pattern match">.*/radiusd</program_name>
      </object>
      <data operation="AND">
        <local_port operator="equals">1812</local_port>
        <protocol operator="equals">udp</protocol>
      </data>
    </inetlisteningservers_test>
    <rpmversioncompare_test id="rvt-2" comment="FreeRADIUS rpm older than 1.0.1-1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="binary" operator="equals">FreeRADIUS</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">1.0.1</tested_version>
        <tested_release operator="equals">1</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <registry_test id="wrt-492" comment="Patch IE-KB841873-WindowsNT4sp6-x86-ENU.exe Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Active Setup\Installed Components\{bfb56e60-5895-496c-bd6b-459b97142e4c}</key>
        <name>IsInstalled</name>
      </object>
      <data operation="AND">
        <value datatype="binary" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-457" comment="the version of mstask.dll is less than 4.71.1979.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mstask.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>4</major>
          <minor>71</minor>
          <build>1979</build>
          <private>1</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-156" comment="the patch kb834707(wildcard*) is installed (Hotfix key)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="pattern match">^SOFTWARE\\Microsoft\\Windows\ NT\\CurrentVersion\\Hotfix\\[Kk][Bb]834707[-a-zA-Z0-9.]*$</key>
        <name operator="equals">Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <compound_test id="cmp-258" comment="Check for Drag&amp;Drop enabled and the patch kb834707(wildcard*)  missing" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="true" test_ref="wrt-157"/>
      <subtest negate="true" test_ref="wrt-156"/>
    </compound_test>
    <file_test id="wft-405" comment="the version of mshtml.dll is less than 6.0.3790.259" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mshtml.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>3790</build>
          <private>259</private>
        </version>
      </data>
    </file_test>
    <swlist_test id="hst-84" comment="WUFTP-26.INETSVCS-FTP with version less than B.11.11.01.006 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <swlist operator="equals">WUFTP-26.INETSVCS-FTP</swlist>
      </object>
      <data>
        <version operator="pattern match">B\.11\.11\.(00.*|01\.00[0-5])</version>
      </data>
    </swlist_test>
    <patch_test id="hpt-65" comment="Patch PHNE_34543 or subsequent is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <area_patched>PHNE</area_patched>
        <patch_number operator="greater than or equal">34543</patch_number>
      </object>
    </patch_test>
    <swlist_test id="hst-62" comment="InternetSrvcs.INETSVCS-RUN is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <swlist operator="equals">InternetSrvcs.INETSVCS-RUN</swlist>
      </object>
    </swlist_test>
    <compound_test id="cmp-825" comment="INETSVCS-RUN without patch PHNE_34543 or later" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="hst-62"/>
      <subtest negate="true" test_ref="hpt-65"/>
    </compound_test>
    <compound_test id="cmp-826" comment="INETSVCS-RUN without patch PHNE_34543 or later, OR WUFTP-26.INETSVCS-FTP with version less than B.11.11.01.006 is installed" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="cmp-825"/>
      <subtest test_ref="hst-84"/>
    </compound_test>
    <file_test id="wft-433" comment="the version of cryptdlg.dll is less than 5.0.1558.6608" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\cryptdlg.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>1558</build>
          <private>6608</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-571" comment="the version of winword.exe is less than 9.0.0.8930" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Winword.exe\Path</component>
          <component type="literal">winword.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>9</major>
          <minor>0</minor>
          <build>0</build>
          <private>8930</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-549" comment="the patch KB824151 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key datatype="string" operator="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB824151</key>
        <name datatype="string" operator="equals">Installed</name>
      </object>
      <data operation="AND">
        <value datatype="string" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-501" comment="the version of httpext.dll is less than 5.0.2195.6958" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\inetsrv\httpext.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>2195</build>
          <private>6958</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-1107" comment="Windows 2000 (sp5 or earlier) is installed" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-1"/>
      <subtest negate="true" test_ref="wrt-539"/>
    </compound_test>
    <file_test id="wft-675" comment="umpnpmgr.dll is less than 5.1.2600.1734" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\umpnpmgr.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>1734</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-786" comment="the version of msadco.dll is less than 2.80.1062.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir</component>
          <component type="literal">\Common Files\System\msadc\msadco.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>2</major>
          <minor>80</minor>
          <build>1062</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-146" comment="The version of Ntoskrnl.exe is less than 4.0.1381.7268" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\System32\Ntoskrnl.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>4</major>
          <minor>0</minor>
          <build>1381</build>
          <private>7268</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-736" comment="the version of Mdbmsg.dll is less than 5.0.1462.22" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Exchange\Setup\Services</component>
          <component type="literal">\RES\Mdbmsg.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>1462</build>
          <private>22</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-738" comment="the version of Mdbmsg.dll greater than or equal 5.0.1460.9 (Exchange Server 5.0,SP2 is installed)." check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Exchange\Setup\Services</component>
          <component type="literal">\RES\Mdbmsg.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="greater than or equal">
          <major>5</major>
          <minor>0</minor>
          <build>1460</build>
          <private>9</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-759" comment="the version of Tcpip.sys is less than 5.2.3790.468 (S03-Gold)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\drivers\tcpip.sys</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>2</minor>
          <build>3790</build>
          <private>468</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-407" comment="the version of mshtml.dll is less than 5.0.3825.700" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mshtml.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>3825</build>
          <private>700</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-178" comment=".wmz EXISTS" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">\SOFTWARE\Classes\.wmz</key>
        <name operator="pattern match">.*</name>
      </object>
    </registry_test>
    <registry_test id="wrt-177" comment=".wms EXISTS" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">\SOFTWARE\Classes\.wms</key>
        <name operator="pattern match">.*</name>
      </object>
    </registry_test>
    <registry_test id="wrt-176" comment=".wmx EXISTS" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">\SOFTWARE\Classes\.wmx</key>
        <name operator="pattern match">.*</name>
      </object>
    </registry_test>
    <registry_test id="wrt-175" comment=".wpl EXISTS" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">\SOFTWARE\Classes\.wpl</key>
        <name operator="pattern match">.*</name>
      </object>
    </registry_test>
    <registry_test id="wrt-174" comment=".wvx EXISTS" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">\SOFTWARE\Classes\.wvx</key>
        <name operator="pattern match">.*</name>
      </object>
    </registry_test>
    <registry_test id="wrt-169" comment=".wax EXISTS" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">\SOFTWARE\Classes\.wax</key>
        <name operator="pattern match">.*</name>
      </object>
    </registry_test>
    <registry_test id="wrt-168" comment=".asx EXISTS" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">\SOFTWARE\Classes\.asx</key>
        <name operator="pattern match">.*</name>
      </object>
    </registry_test>
    <compound_test id="cmp-188" comment="The files .asx, .wax, .wvx, .wpl, .wmx, .wms, .wmz EXIST" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-168"/>
      <subtest negate="false" test_ref="wrt-169"/>
      <subtest negate="false" test_ref="wrt-174"/>
      <subtest negate="false" test_ref="wrt-175"/>
      <subtest negate="false" test_ref="wrt-176"/>
      <subtest negate="false" test_ref="wrt-177"/>
      <subtest negate="false" test_ref="wrt-178"/>
    </compound_test>
    <registry_test id="wrt-84" comment="The patch KB885492 is installed on Windows XP" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">SOFTWARE\Microsoft\Updates\Windows Media Player 9\SP0\KB885492</key>
        <name operator="equals">PackageVersion</name>
      </object>
      <data operation="AND">
        <value operator="equals">1.1</value>
      </data>
    </registry_test>
    <file_test id="wft-374" comment="the version of wmp.dll is les than 9.0.0.3250" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\wmp.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>9</major>
          <minor>0</minor>
          <build>0</build>
          <private>3250</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-82" comment="Windows Media Player 9.0 installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">SOFTWARE\Microsoft\MediaPlayer\9.0\Registration</key>
        <name operator="equals">UDBVersion</name>
      </object>
      <data operation="AND">
        <value operator="equals">9.00.00.2980</value>
      </data>
    </registry_test>
    <file_test id="wft-354" comment="the version of user32.dll is less than 5.1.2600.1617" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\user32.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>1617</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-61" comment="Windows XP SP1 OR Windows XP 64-bit SP1 is installed" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-57"/>
      <subtest negate="false" test_ref="cmp-1066"/>
    </compound_test>
    <file_test id="wft-706" comment="the version of mshtml.dll is less than 6.0.2900.2802" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mshtml.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>2900</build>
          <private>2802</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-294" comment="for 64-bit (x64 arch) Windows (gold edition) a vulnerable version of tapisrv.dll exists" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-22"/>
      <subtest negate="true" test_ref="wrt-3"/>
      <subtest negate="false" test_ref="wft-617"/>
    </compound_test>
    <compound_test id="cmp-302" comment="for 32-bit or 64-bit (itanium architecture) Windows with SP1 a vulnerable version of tapisrv.dll exists" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-23"/>
      <subtest negate="false" test_ref="wrt-4"/>
      <subtest negate="false" test_ref="wft-617"/>
    </compound_test>
    <file_test id="wft-618" comment="the version of tapisrv.dll is less than 5.2.3790.366" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\tapisrv.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>2</minor>
          <build>3790</build>
          <private>366</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-300" comment="for 32-bit or 64-bit (itanium architecture) Windows gold edition a vulnerable version of tapisrv.dll exists" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-23"/>
      <subtest negate="true" test_ref="wrt-3"/>
      <subtest negate="false" test_ref="wft-618"/>
    </compound_test>
    <compound_test id="cmp-303" comment="a vulnerable version of tapisrv.dll exists" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-300"/>
      <subtest negate="false" test_ref="cmp-302"/>
      <subtest negate="false" test_ref="cmp-294"/>
    </compound_test>
    <registry_test id="wrt-24" comment="the patch kb889293 is installed " check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB889293</key>
        <name operator="equals">IsInstalled</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <registry_test id="wrt-23" comment="the patch kb889293 is installed (Installed Components key)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">SOFTWARE\Microsoft\Active Setup\Installed Components\{839117ee-2132-4bae-a56a-42b50204c9b9}</key>
        <name operator="equals">IsInstalled</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <compound_test id="cmp-25" comment="patch kb889293 is installed (hotfix or ID)" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-23"/>
      <subtest negate="false" test_ref="wrt-24"/>
    </compound_test>
    <file_test id="wft-692" comment="netman.dll is less than 5.0.2195.7061" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\netman.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>2195</build>
          <private>7061</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-593" comment="the version of Tcpip.sys is less than 5.0.2195.7035" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\tcpip.sys</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>2195</build>
          <private>7035</private>
        </version>
      </data>
    </file_test>
    <swlist_test id="hst-32" comment="Mozilla v1.7.12 (1.7.12.0.00) or later is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <swlist operator="equals">Mozilla.MOZ-COM</swlist>
      </object>
      <data>
        <version operator="pattern match">((1\.7\.12\..*)|(1\.(([8-9])|(\d{2,}))\..*)|(1\.7\.((1[3-9])|([2-9]\d+))\..*))</version>
      </data>
    </swlist_test>
    <swlist_test id="hst-31" comment="Mozilla is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <swlist operator="equals">Mozilla.MOZ-COM</swlist>
      </object>
    </swlist_test>
    <compound_test id="cmp-689" comment="800 Series OS Release 11.22" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-11"/>
      <subtest test_ref="uut-22"/>
    </compound_test>
    <uname_test id="uut-22" comment="HP Release B.11.22" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <data operation="AND">
        <os_name operator="equals">HP-UX</os_name>
        <os_release operator="equals">B.11.22</os_release>
      </data>
    </uname_test>
    <compound_test id="cmp-688" comment="700 Series OS Release 11.22" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-10"/>
      <subtest test_ref="uut-22"/>
    </compound_test>
    <compound_test id="cmp-690" comment="700 Series or 800 Series OS Release 11.22" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="cmp-688"/>
      <subtest test_ref="cmp-689"/>
    </compound_test>
    <compound_test id="cmp-691" comment="700 Series or 800 Series OS Release 11.00, 11.11, 11.22, or 11.23" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="cmp-619"/>
      <subtest test_ref="cmp-618"/>
      <subtest test_ref="cmp-690"/>
      <subtest test_ref="cmp-682"/>
    </compound_test>
    <file_test id="wft-691" comment="msieftp.dll is less than 6.0.3790.383" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\msieftp.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>3790</build>
          <private>383</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-396" comment="the version of mscms.dll is less than 5.0.2195.7054" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mscms.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>2195</build>
          <private>7054</private>
        </version>
      </data>
    </file_test>
    <patch_test id="hpt-4" comment="Patch PHNE_23949 or later is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <area_patched>PHNE</area_patched>
        <patch_number operator="greater than or equal">23949</patch_number>
      </object>
    </patch_test>
    <inetd_test id="sit-210" comment="Sadmin called using strong authentication" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <server_program datatype="string" operator="equals">/usr/sbin/sadmind</server_program>
      </object>
      <data operation="AND">
        <server_arguments datatype="string" operator="equals">-S 2</server_arguments>
      </data>
    </inetd_test>
    <patch_test id="spt-261" comment="Patch 116454-01 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">116454</base>
      </object>
      <data operation="AND">
        <version datatype="string" operator="greater than or equal">01</version>
      </data>
    </patch_test>
    <patch_test id="spt-260" comment="Patch 116442-01 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">116442</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">01</version>
      </data>
    </patch_test>
    <patch_test id="spt-259" comment="Patch 116457-02 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">116457</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">02</version>
      </data>
    </patch_test>
    <inetd_test id="sit-209" comment="inetd.conf contains sadmind" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <server_program datatype="string" operator="equals">/usr/sbin/sadmind</server_program>
      </object>
    </inetd_test>
    <package_test id="sat-7" comment="System and Network Administration Framework Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <pkginst datatype="string" operator="equals">SUNWadmfw</pkginst>
      </object>
    </package_test>
    <file_test id="wft-583" comment="The version of Ntoskrnl.exe is less than 5.2.3790.280" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\System32\Ntoskrnl.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>2</minor>
          <build>3790</build>
          <private>280</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-644" comment="the version of Quartz.dll is less than 6.1.9.732" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\Quartz.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>1</minor>
          <build>9</build>
          <private>732</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-643" comment="the version of Quartz.dll is greater than or equal to 6.1.9.726" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\Quartz.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="greater than or equal">
          <major>6</major>
          <minor>1</minor>
          <build>9</build>
          <private>726</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-600" comment="DirectX packaged with Windows 2000,SP4 has DirectShow Vulnerability" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="wrt-1"/>
      <subtest test_ref="wrt-222"/>
      <subtest test_ref="wft-643"/>
      <subtest test_ref="wft-644"/>
    </compound_test>
    <patch_test id="hpt-63" comment="Patch PHNE_34306 or subsequent is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <area_patched>PHNE</area_patched>
        <patch_number operator="greater than or equal">34306</patch_number>
      </object>
    </patch_test>
    <file_test id="wft-480" comment="The version of Ntoskrnl.exe is less than 5.1.2600.1151" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path>
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\System32\Ntoskrnl.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version>
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>1151</private>
        </version>
      </data>
    </file_test>
    <swlist_test id="hst-35" comment="Secure_Shell.SECURE_SHELL with version less than A.04.20.005 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <swlist operator="equals">Secure_Shell.SECURE_SHELL</swlist>
      </object>
      <data>
        <version operator="pattern match">A(\.0[0-3]\..*|\.04\.[0-1].*|\.04\.20\.00[0-4])</version>
      </data>
    </swlist_test>
    <swlist_test id="hst-36" comment="Secure_Shell.SECURE_SHELL is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <swlist operator="equals">Secure_Shell.SECURE_SHELL</swlist>
      </object>
    </swlist_test>
    <file_test id="wft-744" comment="the version of Wmpui.dll is less than 8.0.0.4495" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\Wmpui.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>8</major>
          <minor>0</minor>
          <build>0</build>
          <private>4495</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-645" comment="Windows Media Player 8 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\MediaPlayer\8.0\Registration</key>
        <name>UDBVersion</name>
      </object>
      <data operation="AND">
        <value operator="pattern match">8\.0\.*</value>
      </data>
    </registry_test>
    <file_test id="wft-167" comment="the version of webclnt.dll is less than 5.2.3790.1673" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\webclnt.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>2</minor>
          <build>3790</build>
          <private>1673</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-693" comment="netman.dll is less than 5.1.2600.1733" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\netman.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>1733</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-695" comment="netman.dll is less than 5.2.3790.396" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\netman.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>2</minor>
          <build>3790</build>
          <private>396</private>
        </version>
      </data>
    </file_test>
    <patch_test id="hpt-39" comment="Patch PHSS_34123 or later is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <area_patched>PHSS</area_patched>
        <patch_number operator="greater than or equal">34123</patch_number>
      </object>
    </patch_test>
    <swlist_test id="hst-69" comment="VirusVault is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <swlist operator="equals">VaultWS.WS-CORE</swlist>
      </object>
    </swlist_test>
    <permission_test id="upt-59" comment="/usr/bin/gedit is executable" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/gedit</component>
        </path>
      </object>
      <data operation="OR">
        <gexec datatype="boolean" operator="equals">1</gexec>
        <oexec datatype="boolean" operator="equals">1</oexec>
        <uexec datatype="boolean" operator="equals">1</uexec>
      </data>
    </permission_test>
    <rpmversioncompare_test id="rvt-25" comment="gedit RPM earlier than 1:2.2.2-4rhel3" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name operator="equals">gedit</name>
        <tested_epoch operator="equals">1</tested_epoch>
        <tested_version operator="equals">2.2.2</tested_version>
        <tested_release operator="equals">4rhel3</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <file_test id="wft-674" comment="umpnpmgr.dll is less than 5.0.2195.7069" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\umpnpmgr.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>2195</build>
          <private>7069</private>
        </version>
      </data>
    </file_test>
    <permission_test id="upt-60" comment="/usr/bin/sudo is executable by everyone" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/sudo</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="boolean" operator="equals">1</oexec>
      </data>
    </permission_test>
    <file_test id="uft-3" comment="/etc/sudoers exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/etc/sudoers</component>
        </path>
      </object>
    </file_test>
    <rpmversioncompare_test id="rvt-26" comment="sudo RPM earlier than 0:1.6.7p5-1.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name operator="equals">sudo</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">1.6.7p5</tested_version>
        <tested_release operator="equals">1.1</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <file_test id="wft-712" comment="the version of wordpad.exe is less than 5.0.2195.6991" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir</component>
          <component type="literal">\Windows NT\Accessories\wordpad.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>2195</build>
          <private>6991</private>
        </version>
      </data>
    </file_test>
    <patch_test id="hpt-29" comment="Patch PHSS_34204 or subsequent is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <area_patched>PHSS</area_patched>
        <patch_number operator="greater than or equal">34204</patch_number>
      </object>
    </patch_test>
    <swlist_test id="hst-78" comment="HP_Webproxy.HPWEB-PX-CORE A.02.00 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <swlist operator="equals">HP_Webproxy.HPWEB-PX-CORE</swlist>
      </object>
      <data>
        <version operator="equals">A.02.00</version>
      </data>
    </swlist_test>
    <compound_test id="cmp-790" comment="HP_Webproxy.HPWEB-PX-CORE A.02.00 is installed without patch PHSS_34204 or later" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="cmp-674"/>
      <subtest test_ref="hst-78"/>
      <subtest negate="true" test_ref="hpt-29"/>
    </compound_test>
    <patch_test id="hpt-28" comment="Patch PHSS_34203 or subsequent is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <area_patched>PHSS</area_patched>
        <patch_number operator="greater than or equal">34203</patch_number>
      </object>
    </patch_test>
    <swlist_test id="hst-77" comment="HP_Webproxy.HPWEB-PX-CORE A.02.10 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <swlist operator="equals">HP_Webproxy.HPWEB-PX-CORE</swlist>
      </object>
      <data>
        <version operator="equals">A.02.10</version>
      </data>
    </swlist_test>
    <compound_test id="cmp-789" comment="HP_Webproxy.HPWEB-PX-CORE A.02.10 is installed without patch PHSS_34203 or later" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="cmp-674"/>
      <subtest test_ref="hst-77"/>
      <subtest negate="true" test_ref="hpt-28"/>
    </compound_test>
    <patch_test id="hpt-49" comment="Patch PHSS_34119 or subsequent is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <area_patched>PHSS</area_patched>
        <patch_number operator="greater than or equal">34119</patch_number>
      </object>
    </patch_test>
    <swlist_test id="hst-76" comment="VirtualvaultWS A.04.50 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <swlist operator="equals">VaultWS.WS-CORE</swlist>
      </object>
      <data>
        <version operator="equals">A.04.50</version>
      </data>
    </swlist_test>
    <compound_test id="cmp-788" comment="VirtualvaultWS A.04.50 is installed without patch PHSS_34119 or later" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="cmp-674"/>
      <subtest test_ref="hst-76"/>
      <subtest negate="true" test_ref="hpt-49"/>
    </compound_test>
    <patch_test id="hpt-48" comment="Patch PHSS_34171 or subsequent is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <area_patched>PHSS</area_patched>
        <patch_number operator="greater than or equal">34171</patch_number>
      </object>
    </patch_test>
    <swlist_test id="hst-75" comment="VirtualvaultTS A.04.50 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <swlist operator="equals">VaultTS.VV-IWS</swlist>
      </object>
      <data>
        <version operator="equals">A.04.50</version>
      </data>
    </swlist_test>
    <compound_test id="cmp-787" comment="VirtualvaultTS A.04.50 is installed without patch PHSS_34171 or later" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="cmp-674"/>
      <subtest test_ref="hst-75"/>
      <subtest negate="true" test_ref="hpt-48"/>
    </compound_test>
    <patch_test id="hpt-47" comment="Patch PHSS_34120 or subsequent is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <area_patched>PHSS</area_patched>
        <patch_number operator="greater than or equal">34120</patch_number>
      </object>
    </patch_test>
    <swlist_test id="hst-74" comment="VirtualvaultWS A.04.60 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <swlist operator="equals">VaultWS.WS-CORE</swlist>
      </object>
      <data>
        <version operator="equals">A.04.60</version>
      </data>
    </swlist_test>
    <compound_test id="cmp-786" comment="VirtualvaultWS A.04.60 is installed without patch PHSS_34120 or later" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="cmp-674"/>
      <subtest test_ref="hst-74"/>
      <subtest negate="true" test_ref="hpt-47"/>
    </compound_test>
    <patch_test id="hpt-46" comment="Patch PHSS_34170 or subsequent is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <area_patched>PHSS</area_patched>
        <patch_number operator="greater than or equal">34170</patch_number>
      </object>
    </patch_test>
    <swlist_test id="hst-73" comment="VirtualvaultTS A.04.60 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <swlist operator="equals">VaultTS.VV-IWS</swlist>
      </object>
      <data>
        <version operator="equals">A.04.60</version>
      </data>
    </swlist_test>
    <compound_test id="cmp-785" comment="VirtualvaultTS A.04.60 is installed without patch PHSS_34170 or later" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="cmp-674"/>
      <subtest test_ref="hst-73"/>
      <subtest negate="true" test_ref="hpt-46"/>
    </compound_test>
    <patch_test id="hpt-45" comment="Patch PHSS_34121 or subsequent is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <area_patched>PHSS</area_patched>
        <patch_number operator="greater than or equal">34121</patch_number>
      </object>
    </patch_test>
    <swlist_test id="hst-72" comment="VirtualvaultWS A.04.70 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <swlist operator="equals">VaultWS.WS-CORE</swlist>
      </object>
      <data>
        <version operator="equals">A.04.70</version>
      </data>
    </swlist_test>
    <compound_test id="cmp-784" comment="VirtualvaultWS A.04.70 is installed without patch PHSS_34121 or later" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="cmp-674"/>
      <subtest test_ref="hst-72"/>
      <subtest negate="true" test_ref="hpt-45"/>
    </compound_test>
    <swlist_test id="hst-71" comment="VirtualvaultTS A.04.70 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <swlist operator="equals">VaultTS.VV-IWS</swlist>
      </object>
      <data>
        <version operator="equals">A.04.70</version>
      </data>
    </swlist_test>
    <compound_test id="cmp-783" comment="VirtualvaultTS A.04.70 is installed without patch PHSS_34169 or later" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="cmp-674"/>
      <subtest test_ref="hst-71"/>
      <subtest negate="true" test_ref="hpt-44"/>
    </compound_test>
    <file_test id="wft-648" comment="the version of Quartz.dll is less than 6.5.2600.2749" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\Quartz.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>5</minor>
          <build>2600</build>
          <private>2749</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-647" comment="the version of Quartz.dll is greater than or equal to 6.5.2600.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\Quartz.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="greater than or equal">
          <major>6</major>
          <minor>5</minor>
          <build>2600</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-602" comment="DirectX packaged with Windows XP,SP2 has DirectShow Vulnerability" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="wrt-2"/>
      <subtest test_ref="wrt-250"/>
      <subtest test_ref="wft-647"/>
      <subtest test_ref="wft-648"/>
    </compound_test>
    <patch_test id="spt-47" comment="Patch 117767-02 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">117767</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">02</version>
      </data>
    </patch_test>
    <patch_test id="spt-46" comment="Patch 117765-02 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">117765</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">02</version>
      </data>
    </patch_test>
    <package_test id="sat-27" comment="Mozilla Mail (SUNWmozmail) installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <pkginst operator="equals">SUNWmozmail</pkginst>
      </object>
    </package_test>
    <package_test id="sat-26" comment="Mozilla (SUNWmoznav) installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <pkginst operator="equals">SUNWmoznav</pkginst>
      </object>
    </package_test>
    <compound_test id="cmp-72" comment="Mozilla components (any SUNWmoznav/SUNWmozmail) installed" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="sat-26"/>
      <subtest negate="false" test_ref="sat-27"/>
    </compound_test>
    <registry_test id="wrt-76" comment="the patch kb898458  is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">SOFTWARE\Microsoft\Updates\Step by Step Interactive Training\SP2\KB898458\Filelist</key>
        <name operator="pattern match">^.*$</name>
      </object>
    </registry_test>
    <file_test id="wft-155" comment="the version of Orun32.exe is less than 3.5.0.117" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\Help\SBSI\Training\Orun32.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>3</major>
          <minor>5</minor>
          <build>0</build>
          <private>117</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-75" comment="Microsoft Interactive Training is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <oval:notes>
        <oval:note>As stated in the iDefense security advisory, if this key exists and contains a value, then the system has Interactive Training installed, and it will process .cbo files.</oval:note>
      </oval:notes>
      <object>
        <hive operator="equals">HKEY_CLASSES_ROOT</hive>
        <key operator="equals">MITrain.Document\shell\open\command</key>
        <name operator="pattern match">.*</name>
      </object>
    </registry_test>
    <file_test id="wft-614" comment="the version of tapisrv.dll is less than 5.0.2195.7057" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\tapisrv.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>2195</build>
          <private>7057</private>
        </version>
      </data>
    </file_test>
    <patch_test id="hpt-9" comment="Patch PHNE_24394 or later is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <area_patched>PHNE</area_patched>
        <patch_number operator="greater than or equal">24395</patch_number>
      </object>
    </patch_test>
    <compound_test id="cmp-676" comment="800 Series OS Release 10.24" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-11"/>
      <subtest test_ref="uut-18"/>
    </compound_test>
    <uname_test id="uut-18" comment="HP Release B.10.24" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <data operation="AND">
        <os_name operator="equals">HP-UX</os_name>
        <os_release operator="equals">B.10.24</os_release>
      </data>
    </uname_test>
    <compound_test id="cmp-675" comment="700 Series OS Release 10.24" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-10"/>
      <subtest test_ref="uut-18"/>
    </compound_test>
    <compound_test id="cmp-677" comment="700 Series or 800 Series OS Release 10.24" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="cmp-675"/>
      <subtest test_ref="cmp-676"/>
    </compound_test>
    <file_test id="wft-671" comment="nwwks.dll is less than 5.1.2600.2736" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\nwwks.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>2736</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-785" comment="the version of msadco.dll is less than 2.81.1124.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir</component>
          <component type="literal">\Common Files\System\msadc\msadco.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>2</major>
          <minor>81</minor>
          <build>1124</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-358" comment="the version of rpcrt4.dll is less than 5.2.3790.76" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\rpcrt4.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>2</minor>
          <build>3790</build>
          <private>76</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-682" comment="cdoex.dll is less than 6.0.6617.86" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\cdoex.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>6617</build>
          <private>86</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-441" comment="the patch kb890923  is installed (Win2K SP3  Hotfix key)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB890923 -ie501sp3-20050225.100153</key>
        <name datatype="int" operator="equals">Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-598" comment="the version of mshtml.dll is less than 5.0.3539.2400" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mshtml.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>3539</build>
          <private>2400</private>
        </version>
      </data>
    </file_test>
    <rpmversioncompare_test id="rvt-12" comment="libgd-devel RPM is earlier than 0:1.8.4-12.3.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name operator="equals">libgd-devel</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">1.8.4</tested_version>
        <tested_release operator="equals">12.3.1</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <rpmversioncompare_test id="rvt-11" comment="libgd RPM is earlier than 0:1.8.4-12.3.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name operator="equals">libgd</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">1.8.4</tested_version>
        <tested_release operator="equals">12.3.1</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <compound_test id="cmp-260" comment="libgd or libgd-devel RPM is earlier than 0:1.8.4-12.3.1" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="rvt-11"/>
      <subtest negate="false" test_ref="rvt-12"/>
    </compound_test>
    <compound_test id="cmp-224" comment=" a vulnerable version of agentdpv exists for Windows Gold 64-bit (x64) " operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-22"/>
      <subtest negate="true" test_ref="wrt-3"/>
      <subtest negate="false" test_ref="wft-118"/>
    </compound_test>
    <compound_test id="cmp-222" comment=" a vulnerable version of agentdpv exists" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-72"/>
      <subtest negate="false" test_ref="wrt-250"/>
      <subtest negate="false" test_ref="wft-118"/>
    </compound_test>
    <compound_test id="cmp-218" comment=" a vulnerable version of agentdpv exists" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-23"/>
      <subtest negate="true" test_ref="wrt-29"/>
      <subtest negate="false" test_ref="wft-117"/>
    </compound_test>
    <compound_test id="cmp-225" comment=" a vulnerable version of agentdpv exists" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-218"/>
      <subtest negate="false" test_ref="cmp-222"/>
      <subtest negate="false" test_ref="cmp-224"/>
    </compound_test>
    <file_test id="wft-683" comment="shell32.dll is less than 5.0.3900.7071" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\shell32.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>3900</build>
          <private>7071</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-788" comment="the version of shell32.dll is less than 5.0.3900.7078" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\shell32.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>3900</build>
          <private>7078</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-368" comment="the version of winword.exe is less than 10.00.6764.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Winword.exe\Path</component>
          <component type="literal">winword.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>10</major>
          <minor>00</minor>
          <build>6764</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-729" comment="the version of T2embed.dll is less than 5.2.3790.2549" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\T2embed.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>2</minor>
          <build>3790</build>
          <private>2549</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-728" comment="the version of Fontsub.dll is less than 5.2.3790.2549" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\Fontsub.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>2</minor>
          <build>3790</build>
          <private>2549</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-710" comment="Fontsub.dll &lt; 5.2.3790.2549 or T2embed.dll &lt;5.2.3790.2549 (WinXP,64-bit and S03,SP1)" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="wft-728"/>
      <subtest test_ref="wft-729"/>
    </compound_test>
    <file_test id="wft-388" comment="the version of ole32.dll is less than 5.1.2600.2595" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\ole32.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>2595</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-778" comment="the version of mshtml.dll is less than 6.0.3790.507" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mshtml.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>3790</build>
          <private>507</private>
        </version>
      </data>
    </file_test>
    <rpmversioncompare_test id="rvt-14" comment="libxml-devel RPM is earlier than 1:1.8.17-9.2" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name operator="equals">libxml-devel</name>
        <tested_epoch operator="equals">1</tested_epoch>
        <tested_version operator="equals">1.8.17</tested_version>
        <tested_release operator="equals">9.2</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <rpmversioncompare_test id="rvt-13" comment="libxml RPM is earlier than 1:1.8.17-9.2" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name operator="equals">libxml</name>
        <tested_epoch operator="equals">1</tested_epoch>
        <tested_version operator="equals">1.8.17</tested_version>
        <tested_release operator="equals">9.2</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <compound_test id="cmp-261" comment="libxml or libxml-devel RPM is earlier than 1:1.8.17-9.2" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="rvt-13"/>
      <subtest negate="false" test_ref="rvt-14"/>
    </compound_test>
    <file_test id="wft-281" comment="the version of mswrd632.wpc is less than 2004.10.25.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir</component>
          <component type="literal">\Common Files\Microsoft Shared\TextConv\mswrd632.wpc</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>2004</major>
          <minor>10</minor>
          <build>25</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-25" comment="the patch kb885836 is installed (Hotfix key)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB885836</key>
        <name operator="equals">Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-735" comment="the version of msmapi32.dll is less than 10.0.6772.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir</component>
          <component type="literal">\Common Files\System\MAPI\1033\msmapi32.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="greater than">
          <major>10</major>
          <minor>0</minor>
          <build>6772</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-631" comment="Outlook 2002 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key datatype="string" operator="equals">SOFTWARE\Microsoft\Office\10.0\Outlook\InstallRoot</key>
        <name>Path</name>
      </object>
      <data operation="AND">
        <value operator="pattern match">.*OFFICE10.*</value>
      </data>
    </registry_test>
    <file_test id="wft-386" comment="the version of ole32.dll is less than 5.0.2195.7021" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\ole32.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>2195</build>
          <private>7021</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-769" comment="the version of excel.exe is less than 9.0.0.8938" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Excel.exe\Path</component>
          <component type="literal">excel.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>9</major>
          <minor>0</minor>
          <build>0</build>
          <private>8938</private>
        </version>
      </data>
    </file_test>
    <unknown_test id="ukn-24" comment="a website linked to the Crystal Reports Viewer is active" xmlns="http://oval.mitre.org/XMLSchema/oval#independent"/>
    <registry_test id="wrt-400" comment="the w3svc service is enabled" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">SYSTEM\CurrentControlSet\Services\w3svc</key>
        <name operator="equals">Start</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="not equal">4</value>
      </data>
    </registry_test>
    <file_test id="wft-341" comment="the version of CrystalDecisions.Web.dll is less than 9.1.9800.9" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir</component>
          <component type="literal">\Crystal Decisions\1.1\Managed\CrystalDecisions.Web.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>9</major>
          <minor>1</minor>
          <build>9800</build>
          <private>9</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-668" comment="mshtml.dll is less than 6.0.3790.2541" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mshtml.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>3790</build>
          <private>2541</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-700" comment="the version of Mf3216.dll is less than 5.1.2600.1331" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\Mf3216.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>1331</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-699" comment="the version of Gdi32.dll is less than 5.1.2600.1755" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\Gdi32.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>1755</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-645" comment="version of Gdi32.dll is less than 5.1.2600.1755 OR the version of Mf3216.dll is less than 5.1.2600.1331" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="wft-699"/>
      <subtest test_ref="wft-700"/>
    </compound_test>
    <patch_test id="hpt-13" comment="Patch PHNE_33791 or later is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <area_patched>PHNE</area_patched>
        <patch_number operator="greater than or equal">33791</patch_number>
      </object>
    </patch_test>
    <swlist_test id="hst-12" comment="InternetSrvcs.INET-ENG-A-MAN is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <swlist operator="equals">InternetSrvcs.INET-ENG-A-MAN</swlist>
      </object>
      <data>
        <version operator="equals">B.11.11</version>
      </data>
    </swlist_test>
    <swlist_test id="hst-11" comment="InternetSrvcs.INETSVCS-RUN is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <swlist operator="equals">InternetSrvcs.INETSVCS-RUN</swlist>
      </object>
      <data>
        <version operator="equals">B.11.11</version>
      </data>
    </swlist_test>
    <compound_test id="cmp-667" comment="InternetSrvcs.INETSVCS-RUN or InternetSrvcs.INET-ENG-A-MAN (B.11.11) is installed" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="hst-11"/>
      <subtest test_ref="hst-12"/>
    </compound_test>
    <registry_test id="wrt-429" comment="DirectX 9.x Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\DirectX</key>
        <name>Version</name>
      </object>
      <data operation="AND">
        <value operator="pattern match">^4\.[0]*9\..*</value>
      </data>
    </registry_test>
    <compound_test id="cmp-599" comment="Standalone DirectX 9 has DirectShow Vulnerability" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="wrt-429"/>
      <subtest test_ref="wft-641"/>
    </compound_test>
    <file_test id="wft-641" comment="the version of Quartz.dll is less than 6.3.1.889" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\Quartz.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>3</minor>
          <build>1</build>
          <private>889</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-598" comment="Standalone DirectX 8 has DirectShow Vulnerability" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="wrt-421"/>
      <subtest test_ref="wft-641"/>
    </compound_test>
    <file_test id="wft-652" comment="the version of Quartz.dll is less than 6.5.3790.2519" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\Quartz.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>5</minor>
          <build>3790</build>
          <private>2519</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-651" comment="the version of Quartz.dll is greater than or equal to 6.5.3790.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\Quartz.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="greater than or equal">
          <major>6</major>
          <minor>5</minor>
          <build>3790</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-604" comment="DirectX packaged with Windows Server 2003,SP1 has DirectShow Vulnerability" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="wrt-61"/>
      <subtest test_ref="wrt-3"/>
      <subtest test_ref="wft-651"/>
      <subtest test_ref="wft-652"/>
    </compound_test>
    <swlist_test id="hst-52" comment="WUFTP-26.INETSVCS-FTP with version less than B.11.00.01.004 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <swlist operator="equals">WUFTP-26.INETSVCS-FTP</swlist>
      </object>
      <data>
        <version operator="pattern match">B\.11\.00\.(00.*|01\.00[0-3])</version>
      </data>
    </swlist_test>
    <file_test id="wft-689" comment="msieftp.dll is less than 5.50.4956.500" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\msieftp.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>50</minor>
          <build>4956</build>
          <private>500</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-779" comment="the version of mshtml.dll is less than 6.0.3790.2666" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mshtml.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>3790</build>
          <private>2666</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-244" comment="for 64-bit (x64 arch) Windows (gold edition) a vulnerable version of srv.sys exists" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-22"/>
      <subtest negate="true" test_ref="wrt-3"/>
      <subtest negate="false" test_ref="wft-126"/>
    </compound_test>
    <file_test id="wft-124" comment="the version of srv.sys is less than 5.1.2600.2673" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\SYSTEM32\DRIVERS\srv.sys</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>2673</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-236" comment="32-bit version of windows with SP2 is installed and vulnerable version of srv.sys exists" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-250"/>
      <subtest negate="false" test_ref="wrt-72"/>
      <subtest negate="false" test_ref="wft-124"/>
    </compound_test>
    <file_test id="wft-119" comment="the version of srv.sys is less than 5.1.2600.1683" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\SYSTEM32\DRIVERS\srv.sys</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>1683</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-234" comment="for specific Windows configurations a vulnerable version of srv.sys exists" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-23"/>
      <subtest negate="false" test_ref="wrt-4"/>
      <subtest negate="false" test_ref="wft-119"/>
    </compound_test>
    <compound_test id="cmp-254" comment=" a vulnerable version of srv.sys exists" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-234"/>
      <subtest negate="false" test_ref="cmp-236"/>
      <subtest negate="false" test_ref="cmp-244"/>
    </compound_test>
    <registry_test id="wrt-346" comment="the patch kb896727 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key datatype="string" operator="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB896727</key>
        <name datatype="string" operator="equals">Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <permission_test id="upt-57" comment="/usr/bin/telnet is executable by any user" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/telnet</component>
        </path>
      </object>
      <data operation="OR">
        <gexec datatype="boolean" operator="equals">1</gexec>
        <oexec datatype="boolean" operator="equals">1</oexec>
        <uexec datatype="boolean" operator="equals">1</uexec>
      </data>
    </permission_test>
    <rpmversioncompare_test id="rvt-22" comment="telnet RPM earlier than 1:0.17-20.EL3.3" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name operator="equals">telnet</name>
        <tested_epoch operator="equals">1</tested_epoch>
        <tested_version operator="equals">0.17</tested_version>
        <tested_release operator="equals">20.EL3.3</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <file_test id="wft-658" comment="the version of rpcss.dll is less than 5.1.2600.2726" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\rpcss.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>2726</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-657" comment="the version of ole32.dll is less than 5.1.2600.2726" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\ole32.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>2726</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-607" comment="Either ole32.dll or rpcss.dll has a version less than 5.1.2600.2726" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="wft-657"/>
      <subtest test_ref="wft-658"/>
    </compound_test>
    <compound_test id="cmp-159" comment=" for 64-bit (x64 arch) Windows (gold edition) a vulnerable version of telnet.exe exists" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-22"/>
      <subtest negate="true" test_ref="wrt-3"/>
      <subtest negate="false" test_ref="wft-74"/>
    </compound_test>
    <compound_test id="cmp-116" comment="32-bit version of windows with SP2 is installed and vulnerable version of telnet.exe exists" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wft-77"/>
      <subtest negate="false" test_ref="wrt-72"/>
      <subtest negate="false" test_ref="wrt-250"/>
    </compound_test>
    <file_test id="wft-77" comment="the version of telnet.exe is less than 5.1.2600.1684" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\telnet.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>1684</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-166" comment="for specific Windows configurations a vulnerable version of telnet.exe exists" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-23"/>
      <subtest negate="false" test_ref="wrt-4"/>
      <subtest negate="false" test_ref="wft-77"/>
    </compound_test>
    <compound_test id="cmp-181" comment="a vulnerable version of telnet.exe exists" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-166"/>
      <subtest negate="false" test_ref="cmp-116"/>
      <subtest negate="false" test_ref="cmp-159"/>
    </compound_test>
    <file_test id="wft-681" comment="cdosys.dll is less than 6.5.6749.0" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\cdosys.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>5</minor>
          <build>6749</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <patch_test id="spt-88" comment="Patch 113322-02 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">113322</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">02</version>
      </data>
    </patch_test>
    <patch_test id="spt-87" comment="Patch 111570-03 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">111570</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">03</version>
      </data>
    </patch_test>
    <patch_test id="spt-86" comment="Patch 106952-04 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">106952</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">04</version>
      </data>
    </patch_test>
    <package_test id="sat-42" comment="Networking UUCP Utilities - Usr (SUNWbnuu) installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <pkginst operator="equals">SUNWbnuu</pkginst>
      </object>
    </package_test>
    <compound_test id="cmp-1080" comment="Solaris 7,8,or 9 installed" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="uut-4"/>
      <subtest negate="false" test_ref="uut-5"/>
      <subtest negate="false" test_ref="uut-6"/>
    </compound_test>
    <file_test id="wft-731" comment="the version of T2embed.dll is less than 5.2.3790.426" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\T2embed.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>2</minor>
          <build>3790</build>
          <private>426</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-730" comment="the version of Fontsub.dll is less than 5.2.3790.426" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\Fontsub.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>2</minor>
          <build>3790</build>
          <private>426</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-711" comment="Fontsub.dll &lt; 5.2.3790.426 or T2embed.dll &lt;5.2.3790.426 (S03-Gold)" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="wft-730"/>
      <subtest test_ref="wft-731"/>
    </compound_test>
    <file_test id="wft-572" comment="the version of mscms.dll is less than 5.2.3790.359" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mscms.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>2</minor>
          <build>3790</build>
          <private>359</private>
        </version>
      </data>
    </file_test>
    <rpmversioncompare_test id="rvt-30" comment="fetchmail RPM earlier than 0:6.2.5-6.el4.2" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">fetchmail</name>
        <tested_epoch datatype="string" operator="equals">0</tested_epoch>
        <tested_version datatype="string" operator="equals">6.2.5</tested_version>
        <tested_release datatype="string" operator="equals">6.el4.2</tested_release>
      </object>
      <data operation="AND">
        <installed_version datatype="string" operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <file_test id="wft-701" comment="the version of Gdi32.dll is less than 5.1.2600.2770" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\Gdi32.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>2770</private>
        </version>
      </data>
    </file_test>
    <rpmversioncompare_test id="rvt-19" comment="kernel-smp RPM earlier than 0:2.4.21-32.0.1.EL" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name operator="equals">kernel-smp</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">2.4.21</tested_version>
        <tested_release operator="equals">32.0.1.EL</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <rpmversioncompare_test id="rvt-18" comment="kernel-hugemem RPM earlier than 0:2.4.21-32.0.1.EL" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name operator="equals">kernel-hugemem</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">2.4.21</tested_version>
        <tested_release operator="equals">32.0.1.EL</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <rpmversioncompare_test id="rvt-17" comment="kernel RPM earlier than 0:2.4.21-32.0.1.EL" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name operator="equals">kernel</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">2.4.21</tested_version>
        <tested_release operator="equals">32.0.1.EL</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <compound_test id="cmp-268" comment="kernel, kernel-smp or kernel-hugemem RPM earlier than 0:2.4.21-32.0.1.EL" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="rvt-17"/>
      <subtest negate="false" test_ref="rvt-18"/>
      <subtest negate="false" test_ref="rvt-19"/>
    </compound_test>
    <file_test id="wft-684" comment="shell32.dll is less than 6.0.2800.1751" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\shell32.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>2800</build>
          <private>1751</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-99" comment="the version of mshtml.dll is less than 6.0.2900.2668" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mshtml.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>2900</build>
          <private>2668</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-87" comment="the patch kb891781 is installed (Hotfix key)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB891781</key>
        <name operator="equals">IsInstalled</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-376" comment="the version of dhtmled.ocx is less than 6.1.0.9231" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir</component>
          <component type="literal">\microsoft shared\triedit\dhtmled.ocx</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>1</minor>
          <build>0</build>
          <private>9231</private>
        </version>
      </data>
    </file_test>
    <textfilecontent_test id="tft-5" comment="/etc/krb5/krb5.conf is configured with a kerberos domain" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <oval:notes>
        <oval:note>Rough translation of the Sun recommended test of: % grep default_realm /etc/krb5/krb5.conf | grep -v ___default_realm___  default_realm = EXAMPLE.COM</oval:note>
      </oval:notes>
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/etc/krb5/krb5.conf</component>
        </path>
        <line operator="pattern match">^[^#_]*default_realm[^=]*=[^_]*$</line>
      </object>
    </textfilecontent_test>
    <patch_test id="spt-98" comment="Patch 112390-07 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">112390</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">07</version>
      </data>
    </patch_test>
    <patch_test id="spt-97" comment="Patch 112237-07 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">112237</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">07</version>
      </data>
    </patch_test>
    <patch_test id="spt-99" comment="Patch 112908-04 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">112908</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">04</version>
      </data>
    </patch_test>
    <patch_test id="spt-96" comment="Patch 112536-02 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">112536</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">02</version>
      </data>
    </patch_test>
    <package_test id="sat-46" comment=" Sun Enterprise Authentication Mechanism (SEAM, SUNWkrggl) installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <pkginst operator="equals">SUNWkrggl</pkginst>
      </object>
    </package_test>
    <package_test id="sat-45" comment=" Sun Enterprise Authentication Mechanism (SEAM, SUNWkrgdo) installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <pkginst operator="equals">SUNWkrgdo</pkginst>
      </object>
    </package_test>
    <package_test id="sat-44" comment=" Sun Enterprise Authentication Mechanism (SEAM, SUNWkr5sl) installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <pkginst operator="equals">SUNWkr5sl</pkginst>
      </object>
    </package_test>
    <package_test id="sat-29" comment="Sun Enterprise Authentication Mechanism (SEAM, SUNWkr5sv) installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <pkginst operator="equals">SUNWkr5sv</pkginst>
      </object>
    </package_test>
    <compound_test id="cmp-118" comment="Solaris Enterprise Authentication Mechanism (ANY SUNWkr5sl/SUNWkr5sv/SUNWkrgdo/SUNWkrggl)" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="sat-29"/>
      <subtest negate="false" test_ref="sat-44"/>
      <subtest negate="false" test_ref="sat-45"/>
      <subtest negate="false" test_ref="sat-46"/>
    </compound_test>
    <compound_test id="cmp-156" comment="Solaris 7 AND Solaris Enterprise Authentication Mechanism installed" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="uut-5"/>
      <subtest negate="false" test_ref="cmp-118"/>
    </compound_test>
    <compound_test id="cmp-157" comment="Solaris 7 and Solaris Enterprise Authentication Mechanism OR Solaris 8 or 9 installed" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-156"/>
      <subtest negate="false" test_ref="cmp-1081"/>
    </compound_test>
    <permission_test id="upt-227" comment="/usr/bin/zgrep is executable by any user" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/zgrep</component>
        </path>
      </object>
      <data operation="OR">
        <gexec datatype="boolean" operator="equals">1</gexec>
        <oexec datatype="boolean" operator="equals">1</oexec>
        <uexec datatype="boolean" operator="equals">1</uexec>
      </data>
    </permission_test>
    <file_test id="wft-670" comment="nwwks.dll is less than 5.1.2600.1727" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\nwwks.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>1727</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-493" comment="the version of sxs.dll is less than 5.2.3790.121" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\sxs.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>2</minor>
          <build>3790</build>
          <private>121</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-428" comment="DirectX 9.0a Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\DirectX</key>
        <name>Version</name>
      </object>
      <data operation="AND">
        <value operator="pattern match">^4\.[0]*9\.[0]+\.[0]*901</value>
      </data>
    </registry_test>
    <registry_test id="wrt-424" comment="DirectX 9.0-gold Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\DirectX</key>
        <name>Version</name>
      </object>
      <data operation="AND">
        <value operator="pattern match">^4\.[0]*9\.[0]+\.[0]*900</value>
      </data>
    </registry_test>
    <compound_test id="cmp-334" comment="DirectX 9.0 or 9.0a installed." operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="wrt-424"/>
      <subtest test_ref="wrt-428"/>
    </compound_test>
    <file_test id="wft-707" comment="the version of mshtml.dll is less than 6.0.3790.2577" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mshtml.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>3790</build>
          <private>2577</private>
        </version>
      </data>
    </file_test>
    <patch_test id="spt-255" comment="Patch 112808-02 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">112808</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">02</version>
      </data>
    </patch_test>
    <package_test id="sat-6" comment="Toolktalk (SUNWtltk/SUNWtltkx) installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <pkginst operator="pattern match">SUNWtltkx?</pkginst>
      </object>
    </package_test>
    <file_test id="wft-324" comment="File %windir%\system32\urlmon.dll version is less than 5.50.4701.2400" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mshtml.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>50</minor>
          <build>4701</build>
          <private>2400</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-323" comment="File %windir%\system32\mshtml.dll version is less than 5.50.4616.200" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mshtml.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>50</minor>
          <build>4616</build>
          <private>200</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-422" comment="Patch Windows2000-KB819696-x86-ENU.EXE Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB819696</key>
        <name>Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <registry_test id="wrt-421" comment="DirectX 8.x Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\DirectX</key>
        <name>Version</name>
      </object>
      <data operation="AND">
        <value operator="pattern match">^4\.[0]*8\..*</value>
      </data>
    </registry_test>
    <registry_test id="wrt-622" comment="Server 2003 IE Enhanced Security (User) is installed and set." check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\OC Manager\Subcomponents</key>
        <name operator="equals">ieHardenuser</name>
      </object>
      <data operation="AND">
        <value operator="equals">1</value>
      </data>
    </registry_test>
    <registry_test id="wrt-621" comment="Server 2003 IE Enhanced Security (Administror) is installed and set." check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\OC Manager\Subcomponents</key>
        <name operator="equals">ieHardenadmin</name>
      </object>
      <data operation="AND">
        <value operator="equals">1</value>
      </data>
    </registry_test>
    <compound_test id="cmp-686" comment="Server 2003 IE Enhanced Security is installed and set." operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="wrt-621"/>
      <subtest test_ref="wrt-622"/>
    </compound_test>
    <file_test id="wft-708" comment="the version of mshtml.dll is less than 6.0.3790.449" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mshtml.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>3790</build>
          <private>449</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-10027" comment="Internet Explorer 6 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Internet Explorer</key>
        <name>Version</name>
      </object>
      <data operation="AND">
        <value operator="pattern match">6\..*</value>
      </data>
    </registry_test>
    <file_test id="wft-82" comment="the version of inetcomm.dll is less than 5.50.4952.2800" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\inetcomm.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>50</minor>
          <build>4952</build>
          <private>2800</private>
        </version>
      </data>
    </file_test>
    <file_test id="uft-2" comment="/usr/lib/pgsql/tsearch.so (PostgreSQL's tsearch module) exists as a regular file" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/lib/pgsql/tsearch.so</component>
        </path>
      </object>
      <data operation="AND">
        <type operator="equals">regular</type>
      </data>
    </file_test>
    <rpmversioncompare_test id="rvt-10" comment="rh-postgresql-contrib rpm is earlier than 0:7.3.10-1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name operator="equals">rh-postgresql-contrib</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">7.3.10</tested_version>
        <tested_release operator="equals">1</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <file_test id="wft-737" comment="the version of Mapi32.dll is less than 6.0.6617.47" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\Mapi32.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>6617</build>
          <private>47</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-739" comment="the version of Mapi32.dll is greater than or equal 6.0.6603.0 (Exchange 2000 Server,SP3 is installed)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\Mapi32.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="greater than or equal">
          <major>6</major>
          <minor>0</minor>
          <build>6603</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <permission_test id="upt-2" comment="/usr/bin/bzgrep is executable" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/bzgrep</component>
        </path>
      </object>
      <data operation="OR">
        <gexec datatype="boolean" operator="equals">1</gexec>
        <oexec datatype="boolean" operator="equals">1</oexec>
        <uexec datatype="boolean" operator="equals">1</uexec>
      </data>
    </permission_test>
    <registry_test id="wrt-398" comment="WINS Client binding not disabled" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="pattern match">^SYSTEM\\CurrentControlSet\\Services\\NetBT\\Parameters\\Interfaces\\Tcpip.*$</key>
        <name operator="equals">NetbiosOptions</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="not equal">2</value>
      </data>
    </registry_test>
    <registry_test id="wrt-397" comment="TCP/IP NetBIOS not disabled" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SYSTEM\CurrentControlSet\Services\LmHosts</key>
        <name>Start</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="not equal">4</value>
      </data>
    </registry_test>
    <registry_test id="wrt-396" comment="Windows 95 or 98 Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows\CurrentVersion</key>
        <name>Version</name>
      </object>
      <data operation="AND">
        <value operator="pattern match">^Windows.*</value>
      </data>
    </registry_test>
    <compound_test id="cmp-943" comment="Windows 95, 98, NT or 2000 is installed" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-396"/>
      <subtest negate="false" test_ref="cmp-933"/>
    </compound_test>
    <file_test id="wft-427" comment="the version of ssnetlib.dll is less than 2000.80.636.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
          <component type="literal">\ssnetlib.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>2000</major>
          <minor>80</minor>
          <build>636</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-426" comment="the version of sqlservr.exe is less than 2000.80.636.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
          <component type="literal">\sqlservr.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>2000</major>
          <minor>80</minor>
          <build>636</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-193" comment="the version of msasn1.dll is less than 5.0.2195.6905" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\msasn1.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>2195</build>
          <private>6905</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-139" comment="Windows NT or 2000 is installed" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-77"/>
      <subtest negate="false" test_ref="wrt-1"/>
    </compound_test>
    <registry_test id="wrt-201" comment="the Telephony service is enabled" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key datatype="string" operator="equals">SYSTEM\CurrentControlSet\Services\TapiSrv</key>
        <name datatype="string" operator="equals">Start</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="not equal">4</value>
      </data>
    </registry_test>
    <registry_test id="wrt-139" comment="the patch kb893756 is installed (Hotfix key)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key datatype="string" operator="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB893756</key>
        <name datatype="string" operator="equals">Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-617" comment="the version of tapisrv.dll is less than 5.2.3790.2483" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\tapisrv.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>2</minor>
          <build>3790</build>
          <private>2483</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-284" comment=" for 64-bit (x64 arch) Windows (gold edition) a vulnerable version of tapisrv.dll exists" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-22"/>
      <subtest negate="true" test_ref="wrt-3"/>
      <subtest negate="false" test_ref="wft-617"/>
    </compound_test>
    <file_test id="wft-616" comment="the version of tapisrv.dll is less than 5.1.2600.2716" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\tapisrv.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>2716</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-288" comment="32-bit version of windows with SP2 is installed and vulnerable version of tapisrv.dll exists" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-72"/>
      <subtest negate="false" test_ref="wrt-250"/>
      <subtest negate="false" test_ref="wft-616"/>
    </compound_test>
    <file_test id="wft-615" comment="the version of tapisrv.dll is less than 5.1.2600.1715" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\tapisrv.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>1715</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-286" comment="32-bit version of windows with SP1 or earlier is installed and vulnerable version of tapisrv.dll exists" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-72"/>
      <subtest negate="true" test_ref="wrt-29"/>
      <subtest negate="false" test_ref="wft-615"/>
    </compound_test>
    <compound_test id="cmp-290" comment=" a vulnerable version of tapisrv.dll exists" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-286"/>
      <subtest negate="false" test_ref="cmp-288"/>
      <subtest negate="false" test_ref="cmp-284"/>
    </compound_test>
    <patch_test id="spt-277" comment="Patch 122082-01 or later installed (x86-10)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">122082</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">01</version>
      </data>
    </patch_test>
    <compound_test id="cmp-770" comment="Solaris 10 (x86) meets Sun Alert ID 102192 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-10001"/>
      <subtest test_ref="uut-10002"/>
      <subtest negate="true" test_ref="spt-277"/>
    </compound_test>
    <patch_test id="spt-276" comment="Patch 119985-02 or later installed (SPARC-10)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">119985</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">02</version>
      </data>
    </patch_test>
    <compound_test id="cmp-769" comment="Solaris 10 (SPARC) meets Sun Alert ID 102192 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-10001"/>
      <subtest test_ref="uut-10003"/>
      <subtest negate="true" test_ref="spt-276"/>
    </compound_test>
    <file_test id="wft-178" comment="the version of comsvcs.dll is less than 2001.12.4414.53" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\comsvcs.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>2001</major>
          <minor>12</minor>
          <build>4414</build>
          <private>53</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-656" comment="the version of rpcss.dll is less than 5.1.2600.1720" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\rpcss.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>1720</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-655" comment="the version of ole32.dll is less than 5.1.2600.1720" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\ole32.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>1720</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-606" comment="Either ole32.dll or rpcss.dll has a version less than 5.1.2600.1720" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="wft-655"/>
      <subtest test_ref="wft-656"/>
    </compound_test>
    <file_test id="wft-340" comment="File %windir%\System32\Msw3prt.dll is less than 5.0.2195.2956" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\System32\Msw3prt.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>2195</build>
          <private>2956</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-179" comment="the version of comsvcs.dll is less than 2001.12.4720.130" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\comsvcs.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>2001</major>
          <minor>12</minor>
          <build>4720</build>
          <private>130</private>
        </version>
      </data>
    </file_test>
    <permission_test id="upt-44" comment="/usr/bin/oowriter is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/oowriter</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-43" comment="/usr/bin/oowriter is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/oowriter</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-42" comment="/usr/bin/oowriter is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/oowriter</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-942" comment="/usr/bin/oowriter is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-42"/>
      <subtest negate="false" test_ref="upt-43"/>
      <subtest negate="false" test_ref="upt-44"/>
    </compound_test>
    <permission_test id="upt-41" comment="/usr/bin/ooimpress is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ooimpress</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-40" comment="/usr/bin/ooimpress is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ooimpress</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-39" comment="/usr/bin/ooimpress is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ooimpress</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-941" comment="/usr/bin/ooimpress is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-39"/>
      <subtest negate="false" test_ref="upt-40"/>
      <subtest negate="false" test_ref="upt-41"/>
    </compound_test>
    <permission_test id="upt-38" comment="/usr/bin/ooffice is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ooffice</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-37" comment="/usr/bin/ooffice is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ooffice</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-36" comment="/usr/bin/ooffice is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ooffice</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-940" comment="/usr/bin/ooffice is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-36"/>
      <subtest negate="false" test_ref="upt-37"/>
      <subtest negate="false" test_ref="upt-38"/>
    </compound_test>
    <permission_test id="upt-35" comment="/usr/bin/oodraw is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/oodraw</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-34" comment="/usr/bin/oodraw is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/oodraw</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-33" comment="/usr/bin/oodraw is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/oodraw</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-939" comment="/usr/bin/oodraw is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-33"/>
      <subtest negate="false" test_ref="upt-34"/>
      <subtest negate="false" test_ref="upt-35"/>
    </compound_test>
    <permission_test id="upt-32" comment="/usr/bin/oocalc is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/oocalc</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-31" comment="/usr/bin/oocalc is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/oocalc</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-30" comment="/usr/bin/oocalc is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/oocalc</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-938" comment="/usr/bin/oocalc is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-30"/>
      <subtest negate="false" test_ref="upt-31"/>
      <subtest negate="false" test_ref="upt-32"/>
    </compound_test>
    <compound_test id="cmp-937" comment="OpenOffice Permissions" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-938"/>
      <subtest negate="false" test_ref="cmp-939"/>
      <subtest negate="false" test_ref="cmp-940"/>
      <subtest negate="false" test_ref="cmp-941"/>
      <subtest negate="false" test_ref="cmp-942"/>
    </compound_test>
    <rpmversioncompare_test id="rvt-349" comment="openoffice version is less than 1.1.0-15.EL" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">openoffice</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">1.1.0</tested_version>
        <tested_release operator="equals">15.EL</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <compound_test id="cmp-175" comment="64-bit version of Windows and mf3216.dll is less than 5.1.2600.1331" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-70"/>
      <subtest negate="false" test_ref="wft-149"/>
    </compound_test>
    <file_test id="wft-149" comment="the version of mf3216.dll is less than 5.1.2600.1331" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mf3216.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>1331</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-174" comment="service pack 1 is installed and mf3216.dll is less than 5.1.2600.1331" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-4"/>
      <subtest negate="false" test_ref="wft-149"/>
    </compound_test>
    <file_test id="wft-139" comment="the version of mf3216.dll is less than 5.1.2600.132" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mf3216.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>132</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-173" comment="no service pack is installed and mf3216.dll is less than 5.1.2600.132" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="true" test_ref="wrt-3"/>
      <subtest negate="false" test_ref="wft-139"/>
    </compound_test>
    <compound_test id="cmp-172" comment="a vulnerable version of mf3216.dll exists depending on service pack level" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-173"/>
      <subtest negate="false" test_ref="cmp-174"/>
    </compound_test>
    <compound_test id="cmp-171" comment="32-bit version of Windows and a vulnerable version of mf3216.dll exists" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-72"/>
      <subtest negate="false" test_ref="cmp-172"/>
    </compound_test>
    <compound_test id="cmp-170" comment="a vulnerable version of mf3216.dll exists on XP" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-171"/>
      <subtest negate="false" test_ref="cmp-175"/>
    </compound_test>
    <file_test id="wft-698" comment="the version of Mf3216.dll is less than 5.0.2195.6898" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\Mf3216.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>2195</build>
          <private>6898</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-697" comment="the version of Gdi32.dll is less than 5.0.2195.7069" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\Gdi32.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>2195</build>
          <private>7069</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-644" comment="version of Gdi32.dll is less than 5.0.2195.7069 OR the version of Mf3216.dll is less than 5.0.2195.6898" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="wft-697"/>
      <subtest test_ref="wft-698"/>
    </compound_test>
    <file_test id="wft-177" comment="the version of comsvcs.dll is less than 2000.2.3511.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\comsvcs.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>2000</major>
          <minor>2</minor>
          <build>3511</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-434" comment="the version of cryptdlg.dll is less then 5.0.1558.6072" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\cryptdlg.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>1558</build>
          <private>6072</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-36" comment="for 64-bit (x64 arch) Windows (gold edition) a vulnerable version of hh.exe exists" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-22"/>
      <subtest negate="true" test_ref="wrt-3"/>
      <subtest negate="false" test_ref="wft-11"/>
    </compound_test>
    <file_test id="wft-10" comment="the version of hh.exe is less than 5.2.3790.2453" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\hh.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>2</minor>
          <build>3790</build>
          <private>2453</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-29" comment="for 32-bit Windows with sp2 a vulnerable version of hh.exe exists" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-72"/>
      <subtest negate="false" test_ref="wrt-250"/>
      <subtest negate="false" test_ref="wft-10"/>
    </compound_test>
    <compound_test id="cmp-28" comment="for specific Windows configurations a vulnerable version of hh.exe exists" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-23"/>
      <subtest negate="true" test_ref="wrt-29"/>
      <subtest negate="false" test_ref="wft-9"/>
    </compound_test>
    <compound_test id="cmp-49" comment="a vulnerable version of hh.exe exists" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-28"/>
      <subtest negate="false" test_ref="cmp-29"/>
      <subtest negate="false" test_ref="cmp-36"/>
    </compound_test>
    <registry_test id="wrt-477" comment="the patch Q329115 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q329115</key>
        <name>Installed</name>
      </object>
      <data operation="AND">
        <value datatype="binary" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-432" comment="the version of crypt32.dll is less than 5.131.2600.1123" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\crypt32.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>131</minor>
          <build>2600</build>
          <private>1123</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-125" comment="64-bit version of Windows and msgina.dll is less than 5.1.2600.1343" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-70"/>
      <subtest negate="false" test_ref="wft-135"/>
    </compound_test>
    <file_test id="wft-135" comment="the version of msgina.dll is less than 5.1.2600.1343" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\msgina.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>1343</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-124" comment="service pack 1 is installed and msgina.dll is less than 5.1.2600.1343" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-4"/>
      <subtest negate="false" test_ref="wft-135"/>
    </compound_test>
    <file_test id="wft-134" comment="the version of msgina.dll is less than 5.1.2600.128" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\msgina.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>128</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-123" comment="no service pack is installed and msgina.dll is less than 5.1.2600.128" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="true" test_ref="wrt-3"/>
      <subtest negate="false" test_ref="wft-134"/>
    </compound_test>
    <compound_test id="cmp-122" comment="a vulnerable version of msgina.dll exists depending on service pack level" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-123"/>
      <subtest negate="false" test_ref="cmp-124"/>
    </compound_test>
    <compound_test id="cmp-121" comment="32-bit version of Windows and a vulnerable version of msgina.dll exists" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-72"/>
      <subtest negate="false" test_ref="cmp-122"/>
    </compound_test>
    <compound_test id="cmp-120" comment="a vulnerable version of msgina.dll exists" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-121"/>
      <subtest negate="false" test_ref="cmp-125"/>
    </compound_test>
    <registry_test id="wrt-554" comment="Compressed Folders with zipfldr.dll are enabled" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">SOFTWARE\Classes\CompressedFolder</key>
        <name operator="equals">FriendlyTypeName</name>
      </object>
      <data operation="AND">
        <value operator="pattern match">.*zipfldr\.dll.*</value>
      </data>
    </registry_test>
    <registry_test id="wrt-553" comment="the patch q873376 is installed (Hotfix key)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB873376</key>
        <name>Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-534" comment="the 32-bit version of zipfldr.dll is less than 6.0.2800.1584" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\zipfldr.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>2800</build>
          <private>1584</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-1140" comment="service pack 1 and vulnerable 32-bit version of zipfldr.dll" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-4"/>
      <subtest negate="false" test_ref="wft-534"/>
    </compound_test>
    <file_test id="wft-532" comment="the 32-bit version of zipfldr.dll is less than 6.0.2750.167" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\zipfldr.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>2750</build>
          <private>167</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-1139" comment="no service pack and vulnerable 32-bit version of zipfldr.dll" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="true" test_ref="wrt-3"/>
      <subtest negate="false" test_ref="wft-532"/>
    </compound_test>
    <compound_test id="cmp-1141" comment="vulnerable 32-bit version of zipfldr.dll" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-1139"/>
      <subtest negate="false" test_ref="cmp-1140"/>
    </compound_test>
    <registry_test id="wrt-633" comment="the software MailSite Express version 6.1.20 or earlier is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key datatype="string" operator="equals">SOFTWARE\Rockliffe\MailSite</key>
        <name datatype="string" operator="equals">Version</name>
      </object>
      <data operation="AND">
        <value datatype="string" operator="pattern match">^([1-5]\.[0-9].*|6\.(0.*|1|1\.([0-9]($|\..*)|[0-1][0-9]($|\..*)|20($|\..*)|21($|\..*))))$</value>
      </data>
    </registry_test>
    <file_test id="wft-339" comment="File %windir%\System32\msw3prt.dll is less than 5.0.2195.3649" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\System32\msw3prt.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>2195</build>
          <private>3649</private>
        </version>
      </data>
    </file_test>
    <patch_test id="spt-105" comment="Patch 108869-15 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">108869</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">15</version>
      </data>
    </patch_test>
    <patch_test id="spt-104" comment="Patch 107709-18 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">107709</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">18</version>
      </data>
    </patch_test>
    <package_test id="sat-48" comment="Solstice Enterprise Agents SNMP (SUNWsasnm) installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <pkginst operator="equals">SUNWsasnm</pkginst>
      </object>
    </package_test>
    <file_test id="wft-322" comment="the version of umandlg.dll is less than 1.0.0.4" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\umandlg.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>1</major>
          <minor>0</minor>
          <build>0</build>
          <private>4</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-370" comment="the patch KB896423 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key datatype="string" operator="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB896423</key>
        <name datatype="string" operator="equals">Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-630" comment="the version of Spoolsv.exe is less than 5.0.2195.7059" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\spoolsv.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>2195</build>
          <private>7059</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-538" comment="Win2K/XP/2003 service pack 4 (or earlier) is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion</key>
        <name>CSDVersion</name>
      </object>
      <data operation="AND">
        <value operator="pattern match">^Service Pack [0-4]$</value>
      </data>
    </registry_test>
    <process_test id="uct-22" comment="The Xsun X server is running" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <command operator="pattern match">.*Xsun\b.*</command>
      </object>
    </process_test>
    <patch_test id="spt-194" comment="Patch 119060-08 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">119060</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">08</version>
      </data>
    </patch_test>
    <compound_test id="cmp-756" comment="Solaris 10 (x86,Xsun) meets Sun Alert ID 101926 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-10001"/>
      <subtest test_ref="uut-10002"/>
      <subtest negate="true" test_ref="spt-194"/>
      <subtest negate="true" test_ref="uft-33"/>
    </compound_test>
    <patch_test id="spt-192" comment="Patch 112786-41 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">112786</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">41</version>
      </data>
    </patch_test>
    <compound_test id="cmp-754" comment="Solaris 9 (x86,Xsun) meets Sun Alert ID 101926 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-6"/>
      <subtest test_ref="uut-10002"/>
      <subtest negate="true" test_ref="spt-192"/>
      <subtest negate="true" test_ref="uft-33"/>
    </compound_test>
    <patch_test id="spt-191" comment="Patch 108653-83 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">108653</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">83</version>
      </data>
    </patch_test>
    <compound_test id="cmp-753" comment="Solaris 8 (x86,Xsun) meets Sun Alert ID 101926 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-4"/>
      <subtest test_ref="uut-10002"/>
      <subtest negate="true" test_ref="spt-191"/>
      <subtest negate="true" test_ref="uft-33"/>
    </compound_test>
    <patch_test id="spt-190" comment="Patch 119059-08 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">119059</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">08</version>
      </data>
    </patch_test>
    <compound_test id="cmp-752" comment="Solaris 10 (SPARC,Xsun) meets Sun Alert ID 101926 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-10001"/>
      <subtest test_ref="uut-10003"/>
      <subtest negate="true" test_ref="spt-190"/>
      <subtest negate="true" test_ref="uft-33"/>
    </compound_test>
    <patch_test id="spt-189" comment="Patch 112785-52 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">112785</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">52</version>
      </data>
    </patch_test>
    <compound_test id="cmp-751" comment="Solaris 9 (SPARC,Xsun) meets Sun Alert ID 101926 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-6"/>
      <subtest test_ref="uut-10003"/>
      <subtest negate="true" test_ref="spt-189"/>
      <subtest negate="true" test_ref="uft-33"/>
    </compound_test>
    <patch_test id="spt-188" comment="Patch 108652-94 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">108652</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">94</version>
      </data>
    </patch_test>
    <compound_test id="cmp-750" comment="Solaris 8 (SPARC,Xsun) meets Sun Alert ID 101926 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-4"/>
      <subtest test_ref="uut-10003"/>
      <subtest negate="true" test_ref="spt-188"/>
      <subtest negate="true" test_ref="uft-33"/>
    </compound_test>
    <rpmversioncompare_test id="rvt-348" comment="cvs version is less than 1.11.2-18" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">cvs</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">1.11.2</tested_version>
        <tested_release datatype="int" operator="equals">18</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <file_test id="wft-297" comment="the version of ole32.dll is less than 4.0.1381.33562" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\ole32.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>4</major>
          <minor>0</minor>
          <build>1381</build>
          <private>33562</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-197" comment="Terminal Server and ole32.dll is less than 4.0.1381.33562" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-43"/>
      <subtest negate="false" test_ref="wft-297"/>
    </compound_test>
    <file_test id="wft-295" comment="the version of ole32.dll is less than 4.0.1381.7263" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\ole32.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>4</major>
          <minor>0</minor>
          <build>1381</build>
          <private>7263</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-196" comment="non Terminal Server and ole32.dll is less than 4.0.1381.7263" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="true" test_ref="wrt-43"/>
      <subtest negate="false" test_ref="wft-295"/>
    </compound_test>
    <compound_test id="cmp-195" comment="a vulnerable version of ole32.dll exists on NT" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-196"/>
      <subtest negate="false" test_ref="cmp-197"/>
    </compound_test>
    <registry_test id="wrt-382" comment="DataAccess Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\DataAccess</key>
        <name>FullInstallVer</name>
      </object>
      <data operation="AND">
        <value operator="pattern match">^2\.7.*</value>
      </data>
    </registry_test>
    <file_test id="wft-321" comment="File %windir%\System32\odbcbcp.dll is less than 2000.81.9041.40" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\odbcbcp.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>2000</major>
          <minor>81</minor>
          <build>9041</build>
          <private>40</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-320" comment="File %windir%\System32\odbcbcp.dll is less than 2000.81.9001.40" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\odbcbcp.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>2000</major>
          <minor>81</minor>
          <build>9001</build>
          <private>40</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-912" comment="Affected MDAC versions" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wft-320"/>
      <subtest negate="false" test_ref="wft-321"/>
      <subtest negate="false" test_ref="wrt-382"/>
    </compound_test>
    <permission_test id="upt-858" comment="/usr/bin/fetchmail is executable by any user" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/fetchmail</component>
        </path>
      </object>
      <data operation="OR">
        <gexec datatype="boolean" operator="equals">1</gexec>
        <oexec datatype="boolean" operator="equals">1</oexec>
        <uexec datatype="boolean" operator="equals">1</uexec>
      </data>
    </permission_test>
    <rpmversioncompare_test id="rvt-29" comment="fetchmail RPM older than 0:6.2.0-3.el3.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">fetchmail</name>
        <tested_epoch datatype="string" operator="equals">0</tested_epoch>
        <tested_version datatype="string" operator="equals">6.2.0</tested_version>
        <tested_release datatype="string" operator="equals">3.el3.1</tested_release>
      </object>
      <data operation="AND">
        <installed_version datatype="string" operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <registry_test id="wrt-471" comment="RestrictAnonymous registry value allows anonymous connections" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SYSTEM\CurrentControlSet\Control\LSA</key>
        <name>RestrictAnonymous</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">0</value>
      </data>
    </registry_test>
    <registry_test id="wrt-472" comment="Veritas Backup Exec 8.5 Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">Software\VERITAS\Backup Exec\Server</key>
        <name operator="equals">CurrentVersion</name>
      </object>
      <data operation="AND">
        <value operator="equals">8.5</value>
      </data>
    </registry_test>
    <unknown_test id="ukn-25" comment="Affected bkupexec.exe versions 3.60.1.298" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <oval:notes>
        <oval:note>We think, but are not sure that the affected version of bkupexec.exe is 3.60.1.298 The file should be found in C:\Program Files\VERITAS\Backup Exec\NT\bkupexec.exe</oval:note>
      </oval:notes>
    </unknown_test>
    <file_test id="wft-294" comment="the version of helpctr.exe is less than 5.2.3790.161" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\helpctr.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>2</minor>
          <build>3790</build>
          <private>161</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-288" comment="machine has followed the QFE update path and rpcproxy.dll is less than 5.2.3790.141" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\rpcproxy.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>2</minor>
          <build>3790</build>
          <private>141</private>
        </version>
        <development_class>srv03_qfe</development_class>
      </data>
    </file_test>
    <file_test id="wft-284" comment="machine has followed the GDR update path and rpcproxy.dll is less than 5.2.3790.137" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\rpcproxy.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>2</minor>
          <build>3790</build>
          <private>137</private>
        </version>
        <development_class operator="not equal">srv03_qfe</development_class>
      </data>
    </file_test>
    <compound_test id="cmp-190" comment="a vulnerable version of rpcproxy.dll exists on Server 2003" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wft-284"/>
      <subtest negate="false" test_ref="wft-288"/>
    </compound_test>
    <compound_test id="cmp-193" comment="Windows Server 2003 (excluding WinXP 64-bit, Version 2003) is installed" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-61"/>
      <subtest negate="true" test_ref="wrt-40"/>
    </compound_test>
    <patch_test id="hpt-5" comment="Patch PHNE_24395 or later is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <area_patched>PHNE</area_patched>
        <patch_number operator="greater than or equal">24395</patch_number>
      </object>
    </patch_test>
    <compound_test id="cmp-673" comment="800 Series OS Release 11.04" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-11"/>
      <subtest test_ref="uut-17"/>
    </compound_test>
    <uname_test id="uut-17" comment="HP Release B.11.04" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <data operation="AND">
        <os_name operator="equals">HP-UX</os_name>
        <os_release operator="equals">B.11.04</os_release>
      </data>
    </uname_test>
    <compound_test id="cmp-672" comment="700 Series OS Release 11.04" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-10"/>
      <subtest test_ref="uut-17"/>
    </compound_test>
    <compound_test id="cmp-674" comment="700 Series or 800 Series OS Release 11.04" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="cmp-672"/>
      <subtest test_ref="cmp-673"/>
    </compound_test>
    <swlist_test id="hst-21" comment="VirtualVaultOS.VVOS-AUX-IA is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <swlist operator="equals">VirtualVaultOS.VVOS-AUX-IA</swlist>
      </object>
      <data>
        <version operator="equals">B.11.04</version>
      </data>
    </swlist_test>
    <swlist_test id="hst-20" comment="InternetSrvcs.INET-ENG-A-MAN is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <swlist operator="equals">InternetSrvcs.INET-ENG-A-MAN</swlist>
      </object>
      <data>
        <version operator="equals">B.11.04</version>
      </data>
    </swlist_test>
    <swlist_test id="hst-19" comment="InternetSrvcs.INETSVCS-RUN is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <swlist operator="equals">InternetSrvcs.INETSVCS-RUN</swlist>
      </object>
      <data>
        <version operator="equals">B.11.04</version>
      </data>
    </swlist_test>
    <compound_test id="cmp-671" comment="InternetSrvcs.INETSVCS-RUN, InternetSrvcs.INET-ENG-A-MAN, or VirtualVaultOS.VVOS-AUX-IA (B.11.04) is installed" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="hst-19"/>
      <subtest test_ref="hst-20"/>
      <subtest test_ref="hst-21"/>
    </compound_test>
    <registry_test id="wrt-186" comment="the patch kb837009 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB837009</key>
        <name>Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-184" comment="the version of inetcomm.dll is less than 6.00.3790.137" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\inetcomm.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>00</minor>
          <build>3790</build>
          <private>137</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-470" comment="Patch DirectX90-KB839643-x86-ENU Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB839643-DirectX9</key>
        <name>Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-425" comment="File %windir%\system32\dplayx.dll version is less than 5.3.0.903" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\dplayx.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>3</minor>
          <build>0</build>
          <private>903</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-469" comment="DirectX 9.0x Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\DirectX</key>
        <name>Version</name>
      </object>
      <data operation="AND">
        <value operator="pattern match">^4\.09\.00.*</value>
      </data>
    </registry_test>
    <compound_test id="cmp-1050" comment="Unpatched DirectX 9.0x" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-469"/>
      <subtest negate="false" test_ref="wft-425"/>
      <subtest negate="true" test_ref="wrt-470"/>
    </compound_test>
    <registry_test id="wrt-468" comment="Patch DirectX82-KB839643-x86-ENU Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB839643-DirectX82</key>
        <name>Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-424" comment="File %windir%\system32\dplayx.dll version is less than 5.2.3677.144" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\dplayx.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>2</minor>
          <build>3677</build>
          <private>144</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-467" comment="DirectX 8.2x Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\DirectX</key>
        <name>Version</name>
      </object>
      <data operation="AND">
        <value operator="pattern match">^4\.08\.02.*</value>
      </data>
    </registry_test>
    <compound_test id="cmp-1049" comment="Unpatched DirectX 8.2x" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-467"/>
      <subtest negate="false" test_ref="wft-424"/>
      <subtest negate="true" test_ref="wrt-468"/>
    </compound_test>
    <registry_test id="wrt-466" comment="Patch DirectX81-KB839643-x86-ENU Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB839643-DirectX81</key>
        <name>Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-423" comment="File %windir%\system32\dplayx.dll version is less than 5.1.2600.891" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\dplayx.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>891</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-465" comment="DirectX 8.1x Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\DirectX</key>
        <name>Version</name>
      </object>
      <data operation="AND">
        <value operator="pattern match">^4\.08\.01.*</value>
      </data>
    </registry_test>
    <compound_test id="cmp-1048" comment="Unpatched DirectX 8.1x" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-465"/>
      <subtest negate="false" test_ref="wft-423"/>
      <subtest negate="true" test_ref="wrt-466"/>
    </compound_test>
    <registry_test id="wrt-464" comment="Patch DirectX80-KB839643-x86-ENU Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB839643-DirectX8</key>
        <name>Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-422" comment="File %windir%\system32\dplayx.dll version is less than 5.0.2258.410" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\dplayx.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>2258</build>
          <private>410</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-463" comment="DirectX 8.0x Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\DirectX</key>
        <name>Version</name>
      </object>
      <data operation="AND">
        <value operator="pattern match">^4\.08\.00.*</value>
      </data>
    </registry_test>
    <compound_test id="cmp-1047" comment="Unpatched DirectX 8.0x" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-463"/>
      <subtest negate="false" test_ref="wft-422"/>
      <subtest negate="true" test_ref="wrt-464"/>
    </compound_test>
    <registry_test id="wrt-462" comment="Patch Windows2000-KB839643-x86-ENU.EXE Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB839643</key>
        <name>Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-421" comment="File %windir%\system32\dplayx.dll version is less than 5.0.2195.6927" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\dplayx.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>2195</build>
          <private>6927</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-461" comment="DirectX 7.0x Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\DirectX</key>
        <name>Version</name>
      </object>
      <data operation="AND">
        <value operator="pattern match">^4\.07.*</value>
      </data>
    </registry_test>
    <compound_test id="cmp-1046" comment="Unpatched DirectX 7.0" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-461"/>
      <subtest negate="false" test_ref="wft-421"/>
      <subtest negate="true" test_ref="wrt-462"/>
    </compound_test>
    <compound_test id="cmp-1045" comment="Vulnerable versions of DirectX" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-1046"/>
      <subtest negate="false" test_ref="cmp-1047"/>
      <subtest negate="false" test_ref="cmp-1048"/>
      <subtest negate="false" test_ref="cmp-1049"/>
      <subtest negate="false" test_ref="cmp-1050"/>
    </compound_test>
    <file_test id="wft-420" comment="the version of xpstar.dll is less than 2000.80.628.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
          <component type="literal">\xpstar.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>2000</major>
          <minor>80</minor>
          <build>628</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-431" comment="the version of xpweb70.dll is less than 2000.80.606.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
          <component type="literal">\xpweb70.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>2000</major>
          <minor>80</minor>
          <build>606</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-430" comment="the version of xplog70.dll is less than 2000.80.606.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
          <component type="literal">\xplog70.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>2000</major>
          <minor>80</minor>
          <build>606</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-429" comment="the version of xprepl.dll is less than 2000.80.606.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
          <component type="literal">\xprepl.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>2000</major>
          <minor>80</minor>
          <build>606</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-428" comment="the version of xpqueue.dll is less than 2000.80.606.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
          <component type="literal">\xpqueue.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>2000</major>
          <minor>80</minor>
          <build>606</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-419" comment="the version of odsole70.dll is less than 2000.80.606.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
          <component type="literal">\odsole70.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>2000</major>
          <minor>80</minor>
          <build>606</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-418" comment="the version of sqlservr.exe is less than 2000.80.650.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
          <component type="literal">\sqlservr.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>2000</major>
          <minor>80</minor>
          <build>650</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-395" comment="NetBIOS Route not disabled" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SYSTEM\CurrentControlSet\Services\NetBIOS\Linkage</key>
        <name>Route</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="not equal">0</value>
      </data>
    </registry_test>
    <registry_test id="wrt-394" comment="NetBIOS Export not disabled" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SYSTEM\CurrentControlSet\Services\NetBIOS\Linkage</key>
        <name>Export</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="not equal">0</value>
      </data>
    </registry_test>
    <registry_test id="wrt-393" comment="NetBIOS Bind not disabled" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SYSTEM\CurrentControlSet\Services\NetBIOS\Linkage</key>
        <name>Bind</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="not equal">0</value>
      </data>
    </registry_test>
    <compound_test id="cmp-934" comment="NetBIOS enabled" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-393"/>
      <subtest negate="false" test_ref="wrt-394"/>
      <subtest negate="false" test_ref="wrt-395"/>
    </compound_test>
    <compound_test id="cmp-933" comment="Windows NT or 2000 Installed" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-77"/>
      <subtest negate="false" test_ref="wrt-1"/>
    </compound_test>
    <registry_test id="wrt-399" comment="Remote access to registry not controlled" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">SYSTEM\CurrentControlSet\Control\SecurePipeServers\winreg</key>
        <name operator="pattern match">.*</name>
      </object>
    </registry_test>
    <registry_test id="wrt-459" comment="Everyone group given remote access permissions" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SYSTEM\CurrentControlSet\Control\SecurePipeServers\winreg</key>
        <name>Everyone</name>
      </object>
    </registry_test>
    <registry_test id="wrt-458" comment="Patch Q316056 installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>Software\Microsoft\Updates\Exchange Server 2000\SP3\Q316056</key>
        <name operator="pattern match">.*</name>
      </object>
    </registry_test>
    <file_test id="wft-417" comment="File %ExchangeInstallDir%\bin\mad.exe is less than 6.0.5770.21" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Exchange\Setup\Services</component>
          <component type="literal">\bin\mad.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>5700</build>
          <private>21</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-457" comment="Microsoft Exchange 2000 Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="pattern match">^Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\.*</key>
        <name>DisplayName</name>
      </object>
      <data operation="AND">
        <value operator="equals">Microsoft Exchange 2000</value>
      </data>
    </registry_test>
    <registry_test id="wrt-456" comment="Windows NT Server 4.0, Terminal Server Edition Security Rollup Package" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q317636</key>
        <name>Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <compound_test id="cmp-1044" comment="For Terminal Server" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-43"/>
      <subtest negate="true" test_ref="wrt-456"/>
    </compound_test>
    <file_test id="wft-416" comment="File %windir%\system32\winlogon.exe version is less than 4.0.1381.7058" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\winlogon.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>4</major>
          <minor>0</minor>
          <build>1381</build>
          <private>7058</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-1043" comment="For Windows NT 4.0 Workstation, Server and Enterprise Edition" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wft-416"/>
      <subtest negate="true" test_ref="wrt-243"/>
    </compound_test>
    <file_test id="wft-338" comment="File %windir%\System32\w3svc.dll is less than 4.2.764.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\System32\w3svc.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>4</major>
          <minor>2</minor>
          <build>764</build>
          <private>1</private>
        </version>
      </data>
    </file_test>
    <rpmversioncompare_test id="rvt-347" comment="kernel version is less than 2.4.21-15.EL" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">kernel-unsupported</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">2.4.21</tested_version>
        <tested_release operator="equals">15.EL</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <registry_test id="wrt-157" comment="Drag-and-Drop disabled when set to 3" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key datatype="string" operator="pattern match">^Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\[1-3]$</key>
        <name datatype="boolean" operator="equals">1802</name>
      </object>
      <data operation="AND">
        <value datatype="string" operator="equals">3</value>
      </data>
    </registry_test>
    <file_test id="wft-716" comment="the version of shell32.dll is less than 6.0.2900.2578" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\shell32.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>2900</build>
          <private>2578</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-79" comment="Win2K/XP/2003 service pack 2 (or earlier) is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion</key>
        <name operator="equals">CSDVersion</name>
      </object>
      <data operation="AND">
        <value operator="pattern match">^Service Pack [0-2]$</value>
      </data>
    </registry_test>
    <compound_test id="cmp-178" comment="Windows XP service pack 2 (or earlier) is installed" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-2"/>
      <subtest negate="false" test_ref="wrt-79"/>
    </compound_test>
    <file_test id="wft-185" comment="the version of inetcomm.dll is less than 6.00.2800.1409" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\inetcomm.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>00</minor>
          <build>2800</build>
          <private>1409</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-10" comment="the patch kb840374 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB840374</key>
        <name>Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <compound_test id="cmp-149" comment="64-bit version of Windows and helpctr.exe is less than 5.1.2600.1515" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-70"/>
      <subtest negate="false" test_ref="wft-3"/>
    </compound_test>
    <file_test id="wft-3" comment="the version of helpctr.exe is less than 5.1.2600.1515" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\helpctr.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>1515</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-129" comment="service pack 2 is installed and helpctr.exe is less than 5.1.2600.1515" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-250"/>
      <subtest negate="false" test_ref="wft-3"/>
    </compound_test>
    <file_test id="wft-2" comment="the version of helpctr.exe is less than 5.1.2600.137" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\helpctr.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>137</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-128" comment="service pack 1 or earlier is installed and helpctr.exe is less than 5.1.2600.137" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="true" test_ref="wrt-29"/>
      <subtest negate="false" test_ref="wft-2"/>
    </compound_test>
    <compound_test id="cmp-127" comment="a vulnerable version of helpctr.exe exists exists depending on service pack level" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-128"/>
      <subtest negate="false" test_ref="cmp-129"/>
    </compound_test>
    <compound_test id="cmp-126" comment="32-bit version of Windows and a vulnerable version of helpctr.exe exists" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-72"/>
      <subtest negate="false" test_ref="cmp-127"/>
    </compound_test>
    <compound_test id="cmp-114" comment="a vulnerable version of helpctr.exe exists on XP" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-126"/>
      <subtest negate="false" test_ref="cmp-149"/>
    </compound_test>
    <compound_test id="cmp-155" comment="64-bit version of Windows and msasn1.dll is less than 5.1.2600.1362" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-70"/>
      <subtest negate="false" test_ref="wft-196"/>
    </compound_test>
    <file_test id="wft-196" comment="the version of msasn1.dll is less than 5.1.2600.1362" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\msasn1.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>1362</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-154" comment="service pack 1 is installed and msasn1.dll is less than 5.1.2600.1362" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-4"/>
      <subtest negate="false" test_ref="wft-196"/>
    </compound_test>
    <file_test id="wft-195" comment="the version of msasn1.dll is less than 5.1.2600.137" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\msasn1.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>137</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-153" comment="no service pack is installed and msasn1.dll is less than 5.1.2600.137" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="true" test_ref="wrt-3"/>
      <subtest negate="false" test_ref="wft-195"/>
    </compound_test>
    <compound_test id="cmp-152" comment="a vulnerable version of msasn1.dll exists depending on service pack level" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-153"/>
      <subtest negate="false" test_ref="cmp-154"/>
    </compound_test>
    <compound_test id="cmp-151" comment="32-bit version of Windows and a vulnerable version of msasn1.dll exists" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-72"/>
      <subtest negate="false" test_ref="cmp-152"/>
    </compound_test>
    <compound_test id="cmp-150" comment="a vulnerable version of msasn1.dll exists" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-151"/>
      <subtest negate="false" test_ref="cmp-155"/>
    </compound_test>
    <file_test id="uft-1" comment="/etc/httpd/modules/libphp4.so exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/etc/httpd/modules/libphp4.so</component>
        </path>
      </object>
    </file_test>
    <rpminfo_test id="rrt-217" comment="php rpm is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">php</name>
      </object>
    </rpminfo_test>
    <rpmversioncompare_test id="rvt-363" comment="squirrelmail rpm version prior to 1.4.3-0.e3.1 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">squirrelmail</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">1.4.3</tested_version>
        <tested_release operator="equals">0.e3.1</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <file_test id="wft-404" comment="machine has followed the QFE update path and mshtml.dll is less than 6.0.2800.1492" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mshtml.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>2800</build>
          <private>1492</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-403" comment="machine has followed the GDR update path and mshtml.dll is less than 6.0.2800.1491" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mshtml.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>2800</build>
          <private>1491</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-257" comment="a vulnerable version of mshtml.dll exisits GDR/QFE" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wft-403"/>
      <subtest negate="false" test_ref="wft-404"/>
    </compound_test>
    <file_test id="wft-319" comment="the version of evtgprov.dll is less than 5.1.2600.1363" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\evtgprov.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>1363</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-910" comment="Affected evtgprov.dll versions on Windows XP SP1" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-4"/>
      <subtest negate="false" test_ref="wft-319"/>
    </compound_test>
    <file_test id="wft-318" comment="the version of evtgprov.dll is less than 5.1.2600.136" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\evtgprov.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>136</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-909" comment="No service pack is installed, 32 bit Edition, and evtgprov.dll is less than 5.1.2600.136" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-3"/>
      <subtest negate="false" test_ref="wrt-72"/>
      <subtest negate="false" test_ref="wft-318"/>
    </compound_test>
    <compound_test id="cmp-908" comment="A vulnerable version of evtgprov.dll exists on XP" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-909"/>
      <subtest negate="false" test_ref="cmp-910"/>
    </compound_test>
    <file_test id="wft-317" comment="the version of helpctr.exe is less than 5.1.2600.1340" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\helpctr.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>1340</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-907" comment="Affected helpctr.exe versions on Windows XP SP1" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-4"/>
      <subtest negate="false" test_ref="wft-317"/>
    </compound_test>
    <file_test id="wft-316" comment="the version of helpctr.exe is less than 5.1.2600.128" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\helpctr.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>128</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-906" comment="No service pack is installed, 32 bit Edition, and helpctr.exe is less than 5.1.2600.128" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-3"/>
      <subtest negate="false" test_ref="wrt-72"/>
      <subtest negate="false" test_ref="wft-316"/>
    </compound_test>
    <compound_test id="cmp-905" comment="a vulnerable version of helpctr.exe exists on XP" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-906"/>
      <subtest negate="false" test_ref="cmp-907"/>
    </compound_test>
    <activedirectory_test id="wat-5" comment="Review blocked senders" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <oval:notes>
        <oval:note>Non-perjoritive check</oval:note>
      </oval:notes>
      <object>
        <naming_context operator="equals">configuration</naming_context>
        <relative_dn operator="pattern match">CN=[^,]+,CN=Message Delivery,CN=Global Settings,CN=[^,]+,CN=Microsoft Exchange,CN=Services</relative_dn>
        <attribute operator="equals">msExchTurfListNames</attribute>
      </object>
      <data operation="AND">
        <value operator="equals">.*</value>
      </data>
    </activedirectory_test>
    <process_test id="uct-23" comment="The Xorg X server is running" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <command operator="pattern match">.*Xorg\b.*</command>
      </object>
    </process_test>
    <patch_test id="spt-195" comment="Patch 118966-09 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">118966</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">09</version>
      </data>
    </patch_test>
    <compound_test id="cmp-757" comment="Solaris 10 (x86,Xorg) meets Sun Alert ID 101926 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-10001"/>
      <subtest test_ref="uut-10002"/>
      <subtest negate="true" test_ref="spt-195"/>
      <subtest negate="false" test_ref="uft-33"/>
    </compound_test>
    <file_test id="uft-33" comment="File Xorg exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/X11/bin/Xorg</component>
        </path>
      </object>
    </file_test>
    <patch_test id="spt-193" comment="Patch 118908-02 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">118908</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">02</version>
      </data>
    </patch_test>
    <compound_test id="cmp-755" comment="Solaris 9 (x86,Xorg) meets Sun Alert ID 101926 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-6"/>
      <subtest test_ref="uut-10002"/>
      <subtest negate="true" test_ref="spt-193"/>
      <subtest negate="false" test_ref="uft-33"/>
    </compound_test>
    <permission_test id="upt-29" comment="/proc/ is world-executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/proc/</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-28" comment="/proc/tty/ is world-executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/proc/tty/</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-27" comment="/proc/tty/driver/ is world-executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/proc/tty/driver/</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-26" comment="/proc/tty/driver/serial is world-readable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/proc/tty/driver/serial</component>
        </path>
      </object>
      <data operation="AND">
        <oread datatype="int" operator="equals">1</oread>
      </data>
    </permission_test>
    <rpmversioncompare_test id="rvt-346" comment="kernel version is less than 2.4.21-15.EL" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">kernel</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">2.4.21</tested_version>
        <tested_release operator="equals">15.EL</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <registry_test id="wrt-392" comment="Patch 273991USA8.EXE Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SYSTEM\CurrentControlSet\Services\UtilMan{5c773859-bb96- 48fa-875b-6a58aae072f4}</key>
        <name>IsInstalled</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-337" comment="File %windir%\system\vserver.vxd version is less than 4.10.2001.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system\vserver.vxd</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>4</major>
          <minor>10</minor>
          <build>2001</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-391" comment="Windows 98 Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows\CurrentVersion</key>
        <name>Version</name>
      </object>
      <data operation="AND">
        <value operator="equals">Windows 98</value>
      </data>
    </registry_test>
    <file_test id="wft-289" comment="the version of rpcproxy.dll is less than 5.0.2195.6904" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\rpcproxy.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>2195</build>
          <private>6904</private>
        </version>
      </data>
    </file_test>
    <rpmversioncompare_test id="rvt-362" comment="cvs rpm version prior to 1.11.2-24 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">cvs</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">1.11.2</tested_version>
        <tested_release operator="equals">24</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <patch_test id="hpt-26" comment="Patch PHKL_33714 or later is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <area_patched>PHKL</area_patched>
        <patch_number operator="greater than or equal">33714</patch_number>
      </object>
    </patch_test>
    <patch_test id="hpt-25" comment="Patch PHKL_33713 or later is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <area_patched>PHKL</area_patched>
        <patch_number operator="greater than or equal">33713</patch_number>
      </object>
    </patch_test>
    <compound_test id="cmp-702" comment="Either PHKL_33713 or PHKL_33714 or later is installed" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="hpt-25"/>
      <subtest test_ref="hpt-26"/>
    </compound_test>
    <swlist_test id="hst-33" comment="OS-Core.CORE2-KRN is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <swlist operator="equals">OS-Core.CORE2-KRN</swlist>
      </object>
      <data>
        <version operator="equals">B.11.23</version>
      </data>
    </swlist_test>
    <rpmversioncompare_test id="rvt-361" comment="krb5-libs rpm version prior to 1.2.7-24 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">krb5-libs</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">1.2.7</tested_version>
        <tested_release operator="equals">24</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <file_test id="wft-183" comment="the version of inetcomm.dll is less than 6.00.2739.300" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\inetcomm.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>00</minor>
          <build>2739</build>
          <private>300</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-171" comment="Outlook Express 6 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Outlook Express\Version Info</key>
        <name>Current</name>
      </object>
      <data operation="AND">
        <value operator="equals">6,0,2600,0000</value>
      </data>
    </registry_test>
    <file_test id="wft-84" comment="the version of inetcomm.dll is less than 6.0.2800.1506" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\inetcomm.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>2800</build>
          <private>1506</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-173" comment="Outlook Express 6 SP1 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Outlook Express\Version Info</key>
        <name>Current</name>
      </object>
      <data operation="AND">
        <value operator="equals">6,0,2800,1106</value>
      </data>
    </registry_test>
    <file_test id="wft-336" comment="File %windir%\System32\w3svc.dll is less than 5.1.2600.1125" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\System32\w3svc.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>1125</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-390" comment="IIS 5.1 Minor Version" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\INetStp</key>
        <name>MinorVersion</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <rpmversioncompare_test id="rvt-358" comment="ethereal-gnome version is less than 0.10.3-0.30E.2" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">ethereal-gnome</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">0.10.3</tested_version>
        <tested_release operator="equals">0.30E.2</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <rpmversioncompare_test id="rvt-357" comment="ethereal version is less than 0.10.3-0.30E.2" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">ethereal</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">0.10.3</tested_version>
        <tested_release operator="equals">0.30E.2</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <compound_test id="cmp-1022" comment="Vulnerable Config" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="rvt-357"/>
      <subtest negate="false" test_ref="rvt-358"/>
    </compound_test>
    <inetlisteningservers_test id="rlt-233" comment="squid is listening on the network" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <program_name datatype="string" operator="pattern match">^.*squid</program_name>
      </object>
    </inetlisteningservers_test>
    <rpmversioncompare_test id="rvt-356" comment="squid version is less than 2.5.STABLE3-6.3E" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">squid</name>
        <tested_epoch datatype="int" operator="equals">7</tested_epoch>
        <tested_version operator="equals">2.5.STABLE3</tested_version>
        <tested_release operator="equals">6.3E</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <permission_test id="upt-54" comment="/usr/sbin/utempter is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/sbin/utempter</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-53" comment="/usr/sbin/utempter is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/sbin/utempter</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-52" comment="/usr/sbin/utempter is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/sbin/utempter</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-1021" comment="/usr/sbin/utempter is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-52"/>
      <subtest negate="false" test_ref="upt-53"/>
      <subtest negate="false" test_ref="upt-54"/>
    </compound_test>
    <permission_test id="upt-51" comment="/usr/sbin/utempter is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/sbin/utempter</component>
        </path>
      </object>
      <data operation="AND">
        <sgid datatype="int" operator="equals">1</sgid>
      </data>
    </permission_test>
    <compound_test id="cmp-1020" comment="/usr/sbin/utempter is executable" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-51"/>
      <subtest negate="false" test_ref="cmp-1021"/>
    </compound_test>
    <rpmversioncompare_test id="rvt-355" comment="utempter version is less than 0.5.5-1.3EL.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">utempter</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">0.5.5</tested_version>
        <tested_release operator="equals">1.3EL.0</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <permission_test id="upt-50" comment="/usr/bin/lha is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/lha</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-49" comment="/usr/bin/lha is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/lha</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-48" comment="/usr/bin/lha is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/lha</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-1019" comment="/usr/bin/lha is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-48"/>
      <subtest negate="false" test_ref="upt-49"/>
      <subtest negate="false" test_ref="upt-50"/>
    </compound_test>
    <rpmversioncompare_test id="rvt-354" comment="lha version is less than 1.14i-10.2" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">lha</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">1.14i</tested_version>
        <tested_release operator="equals">10.2</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <permission_test id="upt-47" comment="/usr/sbin/tcpdump is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/sbin/tcpdump</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-46" comment="/usr/sbin/tcpdump is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/sbin/tcpdump</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-45" comment="/usr/sbin/tcpdump is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/sbin/tcpdump</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-1017" comment="/usr/sbin/tcpdump is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-45"/>
      <subtest negate="false" test_ref="upt-46"/>
      <subtest negate="false" test_ref="upt-47"/>
    </compound_test>
    <rpmversioncompare_test id="rvt-353" comment="tcpdump version is less than 3.7.2-7.E3.2" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">tcpdump</name>
        <tested_epoch datatype="int" operator="equals">14</tested_epoch>
        <tested_version operator="equals">3.7.2</tested_version>
        <tested_release operator="equals">7.E3.2</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <rpmversioncompare_test id="rvt-345" comment="libpng10-devel version is less than 1.0.13-12" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">libpng-devel</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">1.0.13</tested_version>
        <tested_release datatype="int" operator="equals">12</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <rpmversioncompare_test id="rvt-344" comment="libpng10 version is less than 1.0.13-12" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">libpng</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">1.0.13</tested_version>
        <tested_release datatype="int" operator="equals">12</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <rpmversioncompare_test id="rvt-343" comment="libpng-devel version is less than 1.2.2-21" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">libpng-devel</name>
        <tested_epoch datatype="int" operator="equals">2</tested_epoch>
        <tested_version operator="equals">1.2.2</tested_version>
        <tested_release datatype="int" operator="equals">21</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <rpmversioncompare_test id="rvt-342" comment="libpng version is less than 1.2.2-21" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">libpng</name>
        <tested_epoch datatype="int" operator="equals">2</tested_epoch>
        <tested_version operator="equals">1.2.2</tested_version>
        <tested_release datatype="int" operator="equals">21</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <compound_test id="cmp-932" comment="libpng/libpng-devel is less than 1.2.2-21 or libpng10/libpng-devel less than 1.0.13 is installed" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="rvt-342"/>
      <subtest negate="false" test_ref="rvt-343"/>
      <subtest negate="false" test_ref="rvt-344"/>
      <subtest negate="false" test_ref="rvt-345"/>
    </compound_test>
    <permission_test id="upt-25" comment="/usr/bin/cvs is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/cvs</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-24" comment="/usr/bin/cvs is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/cvs</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-23" comment="/usr/bin/cvs is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/cvs</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-931" comment="/usr/bin/cvs is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-23"/>
      <subtest negate="false" test_ref="upt-24"/>
      <subtest negate="false" test_ref="upt-25"/>
    </compound_test>
    <rpmversioncompare_test id="rvt-341" comment="cvs version is less than 1.11.2-22" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">cvs</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">1.11.2</tested_version>
        <tested_release datatype="int" operator="equals">22</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <registry_test id="wrt-385" comment="COM Internet Services are enabled" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Ole</key>
        <name>EnableDCOMHTTP</name>
      </object>
      <data operation="AND">
        <value operator="equals">Y</value>
      </data>
    </registry_test>
    <file_test id="wft-299" comment="the version of rpcproxy.dll is less than 4.0.1381.33559" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\rpcproxy.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>4</major>
          <minor>0</minor>
          <build>1381</build>
          <private>33559</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-199" comment="Terminal Server and rpcproxy.dll is less than 4.0.1381.33559" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-43"/>
      <subtest negate="false" test_ref="wft-299"/>
    </compound_test>
    <file_test id="wft-298" comment="the version of rpcproxy.dll is less than 4.0.1381.7255" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\rpcproxy.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>4</major>
          <minor>0</minor>
          <build>1381</build>
          <private>7255</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-198" comment="non Terminal Server and rpcproxy.dll is less than 4.0.1381.7255" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="true" test_ref="wrt-43"/>
      <subtest negate="false" test_ref="wft-298"/>
    </compound_test>
    <compound_test id="cmp-21" comment="a vulnerable version of rpcproxy.dll exists on NT" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-198"/>
      <subtest negate="false" test_ref="cmp-199"/>
    </compound_test>
    <compound_test id="cmp-9" comment="Server or Terminal Server product option" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-50"/>
      <subtest negate="false" test_ref="wrt-43"/>
    </compound_test>
    <compound_test id="cmp-8" comment="Windows NT 4.0 Server or Terminal Server is installed" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-77"/>
      <subtest negate="false" test_ref="cmp-9"/>
    </compound_test>
    <registry_test id="wrt-185" comment="the patch kb837001 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB837001</key>
        <name>Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-181" comment="the version of wmsjet40.dll is less than 4.0.8618.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\wmsjet40.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>4</major>
          <minor>0</minor>
          <build>8618</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-142" comment="64-bit version of Windows and wmsjet40.dll is less than 4.0.8618.0" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-70"/>
      <subtest negate="false" test_ref="wft-181"/>
    </compound_test>
    <file_test id="wft-180" comment="the version of msjet40.dll is less than 4.0.8618.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\msjet40.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>4</major>
          <minor>0</minor>
          <build>8618</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-141" comment="32-bit version of Windows and msjet40.dll is less than 4.0.8618.0" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-72"/>
      <subtest negate="false" test_ref="wft-180"/>
    </compound_test>
    <compound_test id="cmp-140" comment="a vulnerable version of Microsoft Jet 4.0 is installed" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-141"/>
      <subtest negate="false" test_ref="cmp-142"/>
    </compound_test>
    <rpmversioncompare_test id="rvt-340" comment="rsync version is less than 2.5.7-4.3E" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">rsync</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">2.5.7</tested_version>
        <tested_release operator="equals">4.3E</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <file_test id="wft-335" comment="File %windir%\System32\nsiislog.dll is less than 4.1.0.3861" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\System32\nsiislog.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>4</major>
          <minor>1</minor>
          <build>0</build>
          <private>3861</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-165" comment="64-bit version of Windows and h323.tsp is less than 5.1.2600.1348" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-70"/>
      <subtest negate="false" test_ref="wft-152"/>
    </compound_test>
    <file_test id="wft-152" comment="the version of h323.tsp is less than 5.1.2600.1348" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\h323.tsp</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>1348</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-164" comment="service pack 1 is installed and h323.tsp is less than 5.1.2600.1348" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-4"/>
      <subtest negate="false" test_ref="wft-152"/>
    </compound_test>
    <file_test id="wft-153" comment="the version of h323.tsp is less than 5.1.2600.134" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\h323.tsp</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>134</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-163" comment="no service pack is installed and h323.tsp is less than 5.1.2600.134" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="true" test_ref="wrt-3"/>
      <subtest negate="false" test_ref="wft-153"/>
    </compound_test>
    <compound_test id="cmp-162" comment="a vulnerable version of h323.tsp exists depending on service pack level" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-163"/>
      <subtest negate="false" test_ref="cmp-164"/>
    </compound_test>
    <compound_test id="cmp-161" comment="32-bit version of Windows and a vulnerable version of h323.tsp exists" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-72"/>
      <subtest negate="false" test_ref="cmp-162"/>
    </compound_test>
    <compound_test id="cmp-160" comment="a vulnerable version of h323.tsp exists" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-161"/>
      <subtest negate="false" test_ref="cmp-165"/>
    </compound_test>
    <file_test id="wft-315" comment="File %windir%\System32\odbcbcp.dll is less than 2000.80.746.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\odbcbcp.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>2000</major>
          <minor>80</minor>
          <build>746</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-377" comment="DataAccess Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\DataAccess</key>
        <name>FullInstallVer</name>
      </object>
      <data operation="AND">
        <value operator="pattern match">^2\.6.*</value>
      </data>
    </registry_test>
    <registry_test id="wrt-376" comment="Patch Q823718 Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Updates\DataAccess\Q823718</key>
        <name>IsInstalled</name>
      </object>
      <data operation="AND">
        <value datatype="binary" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-314" comment="File %windir%\System32\odbcbcp.dll is less than 3.70.11.40" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\odbcbcp.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>3</major>
          <minor>70</minor>
          <build>11</build>
          <private>40</private>
        </version>
      </data>
    </file_test>
    <rpmversioncompare_test id="rvt-23" comment="ImageMagick RPM earlier than 0:5.5.6-15" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <oval:notes>
        <oval:note>The ImageMagick-* RPMs all require that the main ImageMagick RPM have the same version and release number.</oval:note>
      </oval:notes>
      <object>
        <name operator="equals">ImageMagick</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">5.5.6</tested_version>
        <tested_release operator="equals">15</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <file_test id="wft-138" comment="the version of mf3216.dll is less than 5.0.2195.6898" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mf3216.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>2195</build>
          <private>6898</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-15" comment="64-bit version of Windows and rpcss.dll is less than 5.1.2600.1361" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-70"/>
      <subtest negate="false" test_ref="wft-198"/>
    </compound_test>
    <file_test id="wft-198" comment="the version of rpcss.dll is less than 5.1.2600.1361" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\rpcss.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>1361</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-14" comment="service pack 1 is installed and rpcss.dll is less than 5.1.2600.1361" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-4"/>
      <subtest negate="false" test_ref="wft-198"/>
    </compound_test>
    <file_test id="wft-197" comment="the version of rpcss.dll is less than 5.1.2600.135" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\rpcss.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>135</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-13" comment="no service pack is installed and rpcss.dll is less than 5.1.2600.135" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="true" test_ref="wrt-3"/>
      <subtest negate="false" test_ref="wft-197"/>
    </compound_test>
    <compound_test id="cmp-12" comment="a vulnerable version of rpcss.dll exists depending on service pack level" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-13"/>
      <subtest negate="false" test_ref="cmp-14"/>
    </compound_test>
    <compound_test id="cmp-11" comment="32-bit version of Windows and a vulnerable version of rpcss.dll exists" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-72"/>
      <subtest negate="false" test_ref="cmp-12"/>
    </compound_test>
    <compound_test id="cmp-10" comment="a vulnerable version of rpcss.dll exists on XP" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-11"/>
      <subtest negate="false" test_ref="cmp-15"/>
    </compound_test>
    <file_test id="wft-199" comment="the version of rpcss.dll is less than 5.2.3790.142" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\rpcss.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>2</minor>
          <build>3790</build>
          <private>142</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-20" comment="64-bit machine and rpcss.dll is less than 5.2.3790.146" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-70"/>
      <subtest negate="false" test_ref="wft-199"/>
    </compound_test>
    <unknown_test id="ukn-19" comment="machine has followed the QFE update path and rpcss.dll is less than 5.2.3790.142" xmlns="http://oval.mitre.org/XMLSchema/oval#independent"/>
    <unknown_test id="ukn-18" comment="machine has followed the GDR update path and rpcss.dll is less than 5.2.3790.132" xmlns="http://oval.mitre.org/XMLSchema/oval#independent"/>
    <compound_test id="cmp-19" comment="a vulnerable version of rpcss.dll exists on non 64-bit Server 2003" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="ukn-18"/>
      <subtest negate="false" test_ref="ukn-19"/>
    </compound_test>
    <compound_test id="cmp-18" comment="32-bit machine a vulnerable version of rpcss.dll exists" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-72"/>
      <subtest negate="false" test_ref="cmp-19"/>
    </compound_test>
    <compound_test id="cmp-16" comment="a vulnerable version of rpcss.dll exists on Server 2003" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-18"/>
      <subtest negate="false" test_ref="cmp-20"/>
    </compound_test>
    <registry_test id="wrt-491" comment="HTML Help is registered" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Classes\ITSProtocol</key>
        <name operator="pattern match">.*</name>
      </object>
    </registry_test>
    <registry_test id="wrt-482" comment="the patch kb840315 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB840315</key>
        <name>Installed</name>
      </object>
      <data operation="AND">
        <value datatype="binary" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-444" comment="the version of itss.dll is less than 5.2.3790.185" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\itss.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>2</minor>
          <build>3790</build>
          <private>185</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-1071" comment="Internet Explorer 5.5 SP2 or Internet Explorer 6.0 SP1 is installed" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-50"/>
      <subtest negate="false" test_ref="wrt-51"/>
      <subtest negate="false" test_ref="wrt-53"/>
    </compound_test>
    <file_test id="wft-189" comment="the version of rpcss.dll is less than 5.0.2195.6906" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\rpcss.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>2195</build>
          <private>6906</private>
        </version>
      </data>
    </file_test>
    <permission_test id="upt-22" comment="/usr/bin/kmail is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/kmail</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-21" comment="/usr/bin/kmail is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/kmail</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-20" comment="/usr/bin/kmail is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/kmail</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-930" comment="/usr/bin/kmail is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-20"/>
      <subtest negate="false" test_ref="upt-21"/>
      <subtest negate="false" test_ref="upt-22"/>
    </compound_test>
    <permission_test id="upt-19" comment="/usr/bin/ssh is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ssh</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-18" comment="/usr/bin/ssh is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ssh</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-17" comment="/usr/bin/ssh is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ssh</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-929" comment="/usr/bin/ssh is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-17"/>
      <subtest negate="false" test_ref="upt-18"/>
      <subtest negate="false" test_ref="upt-19"/>
    </compound_test>
    <permission_test id="upt-16" comment="/usr/kerberos/bin/rlogin is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/kerberos/bin/rlogin</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-15" comment="/usr/kerberos/bin/rlogin is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/kerberos/bin/rlogin</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-14" comment="/usr/kerberos/bin/rlogin is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/kerberos/bin/rlogin</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-928" comment="/usr/kerberos/bin/rlogin is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-14"/>
      <subtest negate="false" test_ref="upt-15"/>
      <subtest negate="false" test_ref="upt-16"/>
    </compound_test>
    <permission_test id="upt-13" comment="/usr/bin/rlogin is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/rlogin</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-12" comment="/usr/bin/rlogin is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/rlogin</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-11" comment="/usr/bin/rlogin is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/rlogin</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-927" comment="/usr/bin/rlogin is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-11"/>
      <subtest negate="false" test_ref="upt-12"/>
      <subtest negate="false" test_ref="upt-13"/>
    </compound_test>
    <permission_test id="upt-10" comment="/usr/kerberos/bin/telnet is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/kerberos/bin/telnet</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-9" comment="/usr/kerberos/bin/telnet is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/kerberos/bin/telnet</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-8" comment="/usr/kerberos/bin/telnet is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/kerberos/bin/telnet</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-926" comment="/usr/kerberos/bin/telnet is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-8"/>
      <subtest negate="false" test_ref="upt-9"/>
      <subtest negate="false" test_ref="upt-10"/>
    </compound_test>
    <permission_test id="upt-7" comment="/usr/bin/telnet is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/telnet</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-6" comment="/usr/bin/telnet is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/telnet</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-5" comment="/usr/bin/telnet is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/telnet</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-925" comment="/usr/bin/telnet is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-5"/>
      <subtest negate="false" test_ref="upt-6"/>
      <subtest negate="false" test_ref="upt-7"/>
    </compound_test>
    <compound_test id="cmp-924" comment="telnet, rlogin, ssh or kmail is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-925"/>
      <subtest negate="false" test_ref="cmp-926"/>
      <subtest negate="false" test_ref="cmp-927"/>
      <subtest negate="false" test_ref="cmp-928"/>
      <subtest negate="false" test_ref="cmp-929"/>
      <subtest negate="false" test_ref="cmp-930"/>
    </compound_test>
    <rpmversioncompare_test id="rvt-339" comment="kdelibs version is less than 3.1.3-6.4" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">kdelibs</name>
        <tested_epoch datatype="int" operator="equals">6</tested_epoch>
        <tested_version operator="equals">3.1.3</tested_version>
        <tested_release operator="equals">6.4</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <file_test id="wft-313" comment="File %windir%\system32\snmp.exe is less than 4.0.1381.133" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\snmp.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>4</major>
          <minor>0</minor>
          <build>1381</build>
          <private>133</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-151" comment="the version of h323.tsp is less than 5.2.3790.132" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\h323.tsp</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>2</minor>
          <build>3790</build>
          <private>132</private>
        </version>
      </data>
    </file_test>
    <inetlisteningservers_test id="rlt-230" comment="racoon is listening on the network" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <program_name datatype="string" operator="pattern match">^.*racoon</program_name>
      </object>
      <data operation="AND">
        <protocol operator="equals">UDP</protocol>
      </data>
    </inetlisteningservers_test>
    <rpmversioncompare_test id="rvt-338" comment="ipsec-tools version is less than 0.2.5-0.4" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">ipsec-tools</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">0.2.5</tested_version>
        <tested_release operator="equals">0.4</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <rpmversioncompare_test id="rvt-337" comment="squid version is less than 2.5.STABLE3-5.3E" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">squid</name>
        <tested_epoch datatype="int" operator="equals">7</tested_epoch>
        <tested_version operator="equals">2.5.STABLE3</tested_version>
        <tested_release operator="equals">5.3E</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <permission_test id="upt-4" comment="/bin/mount is world-executable AND Set-UID" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/bin/mount</component>
        </path>
      </object>
      <data operation="AND">
        <suid datatype="int" operator="equals">1</suid>
      </data>
    </permission_test>
    <permission_test id="upt-3" comment="/bin/mount is world-executable AND Set-UID" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/bin/mount</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <compound_test id="cmp-923" comment="/bin/mount is world-executable AND Set-UID" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-3"/>
      <subtest negate="false" test_ref="upt-4"/>
    </compound_test>
    <rpmversioncompare_test id="rvt-336" comment="kernel-hugemem version is less than 2.4.21-9.0.3.EL" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">kernel-hugemem</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">2.4.21</tested_version>
        <tested_release operator="equals">9.0.3.EL</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <rpmversioncompare_test id="rvt-335" comment="kernel-smp version is less than 2.4.21-9.0.3.EL" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">kernel-smp</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">2.4.21</tested_version>
        <tested_release operator="equals">9.0.3.EL</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <rpmversioncompare_test id="rvt-334" comment="kernel version is less than 2.4.21-9.0.3.EL" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">kernel</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">2.4.21</tested_version>
        <tested_release operator="equals">9.0.3.EL</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <compound_test id="cmp-921" comment="kernel versions" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="rvt-334"/>
      <subtest negate="false" test_ref="rvt-335"/>
      <subtest negate="false" test_ref="rvt-336"/>
    </compound_test>
    <file_test id="wft-334" comment="File %windir%\System32\nsiislog.dll is less than 4.1.0.3932" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\System32\nsiislog.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>4</major>
          <minor>1</minor>
          <build>0</build>
          <private>3932</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-389" comment="Patch KB822343 Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB822343</key>
        <name>Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <registry_test id="wrt-388" comment="Patch KB817772 Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB817772</key>
        <name>Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-333" comment="File %windir%\System32\nsiislog.dll is less than 4.1.0.3931" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\System32\nsiislog.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>4</major>
          <minor>1</minor>
          <build>0</build>
          <private>3931</private>
        </version>
      </data>
    </file_test>
    <patch_test id="hpt-23" comment="Patch PHNE_32606 or later is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <area_patched>PHNE</area_patched>
        <patch_number operator="greater than or equal">32606</patch_number>
      </object>
    </patch_test>
    <swlist_test id="hst-57" comment="Networking.NET2-KRN is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <swlist operator="equals">Networking.NET2-KRN</swlist>
      </object>
    </swlist_test>
    <activedirectory_test id="wat-4" comment="Review block-list exception values" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <oval:notes>
        <oval:note>Non-perjoritive test</oval:note>
      </oval:notes>
      <object>
        <naming_context operator="equals">configuration</naming_context>
        <relative_dn operator="equals">CN=[^,]+,CN=Message Delivery,CN=Global Settings,CN=[^,]+,CN=Microsoft Exchange,CN=Services</relative_dn>
        <attribute operator="equals">msExchRecipTurfListNames</attribute>
      </object>
      <data operation="AND">
        <value operator="pattern match">.*</value>
      </data>
    </activedirectory_test>
    <registry_test id="wrt-387" comment="Patch Q811114 Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\Hotfix\Q811114</key>
        <name>Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-332" comment="File %windir%\System32\w3svc.dll is less than 5.0.2195.6672" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\System32\w3svc.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>2195</build>
          <private>6672</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-386" comment="Patch Q232449 Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q232449</key>
        <name>Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-331" comment="File %windir%\System32\code.asp is less than 4.0.1381.279" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\System32\code.asp</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>4</major>
          <minor>0</minor>
          <build>1381</build>
          <private>279</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-330" comment="File %windir%\System32\msw3prt.dll is less than 5.0.2195.5807" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\System32\msw3prt.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>2195</build>
          <private>5807</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-329" comment="File %windir%\System32\w3svc.dll is less than 4.2.780.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\System32\w3svc.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>4</major>
          <minor>2</minor>
          <build>780</build>
          <private>1</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-312" comment="File %windir%\system32\urlmon.dll version is less than 5.50.4927.2100" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mshtml.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>50</minor>
          <build>4927</build>
          <private>2100</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-371" comment="Run ActiveX Controls and Plugins Allowed In At Least One Zone" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="pattern match">^SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\[0-4]$</key>
        <name datatype="int">1200</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="not equal">3</value>
      </data>
    </registry_test>
    <compound_test id="cmp-903" comment="Run ActiveX Controls and Plugins Not Disabled" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-368"/>
      <subtest negate="false" test_ref="wrt-371"/>
    </compound_test>
    <file_test id="wft-311" comment="File %windir%\system32\mshtml.dll version is less than 6.0.2713.1100" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mshtml.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>2713</build>
          <private>1100</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-194" comment="the version of msasn1.dll is less than 5.2.3790.139" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\msasn1.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>2</minor>
          <build>3790</build>
          <private>139</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-310" comment="File %windir%\system32\mshtml.dll version is less than 6.0.2716.2200" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mshtml.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>2716</build>
          <private>2200</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-309" comment="the version of mshtml.dll is less than 5.50.4926.2500" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mshtml.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>50</minor>
          <build>4926</build>
          <private>2500</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-369" comment="File Downloads Allowed In At Least One Zone" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="pattern match">^SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\[0-4]$</key>
        <name datatype="int">1803</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="not equal">3</value>
      </data>
    </registry_test>
    <registry_test id="wrt-368" comment="Use Machine Settings" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings</key>
        <name>Security_HKLM_only</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <compound_test id="cmp-902" comment="File Downloads Not Disabled" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-368"/>
      <subtest negate="false" test_ref="wrt-369"/>
    </compound_test>
    <registry_test id="wrt-356" comment="Patch Q319282 Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>Software\Microsoft\Active Setup\Installed Components\{2D5974C5-5185-4f5b-80B6-28015ACDD74C}</key>
        <name>IsInstalled</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <registry_test id="wrt-355" comment="Patch Q316059.exe Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>Software\Microsoft\Active Setup\Installed Components\{E81659DF-28E1-4C60-B4B9-00A4BC5FA76D}</key>
        <name>IsInstalled</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <registry_test id="wrt-354" comment="Patch Q313675 Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>Software\Microsoft\Active Setup\Installed Components\{716E024F-7F74-47F3-B93B-9FF7F3CBF94C}</key>
        <name>IsInstalled</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-308" comment="the version of mshtml.dll is less than 6.0.2712.0300" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mshtml.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>2712</build>
          <private>0300</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-352" comment="Patch Q295106 Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>Software\Microsoft\Active Setup\Installed Components\{754D29C1-0C97-405F-98D0-21B212CA7FF1}</key>
        <name>IsInstalled</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <registry_test id="wrt-351" comment="Patch Q286045 Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>Software\Microsoft\Active Setup\Installed Components\{A954CDD5-A95F-414F-B3FE-FBEF9D2AECEA}</key>
        <name>IsInstalled</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-307" comment="File %windir%\system32\mshtml.dll version is less than 5.50.4613.1700" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mshtml.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>50</minor>
          <build>4613</build>
          <private>1700</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-350" comment="Internet Explorer 5.5 Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Internet Explorer</key>
        <name>Version</name>
      </object>
      <data operation="AND">
        <value operator="equals">5.50.4522.1800</value>
      </data>
    </registry_test>
    <registry_test id="wrt-349" comment="Internet Explorer 5.5 Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Internet Explorer</key>
        <name>Version</name>
      </object>
      <data operation="AND">
        <value operator="equals">5.50.4134.0600</value>
      </data>
    </registry_test>
    <registry_test id="wrt-348" comment="Internet Explorer 5.5 Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Internet Explorer</key>
        <name>Version</name>
      </object>
      <data operation="AND">
        <value operator="equals">5.50.4134.0100</value>
      </data>
    </registry_test>
    <compound_test id="cmp-901" comment="Internet Explorer 5.5 Installed" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-348"/>
      <subtest negate="false" test_ref="wrt-349"/>
      <subtest negate="false" test_ref="wrt-350"/>
    </compound_test>
    <file_test id="wft-157" comment="the version of lsasrv.dll is less than 5.2.3790.134" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\lsasrv.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>2</minor>
          <build>3790</build>
          <private>134</private>
        </version>
      </data>
    </file_test>
    <wmi_test id="wwt-1" comment="Integrated Windows Authentication is used for all directories" check="none exist" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <namespace operator="equals">root\MicrosoftIIsv2</namespace>
        <wql operator="equals">SELECT AuthNTLM from IIsWebDirectorySetting where AuthNTLM = FALSE</wql>
      </object>
    </wmi_test>
    <rpmversioncompare_test id="rvt-330" comment="mozilla-nss version is less than 1.4.2-3.0.2" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">mozilla-nss</name>
        <tested_epoch datatype="int" operator="equals">37</tested_epoch>
        <tested_version operator="equals">1.4.2</tested_version>
        <tested_release operator="equals">3.0.2</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <registry_test id="wrt-347" comment="Win2K/XP/2003 service pack 6 (or later) is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key datatype="string" operator="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion</key>
        <name datatype="string" operator="equals">CSDVersion</name>
      </object>
      <data operation="AND">
        <value datatype="string" operator="pattern match">^Service Pack [6-9]|\d{2,}$</value>
      </data>
    </registry_test>
    <file_test id="wft-306" comment="File %windir%\System32\w3svc.dll is less than 4.0.1381.164" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\w3svc.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>4</major>
          <minor>0</minor>
          <build>1381</build>
          <private>164</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-305" comment="File %windir%\System32\Msw3prt.dll is less than 5.0.2195.3649" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\Msw3prt.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>2195</build>
          <private>3649</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-190" comment="the version of wintrust.dll is less than 5.131.1880.14" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\wintrust.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>131</minor>
          <build>1880</build>
          <private>14</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-673" comment="nwwks.dll is less than 5.2.3790.2506" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\nwwks.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>2</minor>
          <build>3790</build>
          <private>2506</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-304" comment="File %windir%\System32\w3svc.dll is less than 4.2.769.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\w3svc.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>4</major>
          <minor>2</minor>
          <build>769</build>
          <private>1</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-150" comment="the version of h323.tsp is less than 5.0.2195.6901" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\h323.tsp</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>2195</build>
          <private>6901</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-194" comment=" a vulnerable version of agentdpv exists for Windows Gold 64-bit (x64)" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-22"/>
      <subtest negate="true" test_ref="wrt-3"/>
      <subtest negate="false" test_ref="wft-118"/>
    </compound_test>
    <file_test id="wft-118" comment="the version of agentdpv.dll is less than 5.2.3790.1241" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\agentdpv.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>2</minor>
          <build>3790</build>
          <private>1241</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-192" comment=" a vulnerable version of agentdpv exists" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-23"/>
      <subtest negate="false" test_ref="wrt-4"/>
      <subtest negate="false" test_ref="wft-118"/>
    </compound_test>
    <compound_test id="cmp-191" comment="a vulnerable version of agentdpv exists" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-23"/>
      <subtest negate="true" test_ref="wrt-3"/>
      <subtest negate="false" test_ref="wft-117"/>
    </compound_test>
    <compound_test id="cmp-200" comment=" a vulnerable version of agentdpv exists" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-191"/>
      <subtest negate="false" test_ref="cmp-192"/>
      <subtest negate="false" test_ref="cmp-194"/>
    </compound_test>
    <registry_test id="wrt-12" comment="the HCP Protocol is registered" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_CLASSES_ROOT</hive>
        <key operator="equals">HCP</key>
        <name operator="pattern match">.*</name>
      </object>
    </registry_test>
    <file_test id="wft-303" comment="the version of helpctr.exe is less than 5.2.3790.125" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\helpctr.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>2</minor>
          <build>3790</build>
          <private>125</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-170" comment="the version of schannel.dll is less than 4.87.1964.1880" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\schannel.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>4</major>
          <minor>87</minor>
          <build>1964</build>
          <private>1880</private>
        </version>
      </data>
    </file_test>
    <rpmversioncompare_test id="rvt-322" comment="openssl096b version is less than 0.9.6b-15" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">openssl096b</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">0.9.6b</tested_version>
        <tested_release datatype="int" operator="equals">15</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <rpmversioncompare_test id="rvt-321" comment="openssl096 version is less than 0.9.6-25.9" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">openssl096</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">0.9.6</tested_version>
        <tested_release operator="equals">25.9</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <rpmversioncompare_test id="rvt-320" comment="openssl-perl version is less than 0.9.7a-20" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">openssl-perl</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">0.9.7a</tested_version>
        <tested_release operator="equals">20.2</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <rpmversioncompare_test id="rvt-319" comment="openssl-devel version is less than 0.9.7a-20" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">openssl-devel</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">0.9.7a</tested_version>
        <tested_release operator="equals">20.2</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <rpmversioncompare_test id="rvt-318" comment="openssl version is less than 0.9.7a-20" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">openssl</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">0.9.7a</tested_version>
        <tested_release operator="equals">20.2</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <compound_test id="cmp-38" comment="Windows Server 2003 or Windows XP 64-Bit Edition Version 2003" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-61"/>
      <subtest negate="false" test_ref="cmp-1112"/>
    </compound_test>
    <compound_test id="cmp-187" comment="Windows Server 2003 32-bit OR 64-bit OR Windows XP 64-bit Version 2003 is installed" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-38"/>
      <subtest negate="false" test_ref="cmp-34"/>
    </compound_test>
    <registry_test id="wrt-91" comment="the patch KB873333 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB873333</key>
        <name operator="equals">Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-389" comment="the version of ole32.dll is less than 5.2.3790.250" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\ole32.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>2</minor>
          <build>3790</build>
          <private>250</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-6" comment="64-bit version of Windows and rpcrt4.dll is less than 5.1.2600.1361" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-70"/>
      <subtest negate="false" test_ref="wft-188"/>
    </compound_test>
    <file_test id="wft-188" comment="the version of rpcrt4.dll is less than 5.1.2600.1361" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\rpcrt4.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>1361</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-5" comment="service pack 1 is installed and rpcrt4.dll is less than 5.1.2600.1361" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-4"/>
      <subtest negate="false" test_ref="wft-188"/>
    </compound_test>
    <file_test id="wft-187" comment="the version of rpcrt4.dll is less than 5.1.2600.135" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\rpcrt4.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>135</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-4" comment="no service pack is installed and rpcrt4.dll is less than 5.1.2600.135" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="true" test_ref="wrt-3"/>
      <subtest negate="false" test_ref="wft-187"/>
    </compound_test>
    <compound_test id="cmp-3" comment="a vulnerable version of rpcrt4.dll exists depending on service pack level" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-4"/>
      <subtest negate="false" test_ref="cmp-5"/>
    </compound_test>
    <compound_test id="cmp-2" comment="32-bit version of Windows and a vulnerable version of rpcrt4.dll exists" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-72"/>
      <subtest negate="false" test_ref="cmp-3"/>
    </compound_test>
    <compound_test id="cmp-1" comment="a vulnerable version of rpcrt4.dll exists on XP" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-2"/>
      <subtest negate="false" test_ref="cmp-6"/>
    </compound_test>
    <compound_test id="cmp-148" comment="64-bit version of Windows and lsasrv.dll is less than 5.1.2600.1361" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-70"/>
      <subtest negate="false" test_ref="wft-159"/>
    </compound_test>
    <file_test id="wft-159" comment="the version of lsasrv.dll is less than 5.1.2600.1361" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\lsasrv.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>1361</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-147" comment="service pack 1 is installed and lsasrv.dll is less than 5.1.2600.1361" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-4"/>
      <subtest negate="false" test_ref="wft-159"/>
    </compound_test>
    <file_test id="wft-158" comment="the version of lsasrv.dll is less than 5.1.2600.134" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\lsasrv.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>134</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-146" comment="no service pack is installed and lsasrv.dll is less than 5.1.2600.134" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="true" test_ref="wrt-3"/>
      <subtest negate="false" test_ref="wft-158"/>
    </compound_test>
    <compound_test id="cmp-145" comment="a vulnerable version of lsasrv.dll exists depending on service pack level" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-146"/>
      <subtest negate="false" test_ref="cmp-147"/>
    </compound_test>
    <compound_test id="cmp-144" comment="32-bit version of Windows and a vulnerable version of lsasrv.dll exists" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-72"/>
      <subtest negate="false" test_ref="cmp-145"/>
    </compound_test>
    <compound_test id="cmp-143" comment="a vulnerable version of lsasrv.dll exists on XP" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-144"/>
      <subtest negate="false" test_ref="cmp-148"/>
    </compound_test>
    <file_test id="wft-137" comment="the version of mf3216.dll is less than 4.0.1381.33562" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mf3216.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>4</major>
          <minor>0</minor>
          <build>1381</build>
          <private>33562</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-91" comment="NT Terminal Server and mf3216.dll is less than 4.0.1381.33562" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-43"/>
      <subtest negate="false" test_ref="wft-137"/>
    </compound_test>
    <file_test id="wft-136" comment="the version of mf3216.dll is less than 4.0.1381.7263" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mf3216.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>4</major>
          <minor>0</minor>
          <build>1381</build>
          <private>7263</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-90" comment="non Terminal Server and mf3216.dll is less than 4.0.1381.7263" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="true" test_ref="wrt-43"/>
      <subtest negate="false" test_ref="wft-136"/>
    </compound_test>
    <compound_test id="cmp-89" comment="a vulnerable version of mf3216.dll exists on NT" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-90"/>
      <subtest negate="false" test_ref="cmp-91"/>
    </compound_test>
    <file_test id="wft-133" comment="the version of msgina.dll is less than 5.0.2195.6895" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\msjet40.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>2195</build>
          <private>6895</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-196" comment="machine is a member of a domain" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SYSTEM\CurrentControlSet\Services\Netlogon</key>
        <name>Start</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">2</value>
      </data>
    </registry_test>
    <file_test id="wft-132" comment="the version of msgina.dll is less than 4.0.1381.33559" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\msgina.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>4</major>
          <minor>0</minor>
          <build>1381</build>
          <private>33559</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-138" comment="Terminal Server and msgina.dll is less than 4.0.1381.33559" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-43"/>
      <subtest negate="false" test_ref="wft-132"/>
    </compound_test>
    <file_test id="wft-131" comment="the version of msgina.dll is less than 4.0.1381.7255" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\msgina.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>4</major>
          <minor>0</minor>
          <build>1381</build>
          <private>7255</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-137" comment="non Terminal Server and msgina.dll is less than 4.0.1381.7255" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="true" test_ref="wrt-43"/>
      <subtest negate="false" test_ref="wft-131"/>
    </compound_test>
    <compound_test id="cmp-136" comment="a vulnerable version of msgina.dll exists on NT" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-137"/>
      <subtest negate="false" test_ref="cmp-138"/>
    </compound_test>
    <unknown_test id="ukn-17" comment="machine has followed the QFE update path and rpcrt4.dll is less than 5.2.3790.141" xmlns="http://oval.mitre.org/XMLSchema/oval#independent"/>
    <unknown_test id="ukn-16" comment="machine has followed the GDR update path and rpcrt4.dll is less than 5.2.3790.137" xmlns="http://oval.mitre.org/XMLSchema/oval#independent"/>
    <compound_test id="cmp-17" comment="a vulnerable version of rpcrt4.dll exists on Server 2003" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="ukn-16"/>
      <subtest negate="false" test_ref="ukn-17"/>
    </compound_test>
    <registry_test id="wrt-189" comment="the patch kb828741 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB828741</key>
        <name>Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-186" comment="the version of rpcrt4.dll is less than 5.0.2195.6904" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\rpcrt4.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>2195</build>
          <private>6904</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-171" comment="the version of schannel.dll is less than 5.1.2195.6899" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\schannel.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2195</build>
          <private>6899</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-191" comment="the version of wintrust.dll is less than 5.131.2195.6824" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\wintrust.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>131</minor>
          <build>2195</build>
          <private>6824</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-165" comment="PCT support is disabled" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\PCT 1.0\Server</key>
        <name>Enabled</name>
      </object>
      <data operation="AND">
        <value datatype="binary" operator="equals">1</value>
      </data>
    </registry_test>
    <rpmversioncompare_test id="rvt-329" comment="ethereal-gnome version is less than 0.10.3-0.30E.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">ethereal-gnome</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">0.10.3</tested_version>
        <tested_release operator="equals">0.30E.1</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <rpmversioncompare_test id="rvt-328" comment="ethereal version is less than 0.10.3-0.30E.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">ethereal</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">0.10.3</tested_version>
        <tested_release operator="equals">0.30E.1</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <compound_test id="cmp-863" comment="Vulnerable Config" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="rvt-328"/>
      <subtest negate="false" test_ref="rvt-329"/>
    </compound_test>
    <compound_test id="cmp-135" comment="64-bit version of Windows and schannel.dll is less than 5.1.2600.1347" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-70"/>
      <subtest negate="false" test_ref="wft-174"/>
    </compound_test>
    <file_test id="wft-174" comment="the version of schannel.dll is less than 5.1.2600.1347" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\schannel.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>1347</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-134" comment="service pack 1 is installed and schannel.dll is less than 5.1.2600.1347" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-4"/>
      <subtest negate="false" test_ref="wft-174"/>
    </compound_test>
    <file_test id="wft-173" comment="the version of schannel.dll is less than 5.1.2600.136" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\schannel.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>136</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-133" comment="no service pack is installed and schannel.dll is less than 5.1.2600.136" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="true" test_ref="wrt-3"/>
      <subtest negate="false" test_ref="wft-173"/>
    </compound_test>
    <compound_test id="cmp-132" comment="a vulnerable version of schannel.dll exists depending on service pack level" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-133"/>
      <subtest negate="false" test_ref="cmp-134"/>
    </compound_test>
    <compound_test id="cmp-131" comment="32-bit version of Windows and a vulnerable version of schannel.dll exists" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-72"/>
      <subtest negate="false" test_ref="cmp-132"/>
    </compound_test>
    <compound_test id="cmp-130" comment="a vulnerable version of schannel.dll exists" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-131"/>
      <subtest negate="false" test_ref="cmp-135"/>
    </compound_test>
    <metabase_test id="wmt-5" comment="SSL is enabled" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <key datatype="string" operator="pattern match">^LM\\W3SVC\\.*$</key>
        <id datatype="int" operator="equals">5506</id>
      </object>
    </metabase_test>
    <file_test id="wft-172" comment="the version of schannel.dll is less than 5.2.3790.132" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\schannel.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>2</minor>
          <build>3790</build>
          <private>132</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-187" comment="the patch kb835732 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB835732</key>
        <name>Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-192" comment="the version of lsasrv.dll is less than 5.0.2195.6902" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\lsasrv.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>2195</build>
          <private>6902</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-188" comment="the patch kb837009 is installed (installed components key)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Active Setup\Installed Components\{2cc9d512-6db6-4f1c-8979-9a41fae88de0}</key>
        <name>IsInstalled</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-182" comment="the version of inetcomm.dll is less than 5.50.4939.300" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\inetcomm.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>50</minor>
          <build>4939</build>
          <private>300</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-170" comment="Outlook Express 5.5 SP2 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Outlook Express\Version Info</key>
        <name>Current</name>
      </object>
      <data operation="AND">
        <value operator="equals">5,50,4807,1700</value>
      </data>
    </registry_test>
    <patch_test id="spt-302" comment="Patch 121005-01 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">121005</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="equals">01</version>
      </data>
    </patch_test>
    <compound_test id="cmp-855" comment="Solaris 10 (x86) meets Sun Alert ID 102282 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-10001"/>
      <subtest test_ref="uut-10002"/>
      <subtest negate="true" test_ref="spt-302"/>
    </compound_test>
    <patch_test id="spt-301" comment="Patch 118536-03 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">118536</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="equals">03</version>
      </data>
    </patch_test>
    <compound_test id="cmp-854" comment="Solaris 9 (x86) meets Sun Alert ID 102282 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-6"/>
      <subtest test_ref="uut-10002"/>
      <subtest negate="true" test_ref="spt-301"/>
    </compound_test>
    <patch_test id="spt-300" comment="Patch 109325-09 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">109325</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="equals">09</version>
      </data>
    </patch_test>
    <compound_test id="cmp-853" comment="Solaris 8 (x86) meets Sun Alert ID 102282 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-4"/>
      <subtest test_ref="uut-10002"/>
      <subtest negate="true" test_ref="spt-300"/>
    </compound_test>
    <patch_test id="spt-299" comment="Patch 121004-01 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">121004</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="equals">01</version>
      </data>
    </patch_test>
    <compound_test id="cmp-847" comment="Solaris 10 (SPARC) meets Sun Alert ID 102282 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-10001"/>
      <subtest test_ref="uut-10003"/>
      <subtest negate="true" test_ref="spt-299"/>
    </compound_test>
    <patch_test id="spt-298" comment="Patch 118535-03 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">118535</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="equals">03</version>
      </data>
    </patch_test>
    <compound_test id="cmp-846" comment="Solaris 9 (SPARC) meets Sun Alert ID 102282 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-6"/>
      <subtest test_ref="uut-10003"/>
      <subtest negate="true" test_ref="spt-298"/>
    </compound_test>
    <patch_test id="spt-297" comment="Patch 109324-09 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">109324</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="equals">09</version>
      </data>
    </patch_test>
    <compound_test id="cmp-845" comment="Solaris 8 (SPARC) meets Sun Alert ID 102282 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-4"/>
      <subtest test_ref="uut-10003"/>
      <subtest negate="true" test_ref="spt-297"/>
    </compound_test>
    <permission_test id="upt-823" comment="/usr/bin/tethereal is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/tethereal</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-822" comment="/usr/bin/tethereal is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/tethereal</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-821" comment="/usr/bin/tethereal is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/tethereal</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-852" comment="/usr/bin/tethereal is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-821"/>
      <subtest negate="false" test_ref="upt-822"/>
      <subtest negate="false" test_ref="upt-823"/>
    </compound_test>
    <permission_test id="upt-820" comment="/usr/sbin/ethereal is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/sbin/ethereal</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-819" comment="/usr/sbin/ethereal is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/sbin/ethereal</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-818" comment="/usr/sbin/ethereal is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/sbin/ethereal</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-851" comment="/usr/sbin/ethereal is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-818"/>
      <subtest negate="false" test_ref="upt-819"/>
      <subtest negate="false" test_ref="upt-820"/>
    </compound_test>
    <permission_test id="upt-817" comment="/usr/bin/ethereal is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ethereal</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-816" comment="/usr/bin/ethereal is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ethereal</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-815" comment="/usr/bin/ethereal is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ethereal</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-850" comment="/usr/bin/ethereal is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-815"/>
      <subtest negate="false" test_ref="upt-816"/>
      <subtest negate="false" test_ref="upt-817"/>
    </compound_test>
    <compound_test id="cmp-849" comment="Vulnerable Config" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-850"/>
      <subtest negate="false" test_ref="cmp-851"/>
      <subtest negate="false" test_ref="cmp-852"/>
    </compound_test>
    <rpmversioncompare_test id="rvt-327" comment="ethereal-gnome version is less than 0.10.3-0.90.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">ethereal-gnome</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">0.10.3</tested_version>
        <tested_release operator="equals">0.90.1</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <rpmversioncompare_test id="rvt-326" comment="ethereal version is less than 0.10.3-0.90.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">ethereal</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">0.10.3</tested_version>
        <tested_release operator="equals">0.90.1</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <compound_test id="cmp-848" comment="Vulnerable Config" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="rvt-326"/>
      <subtest negate="false" test_ref="rvt-327"/>
    </compound_test>
    <inetlisteningservers_test id="rlt-225" comment="squid is listening on the network" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <program_name datatype="string" operator="pattern match">^.*squid.*</program_name>
      </object>
    </inetlisteningservers_test>
    <rpmversioncompare_test id="rvt-325" comment="squid version is less than 2.5STABLE1-3.9" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">squid</name>
        <tested_epoch datatype="int" operator="equals">7</tested_epoch>
        <tested_version operator="equals">2.5STABLE1</tested_version>
        <tested_release operator="equals">3.9</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <rpmversioncompare_test id="rvt-323" comment="mod_ssl version is less than 2.0.46-32.ent" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">mod_ssl</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">2.0.46</tested_version>
        <tested_release datatype="int" operator="equals">32.ent</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <permission_test id="upt-814" comment="/usr/bin/mozilla is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/mozilla</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-813" comment="/usr/bin/mozilla is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/mozilla</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-812" comment="/usr/bin/mozilla is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/mozilla</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-844" comment="/usr/bin/mozilla is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-812"/>
      <subtest negate="false" test_ref="upt-813"/>
      <subtest negate="false" test_ref="upt-814"/>
    </compound_test>
    <rpmversioncompare_test id="rvt-317" comment="mozilla version is less than 1.4.2-0.9.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">mozilla</name>
        <tested_epoch datatype="int" operator="equals">37</tested_epoch>
        <tested_version operator="equals">1.4.2</tested_version>
        <tested_release operator="equals">0.9.0</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <rpmversioncompare_test id="rvt-316" comment="mozilla-nss version is less than 1.4.2-0.9.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">mozilla-nss</name>
        <tested_epoch datatype="int" operator="equals">37</tested_epoch>
        <tested_version operator="equals">1.4.2</tested_version>
        <tested_release operator="equals">0.9.0</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <rpmversioncompare_test id="rvt-315" comment="openssl096b version is less than 0.9.6b-16" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">openssl096b</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">0.9.6b</tested_version>
        <tested_release datatype="int" operator="equals">16</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <rpmversioncompare_test id="rvt-314" comment="openssl-perl version is less than 0.9.7a-33.4" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">openssl-perl</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">0.9.7a</tested_version>
        <tested_release operator="equals">33.4</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <rpmversioncompare_test id="rvt-313" comment="openssl-devel version is less than 0.9.7a-33.4" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">openssl-devel</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">0.9.7a</tested_version>
        <tested_release operator="equals">33.4</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <rpmversioncompare_test id="rvt-312" comment="openssl version is less than 0.9.7a-33.4" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">openssl</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">0.9.7a</tested_version>
        <tested_release operator="equals">33.4</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <inetlisteningservers_test id="rlt-223" comment="snmpd is listening to the network" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <program_name datatype="string" operator="pattern match">^.*snmpd.*</program_name>
      </object>
    </inetlisteningservers_test>
    <rpmversioncompare_test id="rvt-311" comment="net-snmp version is less than 5.0.9-2.30E.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">net-snmp</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">5.0.9</tested_version>
        <tested_release operator="equals">2.30E.1</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <rpmversioncompare_test id="rvt-310" comment="kernel version is less than 2.4.21-9.EL" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">kernel</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">2.4.21</tested_version>
        <tested_release operator="equals">9.EL</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <uname_test id="uut-3" comment="ix86 architecture" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <data operation="AND">
        <machine_class datatype="string" operator="equals">x86_64</machine_class>
      </data>
    </uname_test>
    <rpmversioncompare_test id="rvt-309" comment="kernel-bigmem version is less than 2.4.21-4.0.2.EL" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">kernel-bigmem</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">2.4.21</tested_version>
        <tested_release operator="equals">4.0.2.EL</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <rpmversioncompare_test id="rvt-308" comment="kernel-smp version is less than 2.4.21-4.0.2.EL" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">kernel-smp</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">2.4.21</tested_version>
        <tested_release operator="equals">4.0.2.EL</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <rpmversioncompare_test id="rvt-307" comment="kernel version is less than 2.4.21-4.0.2.EL" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">kernel</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">2.4.21</tested_version>
        <tested_release operator="equals">4.0.2.EL</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <compound_test id="cmp-843" comment="Vulnerable Configuration" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="rvt-307"/>
      <subtest negate="false" test_ref="rvt-308"/>
      <subtest negate="false" test_ref="rvt-309"/>
    </compound_test>
    <rpmversioncompare_test id="rvt-306" comment="cvs version is less than 1.11.2-14" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">cvs</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">1.11.2</tested_version>
        <tested_release datatype="int" operator="equals">14</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <rpmversioncompare_test id="rvt-305" comment="kdepim version is less than 3.1.3-3.3" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">kdepim</name>
        <tested_epoch datatype="int" operator="equals">6</tested_epoch>
        <tested_version operator="equals">3.1.3</tested_version>
        <tested_release operator="equals">3.3</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <rpmversioncompare_test id="rvt-304" comment="httpd version is less than 2.0.46-26.ent" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">httpd</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">2.0.46</tested_version>
        <tested_release operator="equals">26.ent</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <rpmversioncompare_test id="rvt-303" comment="httpd version is less than 2.0.40-21.9" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">httpd</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">2.0.40</tested_version>
        <tested_release operator="equals">21.9</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <rpmversioncompare_test id="rvt-302" comment="sysstat version is less than 4.0.7-4.EL3.2" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">sysstat</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">4.0.7</tested_version>
        <tested_release operator="equals">4.EL3.2</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <inetlisteningservers_test id="rlt-221" comment="rpc.mountd is listening to the network" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <program_name datatype="string" operator="pattern match">^.*rpc\.mountd</program_name>
      </object>
    </inetlisteningservers_test>
    <rpmversioncompare_test id="rvt-301" comment="nfs-utils version is less than 1.0.6-7.EL" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">nfs-utils</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">1.0.6</tested_version>
        <tested_release operator="equals">7.EL</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <rpmversioncompare_test id="rvt-300" comment="kernel-bigmem version is less than 2.4.20-28.9" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">kernel-bigmem</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">2.4.20</tested_version>
        <tested_release operator="equals">28.9</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <rpmversioncompare_test id="rvt-299" comment="kernel-smp version is less than 2.4.20-28.9" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">kernel-smp</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">2.4.20</tested_version>
        <tested_release operator="equals">28.9</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <rpmversioncompare_test id="rvt-298" comment="kernel version is less than 2.4.20-28.9" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">kernel</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">2.4.20</tested_version>
        <tested_release operator="equals">28.9</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <compound_test id="cmp-840" comment="Vulnerable Configuration" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="rvt-298"/>
      <subtest negate="false" test_ref="rvt-299"/>
      <subtest negate="false" test_ref="rvt-300"/>
    </compound_test>
    <permission_test id="upt-811" comment="/usr/share/services/kfile_vcf.desktop is readable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/share/services/kfile_vcf.desktop</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-810" comment="/usr/share/services/kfile_vcf.desktop is readable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/share/services/kfile_vcf.desktop</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-809" comment="/usr/share/services/kfile_vcf.desktop is readable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/share/services/kfile_vcf.desktop</component>
        </path>
      </object>
      <data operation="AND">
        <uread datatype="int" operator="equals">1</uread>
      </data>
    </permission_test>
    <compound_test id="cmp-839" comment="/usr/share/services/kfile_vcf.desktop is readable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-809"/>
      <subtest negate="false" test_ref="upt-810"/>
      <subtest negate="false" test_ref="upt-811"/>
    </compound_test>
    <rpmversioncompare_test id="rvt-297" comment="kdepim version is less than 3.1-6" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">kdepim</name>
        <tested_epoch datatype="int" operator="equals">6</tested_epoch>
        <tested_version operator="equals">3.1</tested_version>
        <tested_release datatype="int" operator="equals">6</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <permission_test id="upt-808" comment="/usr/sbin/tethereal is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/sbin/tethereal</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-807" comment="/usr/sbin/tethereal is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/sbin/tethereal</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-806" comment="/usr/sbin/tethereal is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/sbin/tethereal</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-833" comment="/usr/sbin/tethereal is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-806"/>
      <subtest negate="false" test_ref="upt-807"/>
      <subtest negate="false" test_ref="upt-808"/>
    </compound_test>
    <permission_test id="upt-805" comment="/usr/sbin/ethereal is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/sbin/ethereal</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-804" comment="/usr/sbin/ethereal is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/sbin/ethereal</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-803" comment="/usr/sbin/ethereal is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/sbin/ethereal</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-832" comment="/usr/sbin/ethereal is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-803"/>
      <subtest negate="false" test_ref="upt-804"/>
      <subtest negate="false" test_ref="upt-805"/>
    </compound_test>
    <permission_test id="upt-802" comment="/usr/bin/ethereal is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ethereal</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-801" comment="/usr/bin/ethereal is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ethereal</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-800" comment="/usr/bin/ethereal is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ethereal</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-831" comment="/usr/bin/ethereal is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-800"/>
      <subtest negate="false" test_ref="upt-801"/>
      <subtest negate="false" test_ref="upt-802"/>
    </compound_test>
    <compound_test id="cmp-830" comment="Vulnerable Config" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-831"/>
      <subtest negate="false" test_ref="cmp-832"/>
      <subtest negate="false" test_ref="cmp-833"/>
    </compound_test>
    <rpmversioncompare_test id="rvt-296" comment="ethereal-gnome version is less than 0.10.0a-0.90.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">ethereal=gnome</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">0.10.0a</tested_version>
        <tested_release operator="equals">0.90.1</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <rpmversioncompare_test id="rvt-295" comment="ethereal version is less than 0.10.0a-0.90.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">ethereal</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">0.10.0a</tested_version>
        <tested_release operator="equals">0.90.1</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <compound_test id="cmp-829" comment="Vulnerable Config" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="rvt-295"/>
      <subtest negate="false" test_ref="rvt-296"/>
    </compound_test>
    <permission_test id="upt-799" comment="/ is world-writable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/</component>
        </path>
      </object>
      <data operation="AND">
        <owrite datatype="int" operator="equals">1</owrite>
      </data>
    </permission_test>
    <rpmversioncompare_test id="rvt-294" comment="cvs version is less than 1.11.2-13" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">cvs</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">1.11.2</tested_version>
        <tested_release datatype="int" operator="equals">13</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <rpmversioncompare_test id="rvt-293" comment="tcpdump version is less than 3.7.2-7.E3.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">tcpdump</name>
        <tested_epoch datatype="int" operator="equals">14</tested_epoch>
        <tested_version operator="equals">3.7.2</tested_version>
        <tested_release operator="equals">7.E3.1</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <rpmversioncompare_test id="rvt-292" comment="sysstat version is less than 4.0.7-4.rhl9.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">sysstat</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">4.0.7</tested_version>
        <tested_release operator="equals">4.rhl9.1</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <permission_test id="upt-798" comment="/usr/sbin/tcpdump is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/sbin/tcpdump</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-797" comment="/usr/sbin/tcpdump is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/sbin/tcpdump</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-796" comment="/usr/sbin/tcpdump is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/sbin/tcpdump</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-823" comment="/usr/sbin/tcpdump is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-796"/>
      <subtest negate="false" test_ref="upt-797"/>
      <subtest negate="false" test_ref="upt-798"/>
    </compound_test>
    <rpmversioncompare_test id="rvt-291" comment="tcpdump version is less than 3.7.2-7.9.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">tcpdump</name>
        <tested_epoch datatype="int" operator="equals">14</tested_epoch>
        <tested_version operator="equals">3.7.2</tested_version>
        <tested_release operator="equals">7.9.1</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <rpmversioncompare_test id="rvt-290" comment="gdk-pixbuf-gnome version is less than 0.22.0-6.1.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">gdk-pixbuf-gnome</name>
        <tested_epoch datatype="int" operator="equals">1</tested_epoch>
        <tested_version operator="equals">0.22.0</tested_version>
        <tested_release operator="equals">6.1.0</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <rpmversioncompare_test id="rvt-289" comment="gdk-pixbuf-devel version is less than 0.22.0-6.1.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">gdk-pixbuf-devel</name>
        <tested_epoch datatype="int" operator="equals">1</tested_epoch>
        <tested_version operator="equals">0.22.0</tested_version>
        <tested_release operator="equals">6.1.0</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <rpmversioncompare_test id="rvt-288" comment="gdk-pixbuf version is less than 0.22.0-6.1.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">gdk-pixbuf</name>
        <tested_epoch datatype="int" operator="equals">1</tested_epoch>
        <tested_version operator="equals">0.22.0</tested_version>
        <tested_release operator="equals">6.1.0</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <compound_test id="cmp-822" comment="Vulnerable configuration" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="rvt-288"/>
      <subtest negate="false" test_ref="rvt-289"/>
      <subtest negate="false" test_ref="rvt-290"/>
    </compound_test>
    <rpmversioncompare_test id="rvt-287" comment="gdk-pixbuf-gnome version is less than 0.22.0-6.0.3" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">gdk-pixbuf-gnome</name>
        <tested_epoch datatype="int" operator="equals">1</tested_epoch>
        <tested_version operator="equals">0.22.0</tested_version>
        <tested_release operator="equals">6.0.3</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <rpmversioncompare_test id="rvt-286" comment="gdk-pixbuf-devel version is less than 0.22.0-6.0.3" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">gdk-pixbuf-devel</name>
        <tested_epoch datatype="int" operator="equals">1</tested_epoch>
        <tested_version operator="equals">0.22.0</tested_version>
        <tested_release operator="equals">6.0.3</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <rpmversioncompare_test id="rvt-285" comment="gdk-pixbuf version is less than 0.22.0-6.0.3" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">gdk-pixbuf</name>
        <tested_epoch datatype="int" operator="equals">1</tested_epoch>
        <tested_version operator="equals">0.22.0</tested_version>
        <tested_release operator="equals">6.0.3</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <compound_test id="cmp-821" comment="Vulnerable configuration" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="rvt-285"/>
      <subtest negate="false" test_ref="rvt-286"/>
      <subtest negate="false" test_ref="rvt-287"/>
    </compound_test>
    <file_test id="wft-30" comment="the version of msgsc.dll is less than 6.1.0.211" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir</component>
          <component type="literal">\MSN Messenger\msgsc.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>1</minor>
          <build>0</build>
          <private>211</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-45" comment="the version of msgsc.dll is greater than 6.0.0.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir</component>
          <component type="literal">\MSN Messenger\msgsc.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="greater than">
          <major>6</major>
          <minor>0</minor>
          <build>0</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-68" comment="Microsoft MSN Messenger 6.0 or 6.1 (but less than 6.1.0211) is installed" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wft-45"/>
      <subtest negate="false" test_ref="wft-30"/>
    </compound_test>
    <registry_test id="wrt-199" comment="Microsoft Office XP Service Pack 3 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90280409-6000-11D3-8CFE-0050048383C9}</key>
        <name>DisplayVersion</name>
      </object>
      <data operation="AND">
        <value>10.0.6626.0</value>
      </data>
    </registry_test>
    <registry_test id="wrt-198" comment="the patch kb828040 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90280409-6000-11D3-8CFE-0050048383C9}</key>
        <name>DisplayVersion</name>
      </object>
      <data operation="AND">
        <value>10.0.4333.0</value>
      </data>
    </registry_test>
    <file_test id="wft-130" comment="the version of outlook.exe is less than 10.00.5709.0000" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\OUTLOOK.EXE\Path</component>
          <component type="literal">outlook.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>10</major>
          <minor>00</minor>
          <build>5709</build>
          <private>0000</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-197" comment="Outlook 2002 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Office\10.0\Outlook\InstallRoot</key>
        <name operator="pattern match">.*</name>
      </object>
    </registry_test>
    <registry_test id="wrt-161" comment="the Windows Media Monitor service is disabled" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">SOFTWARE\Microsoft\Updates\Windows Media Services\KB832359</key>
        <name>Start</name>
      </object>
      <data operation="AND">
        <value operator="not equal">4</value>
      </data>
    </registry_test>
    <registry_test id="wrt-160" comment="the Windows Media Station service is disabled" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">SYSTEM\CurrentControlSet\Services\nsstation</key>
        <name>Start</name>
      </object>
      <data operation="AND">
        <value operator="not equal">4</value>
      </data>
    </registry_test>
    <unknown_test id="ukn-3" comment="configured to only offer streaming media over unicast" xmlns="http://oval.mitre.org/XMLSchema/oval#independent"/>
    <registry_test id="wrt-149" comment="the patch kb832359 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">SOFTWARE\Microsoft\Updates\Windows Media Services\KB832359</key>
        <name>IsInstalled</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-47" comment="the version of nspmon.exe is less than 4.1.0.3934" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\Windows Media\Server\nspmon.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>4</major>
          <minor>1</minor>
          <build>0</build>
          <private>3934</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-46" comment="the version of nscm.exe is less than 4.1.0.3934" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\Windows Media\Server\nscm.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>4</major>
          <minor>1</minor>
          <build>0</build>
          <private>3934</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-162" comment="Windows Media Services 4.1 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\NetShow</key>
        <name>Version</name>
      </object>
      <data operation="AND">
        <value operator="equals">4.1</value>
      </data>
    </registry_test>
    <compound_test id="cmp-59" comment="Windows Media Services 4.1 is installed on Microsoft Windows 2000 Server" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-162"/>
      <subtest negate="false" test_ref="cmp-60"/>
    </compound_test>
    <rpmversioncompare_test id="rvt-284" comment="mutt version is less than 1.4.1-3.4" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">mutt</name>
        <tested_epoch datatype="int" operator="equals">5</tested_epoch>
        <tested_version operator="equals">1.4.1</tested_version>
        <tested_release operator="equals">3.4</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <rpmversioncompare_test id="rvt-283" comment="kernel-bigmem version is less than 2.4.20-30.9" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">kernel-bigmem</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">2.4.20</tested_version>
        <tested_release operator="equals">30.9</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <rpmversioncompare_test id="rvt-282" comment="kernel-smp version is less than 2.4.20-30.9" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">kernel-smp</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">2.4.20</tested_version>
        <tested_release operator="equals">30.9</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <rpmversioncompare_test id="rvt-281" comment="kernel version is less than 2.4.20-30.9" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">kernel</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">2.4.20</tested_version>
        <tested_release operator="equals">30.9</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <compound_test id="cmp-816" comment="Vulnerable Configuration" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="rvt-281"/>
      <subtest negate="false" test_ref="rvt-282"/>
      <subtest negate="false" test_ref="rvt-283"/>
    </compound_test>
    <rpmversioncompare_test id="rvt-280" comment="libxml2-python version is less than 2.5.10-6" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">libxml2-python</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">2.5.10</tested_version>
        <tested_release datatype="int" operator="equals">6</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <rpmversioncompare_test id="rvt-279" comment="libxml2-devel version is less than 2.5.10-6" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">libxml2-devel</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">2.5.10</tested_version>
        <tested_release datatype="int" operator="equals">6</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <rpmversioncompare_test id="rvt-278" comment="libxml2 version is less than 2.5.10-6" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">libxml2</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">2.5.10</tested_version>
        <tested_release datatype="int" operator="equals">6</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <compound_test id="cmp-815" comment="Vulnerable Config" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="rvt-278"/>
      <subtest negate="false" test_ref="rvt-279"/>
      <subtest negate="false" test_ref="rvt-280"/>
    </compound_test>
    <rpmversioncompare_test id="rvt-277" comment="XFree86 version is less than 4.3.0-55.EL" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">XFree86</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">4.3.0</tested_version>
        <tested_release operator="equals">55.EL</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <inetlisteningservers_test id="rlt-220" comment="httpd is listening to the network" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <program_name datatype="string" operator="pattern match">^.*httpd</program_name>
      </object>
      <data operation="AND">
        <protocol operator="equals">TCP</protocol>
      </data>
    </inetlisteningservers_test>
    <rpmversioncompare_test id="rvt-276" comment="mod_python version is less than 3.0.1-4" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">mod_python</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">3.0.1</tested_version>
        <tested_release datatype="int" operator="equals">4</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <rpmversioncompare_test id="rvt-275" comment="samba version is less than 3.0.2-6.3E" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">samba</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">3.0.2</tested_version>
        <tested_release operator="equals">6.3E</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <rpmversioncompare_test id="rvt-274" comment="pwlib version is less than 1.4.7-7.EL" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">pwlib</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">1.4.7</tested_version>
        <tested_release operator="equals">7.EL</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <rpmversioncompare_test id="rvt-273" comment="kernel-hugemem version is less than 2.4.21-9.0.1.EL" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">kernel-hugemem</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">2.4.21</tested_version>
        <tested_release operator="equals">9.0.1.EL</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <rpmversioncompare_test id="rvt-272" comment="kernel-smp version is less than 2.4.21-9.0.1.EL" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">kernel-smp</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">2.4.21</tested_version>
        <tested_release operator="equals">9.0.1.EL</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <rpmversioncompare_test id="rvt-271" comment="kernel version is less than 2.4.21-9.0.1.EL" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">kernel</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">2.4.21</tested_version>
        <tested_release operator="equals">9.0.1.EL</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <compound_test id="cmp-808" comment="Vulnerable Config" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="rvt-271"/>
      <subtest negate="false" test_ref="rvt-272"/>
      <subtest negate="false" test_ref="rvt-273"/>
    </compound_test>
    <rpmversioncompare_test id="rvt-270" comment="kdelibs version is less than 3.1-13" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">kdelibs</name>
        <tested_epoch datatype="int" operator="equals">6</tested_epoch>
        <tested_version operator="equals">3.1</tested_version>
        <tested_release datatype="int" operator="equals">13</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <permission_test id="upt-795" comment="/usr/bin/mc is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/mc</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-794" comment="/usr/bin/mc is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/mc</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-793" comment="/usr/bin/mc is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/mc</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-806" comment="/usr/bin/mc is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-793"/>
      <subtest negate="false" test_ref="upt-794"/>
      <subtest negate="false" test_ref="upt-795"/>
    </compound_test>
    <rpmversioncompare_test id="rvt-269" comment="mc version is less than 4.6.0-7.9" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">mc</name>
        <tested_epoch datatype="int" operator="equals">1</tested_epoch>
        <tested_version operator="equals">4.6.0</tested_version>
        <tested_release operator="equals">7.9</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <permission_test id="upt-792" comment="/usr/bin/slocate is setgid" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/slocate</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-791" comment="/usr/bin/slocate is setgid" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/slocate</component>
        </path>
      </object>
      <data operation="AND">
        <sgid datatype="int" operator="equals">1</sgid>
      </data>
    </permission_test>
    <compound_test id="cmp-805" comment="/usr/bin/slocate is setgid" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-791"/>
      <subtest negate="false" test_ref="upt-792"/>
    </compound_test>
    <rpmversioncompare_test id="rvt-268" comment="slocate version is less than 2.7-2" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">slocate</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">2.7</tested_version>
        <tested_release datatype="int" operator="equals">2</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <permission_test id="upt-790" comment="/usr/bin/gaim is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/gaim</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-789" comment="/usr/bin/gaim is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/gaim</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-788" comment="/usr/bin/gaim is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/gaim</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-802" comment="/usr/bin/gaim is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-788"/>
      <subtest negate="false" test_ref="upt-789"/>
      <subtest negate="false" test_ref="upt-790"/>
    </compound_test>
    <rpmversioncompare_test id="rvt-267" comment="gaim version is less than 0.75-0.9.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">gaim</name>
        <tested_epoch datatype="int" operator="equals">1</tested_epoch>
        <tested_version operator="equals">0.75</tested_version>
        <tested_release operator="equals">0.9.0</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <inetlisteningservers_test id="rlt-218" comment="httpd is listening on the network" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <program_name datatype="string" operator="pattern match">^.*httpd.*</program_name>
      </object>
      <data operation="AND">
        <protocol operator="equals">TCP</protocol>
      </data>
    </inetlisteningservers_test>
    <rpmversioncompare_test id="rvt-266" comment="mailman version is less than 2.1.1-5" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">mailman</name>
        <tested_epoch datatype="int" operator="equals">3</tested_epoch>
        <tested_version operator="equals">2.1.1</tested_version>
        <tested_release datatype="int" operator="equals">5</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <file_test id="wft-797" comment="the version of inetcomm.dll is less than 6.0.3790.2663" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\inetcomm.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>3790</build>
          <private>2663</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-10004" comment="Outlook Express 6.0 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Outlook Express\Version Info</key>
        <name>Current</name>
      </object>
      <data operation="AND">
        <value operator="pattern match">6\.0\..*</value>
      </data>
    </registry_test>
    <rpmversioncompare_test id="rvt-265" comment="mutt version is less than 1.4.1-3.3" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">mutt</name>
        <tested_epoch datatype="int" operator="equals">5</tested_epoch>
        <tested_version operator="equals">1.4.1</tested_version>
        <tested_release operator="equals">3.3</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <rpmversioncompare_test id="rvt-264" comment="netpbm-progs version is less than 9.24-11.30.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">netpbm-progs</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">9.24</tested_version>
        <tested_release operator="equals">11.30.1</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <rpmversioncompare_test id="rvt-263" comment="netpbm-devel version is less than 9.24-11.30.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">netpbm-devel</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">9.24</tested_version>
        <tested_release operator="equals">11.30.1</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <rpmversioncompare_test id="rvt-262" comment="netpbm version is less than 9.24-11.30.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">netpbm</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">9.24</tested_version>
        <tested_release operator="equals">11.30.1</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <compound_test id="cmp-574" comment="Vulnerable Config" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="rvt-262"/>
      <subtest negate="false" test_ref="rvt-263"/>
      <subtest negate="false" test_ref="rvt-264"/>
    </compound_test>
    <permission_test id="upt-787" comment="/usr/X11R6/bin/XFree86 is SUID and executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/X11R6/bin/XFree86</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-786" comment="/usr/X11R6/bin/XFree86 is SUID and executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/X11R6/bin/XFree86</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <compound_test id="cmp-569" comment="/usr/X11R6/bin/XFree86 is SUID and executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-786"/>
      <subtest negate="false" test_ref="upt-787"/>
    </compound_test>
    <permission_test id="upt-785" comment="/usr/X11R6/bin/XFree86 is SUID and executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/X11R6/bin/XFree86</component>
        </path>
      </object>
      <data operation="AND">
        <suid datatype="int" operator="equals">1</suid>
      </data>
    </permission_test>
    <compound_test id="cmp-568" comment="/usr/X11R6/bin/XFree86 is SUID and executable" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-785"/>
      <subtest negate="false" test_ref="cmp-569"/>
    </compound_test>
    <rpmversioncompare_test id="rvt-261" comment="XFree86 version is less than 4.3.0-2.90.55" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">XFree86</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">4.3.0</tested_version>
        <tested_release operator="equals">2.90.55</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <permission_test id="upt-657" comment="/usr/bin/ppmtopi1 is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmtopi1</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-656" comment="/usr/bin/ppmtopi1 is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmtopi1</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-655" comment="/usr/bin/ppmtopi1 is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmtopi1</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-525" comment="/usr/bin/ppmtopi1 is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-655"/>
      <subtest negate="false" test_ref="upt-656"/>
      <subtest negate="false" test_ref="upt-657"/>
    </compound_test>
    <permission_test id="upt-654" comment="/usr/bin/ppmtopgm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmtopgm</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-653" comment="/usr/bin/ppmtopgm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmtopgm</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-652" comment="/usr/bin/ppmtopgm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmtopgm</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-524" comment="/usr/bin/ppmtopgm is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-652"/>
      <subtest negate="false" test_ref="upt-653"/>
      <subtest negate="false" test_ref="upt-654"/>
    </compound_test>
    <permission_test id="upt-651" comment="/usr/bin/ppmtopcx is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmtopcx</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-650" comment="/usr/bin/ppmtopcx is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmtopcx</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-649" comment="/usr/bin/ppmtopcx is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmtopcx</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-523" comment="/usr/bin/ppmtopcx is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-649"/>
      <subtest negate="false" test_ref="upt-650"/>
      <subtest negate="false" test_ref="upt-651"/>
    </compound_test>
    <permission_test id="upt-648" comment="/usr/bin/ppmtoneo is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmtoneo</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-647" comment="/usr/bin/ppmtoneo is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmtoneo</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-646" comment="/usr/bin/ppmtoneo is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmtoneo</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-522" comment="/usr/bin/ppmtoneo is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-646"/>
      <subtest negate="false" test_ref="upt-647"/>
      <subtest negate="false" test_ref="upt-648"/>
    </compound_test>
    <permission_test id="upt-645" comment="/usr/bin/ppmtompeg is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmtompeg</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-644" comment="/usr/bin/ppmtompeg is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmtompeg</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-643" comment="/usr/bin/ppmtompeg is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmtompeg</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-521" comment="/usr/bin/ppmtompeg is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-643"/>
      <subtest negate="false" test_ref="upt-644"/>
      <subtest negate="false" test_ref="upt-645"/>
    </compound_test>
    <permission_test id="upt-642" comment="/usr/bin/ppmtomitsu is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmtomitsu</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-641" comment="/usr/bin/ppmtomitsu is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmtomitsu</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-640" comment="/usr/bin/ppmtomitsu is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmtomitsu</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-520" comment="/usr/bin/ppmtomitsu is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-640"/>
      <subtest negate="false" test_ref="upt-641"/>
      <subtest negate="false" test_ref="upt-642"/>
    </compound_test>
    <permission_test id="upt-639" comment="/usr/bin/ppmtolj is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmtolj</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-638" comment="/usr/bin/ppmtolj is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmtolj</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-637" comment="/usr/bin/ppmtolj is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmtolj</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-519" comment="/usr/bin/ppmtolj is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-637"/>
      <subtest negate="false" test_ref="upt-638"/>
      <subtest negate="false" test_ref="upt-639"/>
    </compound_test>
    <permission_test id="upt-636" comment="/usr/bin/ppmtoleaf is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmtoleaf</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-635" comment="/usr/bin/ppmtoleaf is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmtoleaf</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-634" comment="/usr/bin/ppmtoleaf is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmtoleaf</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-518" comment="/usr/bin/ppmtoleaf is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-634"/>
      <subtest negate="false" test_ref="upt-635"/>
      <subtest negate="false" test_ref="upt-636"/>
    </compound_test>
    <permission_test id="upt-633" comment="/usr/bin/ppmtojpeg is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmtojpeg</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-632" comment="/usr/bin/ppmtojpeg is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmtojpeg</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-631" comment="/usr/bin/ppmtojpeg is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmtojpeg</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-517" comment="/usr/bin/ppmtojpeg is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-631"/>
      <subtest negate="false" test_ref="upt-632"/>
      <subtest negate="false" test_ref="upt-633"/>
    </compound_test>
    <permission_test id="upt-630" comment="/usr/bin/ppmtoilbm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmtoilbm</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-629" comment="/usr/bin/ppmtoilbm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmtoilbm</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-628" comment="/usr/bin/ppmtoilbm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmtoilbm</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-516" comment="/usr/bin/ppmtoilbm is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-628"/>
      <subtest negate="false" test_ref="upt-629"/>
      <subtest negate="false" test_ref="upt-630"/>
    </compound_test>
    <permission_test id="upt-627" comment="/usr/bin/ppmtoicr is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmtoicr</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-626" comment="/usr/bin/ppmtoicr is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmtoicr</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-625" comment="/usr/bin/ppmtoicr is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmtoicr</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-515" comment="/usr/bin/ppmtoicr is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-625"/>
      <subtest negate="false" test_ref="upt-626"/>
      <subtest negate="false" test_ref="upt-627"/>
    </compound_test>
    <permission_test id="upt-624" comment="/usr/bin/ppmtogif is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmtogif</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-623" comment="/usr/bin/ppmtogif is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmtogif</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-622" comment="/usr/bin/ppmtogif is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmtogif</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-514" comment="/usr/bin/ppmtogif is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-622"/>
      <subtest negate="false" test_ref="upt-623"/>
      <subtest negate="false" test_ref="upt-624"/>
    </compound_test>
    <permission_test id="upt-621" comment="/usr/bin/ppmtoeyuv is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmtoeyuv</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-620" comment="/usr/bin/ppmtoeyuv is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmtoeyuv</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-619" comment="/usr/bin/ppmtoeyuv is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmtoeyuv</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-513" comment="/usr/bin/ppmtoeyuv is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-619"/>
      <subtest negate="false" test_ref="upt-620"/>
      <subtest negate="false" test_ref="upt-621"/>
    </compound_test>
    <permission_test id="upt-618" comment="/usr/bin/ppmtobmp is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmtobmp</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-617" comment="/usr/bin/ppmtobmp is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmtobmp</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-616" comment="/usr/bin/ppmtobmp is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmtobmp</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-512" comment="/usr/bin/ppmtobmp is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-616"/>
      <subtest negate="false" test_ref="upt-617"/>
      <subtest negate="false" test_ref="upt-618"/>
    </compound_test>
    <permission_test id="upt-615" comment="/usr/bin/ppmtoacad is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmtoacad</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-614" comment="/usr/bin/ppmtoacad is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmtoacad</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-613" comment="/usr/bin/ppmtoacad is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmtoacad</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-511" comment="/usr/bin/ppmtoacad is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-613"/>
      <subtest negate="false" test_ref="upt-614"/>
      <subtest negate="false" test_ref="upt-615"/>
    </compound_test>
    <permission_test id="upt-612" comment="/usr/bin/ppmspread is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmspread</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-611" comment="/usr/bin/ppmspread is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmspread</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-610" comment="/usr/bin/ppmspread is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmspread</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-510" comment="/usr/bin/ppmspread is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-610"/>
      <subtest negate="false" test_ref="upt-611"/>
      <subtest negate="false" test_ref="upt-612"/>
    </compound_test>
    <permission_test id="upt-609" comment="/usr/bin/ppmshift is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmshift</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-608" comment="/usr/bin/ppmshift is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmshift</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-607" comment="/usr/bin/ppmshift is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmshift</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-509" comment="/usr/bin/ppmshift is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-607"/>
      <subtest negate="false" test_ref="upt-608"/>
      <subtest negate="false" test_ref="upt-609"/>
    </compound_test>
    <permission_test id="upt-606" comment="/usr/bin/ppmrelief is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmrelief</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-605" comment="/usr/bin/ppmrelief is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmrelief</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-604" comment="/usr/bin/ppmrelief is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmrelief</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-508" comment="/usr/bin/ppmrelief is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-604"/>
      <subtest negate="false" test_ref="upt-605"/>
      <subtest negate="false" test_ref="upt-606"/>
    </compound_test>
    <permission_test id="upt-603" comment="/usr/bin/ppmqvga is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmqvga</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-602" comment="/usr/bin/ppmqvga is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmqvga</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-601" comment="/usr/bin/ppmqvga is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmqvga</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-507" comment="/usr/bin/ppmqvga is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-601"/>
      <subtest negate="false" test_ref="upt-602"/>
      <subtest negate="false" test_ref="upt-603"/>
    </compound_test>
    <permission_test id="upt-600" comment="/usr/bin/ppmquant is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmquant</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-599" comment="/usr/bin/ppmquant is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmquant</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-598" comment="/usr/bin/ppmquant is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmquant</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-506" comment="/usr/bin/ppmquant is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-598"/>
      <subtest negate="false" test_ref="upt-599"/>
      <subtest negate="false" test_ref="upt-600"/>
    </compound_test>
    <permission_test id="upt-597" comment="/usr/bin/ppmpat is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmpat</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-596" comment="/usr/bin/ppmpat is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmpat</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-595" comment="/usr/bin/ppmpat is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmpat</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-505" comment="/usr/bin/ppmpat is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-595"/>
      <subtest negate="false" test_ref="upt-596"/>
      <subtest negate="false" test_ref="upt-597"/>
    </compound_test>
    <permission_test id="upt-594" comment="/usr/bin/ppmntsc is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmntsc</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-593" comment="/usr/bin/ppmntsc is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmntsc</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-592" comment="/usr/bin/ppmntsc is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmntsc</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-504" comment="/usr/bin/ppmntsc is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-592"/>
      <subtest negate="false" test_ref="upt-593"/>
      <subtest negate="false" test_ref="upt-594"/>
    </compound_test>
    <permission_test id="upt-591" comment="/usr/bin/ppmnorm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmnorm</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-590" comment="/usr/bin/ppmnorm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmnorm</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-589" comment="/usr/bin/ppmnorm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmnorm</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-503" comment="/usr/bin/ppmnorm is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-589"/>
      <subtest negate="false" test_ref="upt-590"/>
      <subtest negate="false" test_ref="upt-591"/>
    </compound_test>
    <permission_test id="upt-588" comment="/usr/bin/ppmmix is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmmix</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-587" comment="/usr/bin/ppmmix is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmmix</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-586" comment="/usr/bin/ppmmix is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmmix</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-502" comment="/usr/bin/ppmmix is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-586"/>
      <subtest negate="false" test_ref="upt-587"/>
      <subtest negate="false" test_ref="upt-588"/>
    </compound_test>
    <permission_test id="upt-585" comment="/usr/bin/ppmmake is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmmake</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-584" comment="/usr/bin/ppmmake is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmmake</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-583" comment="/usr/bin/ppmmake is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmmake</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-501" comment="/usr/bin/ppmmake is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-583"/>
      <subtest negate="false" test_ref="upt-584"/>
      <subtest negate="false" test_ref="upt-585"/>
    </compound_test>
    <permission_test id="upt-582" comment="/usr/bin/ppmlabel is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmlabel</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-581" comment="/usr/bin/ppmlabel is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmlabel</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-580" comment="/usr/bin/ppmlabel is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmlabel</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-500" comment="/usr/bin/ppmlabel is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-580"/>
      <subtest negate="false" test_ref="upt-581"/>
      <subtest negate="false" test_ref="upt-582"/>
    </compound_test>
    <permission_test id="upt-579" comment="/usr/bin/ppmhist is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmhist</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-578" comment="/usr/bin/ppmhist is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmhist</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-577" comment="/usr/bin/ppmhist is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmhist</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-499" comment="/usr/bin/ppmhist is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-577"/>
      <subtest negate="false" test_ref="upt-578"/>
      <subtest negate="false" test_ref="upt-579"/>
    </compound_test>
    <permission_test id="upt-576" comment="/usr/bin/ppmforge is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmforge</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-575" comment="/usr/bin/ppmforge is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmforge</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-574" comment="/usr/bin/ppmforge is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmforge</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-498" comment="/usr/bin/ppmforge is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-574"/>
      <subtest negate="false" test_ref="upt-575"/>
      <subtest negate="false" test_ref="upt-576"/>
    </compound_test>
    <permission_test id="upt-573" comment="/usr/bin/ppmflash is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmflash</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-572" comment="/usr/bin/ppmflash is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmflash</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-571" comment="/usr/bin/ppmflash is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmflash</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-497" comment="/usr/bin/ppmflash is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-571"/>
      <subtest negate="false" test_ref="upt-572"/>
      <subtest negate="false" test_ref="upt-573"/>
    </compound_test>
    <permission_test id="upt-570" comment="/usr/bin/ppmdither is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmdither</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-569" comment="/usr/bin/ppmdither is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmdither</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-568" comment="/usr/bin/ppmdither is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmdither</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-496" comment="/usr/bin/ppmdither is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-568"/>
      <subtest negate="false" test_ref="upt-569"/>
      <subtest negate="false" test_ref="upt-570"/>
    </compound_test>
    <permission_test id="upt-567" comment="/usr/bin/ppmdist is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmdist</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-566" comment="/usr/bin/ppmdist is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmdist</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-565" comment="/usr/bin/ppmdist is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmdist</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-495" comment="/usr/bin/ppmdist is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-565"/>
      <subtest negate="false" test_ref="upt-566"/>
      <subtest negate="false" test_ref="upt-567"/>
    </compound_test>
    <permission_test id="upt-564" comment="/usr/bin/ppmdim is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmdim</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-563" comment="/usr/bin/ppmdim is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmdim</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-562" comment="/usr/bin/ppmdim is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmdim</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-494" comment="/usr/bin/ppmdim is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-562"/>
      <subtest negate="false" test_ref="upt-563"/>
      <subtest negate="false" test_ref="upt-564"/>
    </compound_test>
    <permission_test id="upt-561" comment="/usr/bin/ppmcolors is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmcolors</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-560" comment="/usr/bin/ppmcolors is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmcolors</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-559" comment="/usr/bin/ppmcolors is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmcolors</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-493" comment="/usr/bin/ppmcolors is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-559"/>
      <subtest negate="false" test_ref="upt-560"/>
      <subtest negate="false" test_ref="upt-561"/>
    </compound_test>
    <permission_test id="upt-558" comment="/usr/bin/ppmcolormask is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmcolormask</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-557" comment="/usr/bin/ppmcolormask is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmcolormask</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-556" comment="/usr/bin/ppmcolormask is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmcolormask</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-492" comment="/usr/bin/ppmcolormask is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-556"/>
      <subtest negate="false" test_ref="upt-557"/>
      <subtest negate="false" test_ref="upt-558"/>
    </compound_test>
    <permission_test id="upt-555" comment="/usr/bin/ppmcie is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmcie</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-554" comment="/usr/bin/ppmcie is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmcie</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-553" comment="/usr/bin/ppmcie is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmcie</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-491" comment="/usr/bin/ppmcie is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-553"/>
      <subtest negate="false" test_ref="upt-554"/>
      <subtest negate="false" test_ref="upt-555"/>
    </compound_test>
    <permission_test id="upt-552" comment="/usr/bin/ppmchange is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmchange</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-551" comment="/usr/bin/ppmchange is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmchange</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-550" comment="/usr/bin/ppmchange is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmchange</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-490" comment="/usr/bin/ppmchange is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-550"/>
      <subtest negate="false" test_ref="upt-551"/>
      <subtest negate="false" test_ref="upt-552"/>
    </compound_test>
    <permission_test id="upt-549" comment="/usr/bin/ppmbrighten is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmbrighten</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-548" comment="/usr/bin/ppmbrighten is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmbrighten</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-547" comment="/usr/bin/ppmbrighten is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmbrighten</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-489" comment="/usr/bin/ppmbrighten is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-547"/>
      <subtest negate="false" test_ref="upt-548"/>
      <subtest negate="false" test_ref="upt-549"/>
    </compound_test>
    <permission_test id="upt-546" comment="/usr/bin/ppm3d is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppm3d</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-545" comment="/usr/bin/ppm3d is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppm3d</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-544" comment="/usr/bin/ppm3d is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppm3d</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-488" comment="/usr/bin/ppm3d is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-544"/>
      <subtest negate="false" test_ref="upt-545"/>
      <subtest negate="false" test_ref="upt-546"/>
    </compound_test>
    <permission_test id="upt-543" comment="/usr/bin/pnmtoxwd is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmtoxwd</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-542" comment="/usr/bin/pnmtoxwd is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmtoxwd</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-541" comment="/usr/bin/pnmtoxwd is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmtoxwd</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-487" comment="/usr/bin/pnmtoxwd is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-541"/>
      <subtest negate="false" test_ref="upt-542"/>
      <subtest negate="false" test_ref="upt-543"/>
    </compound_test>
    <permission_test id="upt-540" comment="/usr/bin/pnmtotiffcmyk is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmtotiffcmyk</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-539" comment="/usr/bin/pnmtotiffcmyk is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmtotiffcmyk</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-538" comment="/usr/bin/pnmtotiffcmyk is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmtotiffcmyk</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-486" comment="/usr/bin/pnmtotiffcmyk is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-538"/>
      <subtest negate="false" test_ref="upt-539"/>
      <subtest negate="false" test_ref="upt-540"/>
    </compound_test>
    <permission_test id="upt-537" comment="/usr/bin/pnmtotiff is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmtotiff</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-536" comment="/usr/bin/pnmtotiff is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmtotiff</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-535" comment="/usr/bin/pnmtotiff is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmtotiff</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-485" comment="/usr/bin/pnmtotiff is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-535"/>
      <subtest negate="false" test_ref="upt-536"/>
      <subtest negate="false" test_ref="upt-537"/>
    </compound_test>
    <permission_test id="upt-534" comment="/usr/bin/pnmtosir is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmtosir</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-533" comment="/usr/bin/pnmtosir is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmtosir</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-532" comment="/usr/bin/pnmtosir is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmtosir</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-484" comment="/usr/bin/pnmtosir is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-532"/>
      <subtest negate="false" test_ref="upt-533"/>
      <subtest negate="false" test_ref="upt-534"/>
    </compound_test>
    <permission_test id="upt-531" comment="/usr/bin/pnmtosgi is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmtosgi</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-530" comment="/usr/bin/pnmtosgi is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmtosgi</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-528" comment="/usr/bin/pnmtosgi is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmtosgi</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-483" comment="/usr/bin/pnmtosgi is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-528"/>
      <subtest negate="false" test_ref="upt-530"/>
      <subtest negate="false" test_ref="upt-531"/>
    </compound_test>
    <permission_test id="upt-527" comment="/usr/bin/pnmtorle is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmtorle</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-526" comment="/usr/bin/pnmtorle is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmtorle</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-525" comment="/usr/bin/pnmtorle is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmtorle</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-482" comment="/usr/bin/pnmtorle is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-525"/>
      <subtest negate="false" test_ref="upt-526"/>
      <subtest negate="false" test_ref="upt-527"/>
    </compound_test>
    <permission_test id="upt-524" comment="/usr/bin/pnmtorast is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmtorast</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-523" comment="/usr/bin/pnmtorast is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmtorast</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-522" comment="/usr/bin/pnmtorast is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmtorast</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-481" comment="/usr/bin/pnmtorast is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-522"/>
      <subtest negate="false" test_ref="upt-523"/>
      <subtest negate="false" test_ref="upt-524"/>
    </compound_test>
    <permission_test id="upt-521" comment="/usr/bin/pnmtops is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmtops</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-520" comment="/usr/bin/pnmtops is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmtops</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-519" comment="/usr/bin/pnmtops is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmtops</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-480" comment="/usr/bin/pnmtops is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-519"/>
      <subtest negate="false" test_ref="upt-520"/>
      <subtest negate="false" test_ref="upt-521"/>
    </compound_test>
    <permission_test id="upt-518" comment="/usr/bin/pnmtopng is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmtopng</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-517" comment="/usr/bin/pnmtopng is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmtopng</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-516" comment="/usr/bin/pnmtopng is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmtopng</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-479" comment="/usr/bin/pnmtopng is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-516"/>
      <subtest negate="false" test_ref="upt-517"/>
      <subtest negate="false" test_ref="upt-518"/>
    </compound_test>
    <permission_test id="upt-515" comment="/usr/bin/pnmtoplainpnm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmtoplainpnm</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-514" comment="/usr/bin/pnmtoplainpnm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmtoplainpnm</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-513" comment="/usr/bin/pnmtoplainpnm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmtoplainpnm</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-478" comment="/usr/bin/pnmtoplainpnm is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-513"/>
      <subtest negate="false" test_ref="upt-514"/>
      <subtest negate="false" test_ref="upt-515"/>
    </compound_test>
    <permission_test id="upt-512" comment="/usr/bin/pnmtopalm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmtopalm</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-511" comment="/usr/bin/pnmtopalm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmtopalm</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-510" comment="/usr/bin/pnmtopalm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmtopalm</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-477" comment="/usr/bin/pnmtopalm is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-510"/>
      <subtest negate="false" test_ref="upt-511"/>
      <subtest negate="false" test_ref="upt-512"/>
    </compound_test>
    <permission_test id="upt-509" comment="/usr/bin/pnmtojpeg is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmtojpeg</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-508" comment="/usr/bin/pnmtojpeg is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmtojpeg</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-507" comment="/usr/bin/pnmtojpeg is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmtojpeg</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-476" comment="/usr/bin/pnmtojpeg is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-507"/>
      <subtest negate="false" test_ref="upt-508"/>
      <subtest negate="false" test_ref="upt-509"/>
    </compound_test>
    <permission_test id="upt-506" comment="/usr/bin/pnmtofits is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmtofits</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-505" comment="/usr/bin/pnmtofits is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmtofits</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-504" comment="/usr/bin/pnmtofits is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmtofits</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-475" comment="/usr/bin/pnmtofits is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-504"/>
      <subtest negate="false" test_ref="upt-505"/>
      <subtest negate="false" test_ref="upt-506"/>
    </compound_test>
    <permission_test id="upt-503" comment="/usr/bin/pnmtofiasco is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmtofiasco</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-502" comment="/usr/bin/pnmtofiasco is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmtofiasco</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-501" comment="/usr/bin/pnmtofiasco is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmtofiasco</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-474" comment="/usr/bin/pnmtofiasco is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-501"/>
      <subtest negate="false" test_ref="upt-502"/>
      <subtest negate="false" test_ref="upt-503"/>
    </compound_test>
    <permission_test id="upt-500" comment="/usr/bin/pnmtoddif is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmtoddif</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-499" comment="/usr/bin/pnmtoddif is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmtoddif</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-498" comment="/usr/bin/pnmtoddif is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmtoddif</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-473" comment="/usr/bin/pnmtoddif is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-498"/>
      <subtest negate="false" test_ref="upt-499"/>
      <subtest negate="false" test_ref="upt-500"/>
    </compound_test>
    <permission_test id="upt-497" comment="/usr/bin/pnmtile is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmtile</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-496" comment="/usr/bin/pnmtile is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmtile</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-495" comment="/usr/bin/pnmtile is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmtile</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-472" comment="/usr/bin/pnmtile is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-495"/>
      <subtest negate="false" test_ref="upt-496"/>
      <subtest negate="false" test_ref="upt-497"/>
    </compound_test>
    <permission_test id="upt-494" comment="/usr/bin/pnmsplit is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmsplit</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-493" comment="/usr/bin/pnmsplit is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmsplit</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-492" comment="/usr/bin/pnmsplit is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmsplit</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-471" comment="/usr/bin/pnmsplit is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-492"/>
      <subtest negate="false" test_ref="upt-493"/>
      <subtest negate="false" test_ref="upt-494"/>
    </compound_test>
    <permission_test id="upt-491" comment="/usr/bin/pnmsmooth is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmsmooth</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-490" comment="/usr/bin/pnmsmooth is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmsmooth</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-489" comment="/usr/bin/pnmsmooth is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmsmooth</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-470" comment="/usr/bin/pnmsmooth is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-489"/>
      <subtest negate="false" test_ref="upt-490"/>
      <subtest negate="false" test_ref="upt-491"/>
    </compound_test>
    <permission_test id="upt-488" comment="/usr/bin/pnmshear is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmshear</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-487" comment="/usr/bin/pnmshear is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmshear</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-486" comment="/usr/bin/pnmshear is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmshear</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-469" comment="/usr/bin/pnmshear is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-486"/>
      <subtest negate="false" test_ref="upt-487"/>
      <subtest negate="false" test_ref="upt-488"/>
    </compound_test>
    <permission_test id="upt-485" comment="/usr/bin/pnmscalefixed is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmscalefixed</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-484" comment="/usr/bin/pnmscalefixed is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmscalefixed</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-483" comment="/usr/bin/pnmscalefixed is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmscalefixed</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-468" comment="/usr/bin/pnmscalefixed is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-483"/>
      <subtest negate="false" test_ref="upt-484"/>
      <subtest negate="false" test_ref="upt-485"/>
    </compound_test>
    <permission_test id="upt-784" comment="/usr/bin/zeisstopnm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/zeisstopnm</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-783" comment="/usr/bin/zeisstopnm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/zeisstopnm</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-782" comment="/usr/bin/zeisstopnm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/zeisstopnm</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-567" comment="/usr/bin/zeisstopnm is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-782"/>
      <subtest negate="false" test_ref="upt-783"/>
      <subtest negate="false" test_ref="upt-784"/>
    </compound_test>
    <permission_test id="upt-781" comment="/usr/bin/yuvtoppm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/yuvtoppm</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-780" comment="/usr/bin/yuvtoppm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/yuvtoppm</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-779" comment="/usr/bin/yuvtoppm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/yuvtoppm</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-566" comment="/usr/bin/yuvtoppm is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-779"/>
      <subtest negate="false" test_ref="upt-780"/>
      <subtest negate="false" test_ref="upt-781"/>
    </compound_test>
    <permission_test id="upt-778" comment="/usr/bin/yuvsplittoppm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/yuvsplittoppm</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-777" comment="/usr/bin/yuvsplittoppm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/yuvsplittoppm</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-776" comment="/usr/bin/yuvsplittoppm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/yuvsplittoppm</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-565" comment="/usr/bin/yuvsplittoppm is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-776"/>
      <subtest negate="false" test_ref="upt-777"/>
      <subtest negate="false" test_ref="upt-778"/>
    </compound_test>
    <permission_test id="upt-775" comment="/usr/bin/ybmtopbm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ybmtopbm</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-774" comment="/usr/bin/ybmtopbm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ybmtopbm</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-773" comment="/usr/bin/ybmtopbm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ybmtopbm</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-564" comment="/usr/bin/ybmtopbm is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-773"/>
      <subtest negate="false" test_ref="upt-774"/>
      <subtest negate="false" test_ref="upt-775"/>
    </compound_test>
    <permission_test id="upt-772" comment="/usr/bin/xwdtopnm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/xwdtopnm</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-771" comment="/usr/bin/xwdtopnm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/xwdtopnm</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-770" comment="/usr/bin/xwdtopnm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/xwdtopnm</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-563" comment="/usr/bin/xwdtopnm is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-770"/>
      <subtest negate="false" test_ref="upt-771"/>
      <subtest negate="false" test_ref="upt-772"/>
    </compound_test>
    <permission_test id="upt-769" comment="/usr/bin/xvminitoppm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/xvminitoppm</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-768" comment="/usr/bin/xvminitoppm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/xvminitoppm</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-767" comment="/usr/bin/xvminitoppm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/xvminitoppm</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-562" comment="/usr/bin/xvminitoppm is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-767"/>
      <subtest negate="false" test_ref="upt-768"/>
      <subtest negate="false" test_ref="upt-769"/>
    </compound_test>
    <permission_test id="upt-766" comment="/usr/bin/xpmtoppm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/xpmtoppm</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-765" comment="/usr/bin/xpmtoppm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/xpmtoppm</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-764" comment="/usr/bin/xpmtoppm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/xpmtoppm</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-561" comment="/usr/bin/xpmtoppm is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-764"/>
      <subtest negate="false" test_ref="upt-765"/>
      <subtest negate="false" test_ref="upt-766"/>
    </compound_test>
    <permission_test id="upt-763" comment="/usr/bin/ximtoppm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ximtoppm</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-762" comment="/usr/bin/ximtoppm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ximtoppm</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-761" comment="/usr/bin/ximtoppm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ximtoppm</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-560" comment="/usr/bin/ximtoppm is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-761"/>
      <subtest negate="false" test_ref="upt-762"/>
      <subtest negate="false" test_ref="upt-763"/>
    </compound_test>
    <permission_test id="upt-760" comment="/usr/bin/xbmtopbm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/xbmtopbm</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-759" comment="/usr/bin/xbmtopbm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/xbmtopbm</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-758" comment="/usr/bin/xbmtopbm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/xbmtopbm</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-559" comment="/usr/bin/xbmtopbm is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-758"/>
      <subtest negate="false" test_ref="upt-759"/>
      <subtest negate="false" test_ref="upt-760"/>
    </compound_test>
    <permission_test id="upt-757" comment="/usr/bin/winicontoppm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/winicontoppm</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-756" comment="/usr/bin/winicontoppm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/winicontoppm</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-755" comment="/usr/bin/winicontoppm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/winicontoppm</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-558" comment="/usr/bin/winicontoppm is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-755"/>
      <subtest negate="false" test_ref="upt-756"/>
      <subtest negate="false" test_ref="upt-757"/>
    </compound_test>
    <permission_test id="upt-754" comment="/usr/bin/wbmptopbm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/wbmptopbm</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-753" comment="/usr/bin/wbmptopbm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/wbmptopbm</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-752" comment="/usr/bin/wbmptopbm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/wbmptopbm</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-557" comment="/usr/bin/wbmptopbm is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-752"/>
      <subtest negate="false" test_ref="upt-753"/>
      <subtest negate="false" test_ref="upt-754"/>
    </compound_test>
    <permission_test id="upt-751" comment="/usr/bin/tifftopnm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/tifftopnm</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-750" comment="/usr/bin/tifftopnm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/tifftopnm</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-749" comment="/usr/bin/tifftopnm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/tifftopnm</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-556" comment="/usr/bin/tifftopnm is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-749"/>
      <subtest negate="false" test_ref="upt-750"/>
      <subtest negate="false" test_ref="upt-751"/>
    </compound_test>
    <permission_test id="upt-748" comment="/usr/bin/thinkjettopbm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/thinkjettopbm</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-747" comment="/usr/bin/thinkjettopbm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/thinkjettopbm</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-746" comment="/usr/bin/thinkjettopbm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/thinkjettopbm</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-555" comment="/usr/bin/thinkjettopbm is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-746"/>
      <subtest negate="false" test_ref="upt-747"/>
      <subtest negate="false" test_ref="upt-748"/>
    </compound_test>
    <permission_test id="upt-745" comment="/usr/bin/tgatoppm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/tgatoppm</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-744" comment="/usr/bin/tgatoppm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/tgatoppm</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-743" comment="/usr/bin/tgatoppm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/tgatoppm</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-554" comment="/usr/bin/tgatoppm is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-743"/>
      <subtest negate="false" test_ref="upt-744"/>
      <subtest negate="false" test_ref="upt-745"/>
    </compound_test>
    <permission_test id="upt-742" comment="/usr/bin/sputoppm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/sputoppm</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-741" comment="/usr/bin/sputoppm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/sputoppm</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-740" comment="/usr/bin/sputoppm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/sputoppm</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-553" comment="/usr/bin/sputoppm is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-740"/>
      <subtest negate="false" test_ref="upt-741"/>
      <subtest negate="false" test_ref="upt-742"/>
    </compound_test>
    <permission_test id="upt-739" comment="/usr/bin/spottopgm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/spottopgm</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-738" comment="/usr/bin/spottopgm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/spottopgm</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-737" comment="/usr/bin/spottopgm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/spottopgm</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-552" comment="/usr/bin/spottopgm is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-737"/>
      <subtest negate="false" test_ref="upt-738"/>
      <subtest negate="false" test_ref="upt-739"/>
    </compound_test>
    <permission_test id="upt-736" comment="/usr/bin/spctoppm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/spctoppm</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-735" comment="/usr/bin/spctoppm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/spctoppm</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-734" comment="/usr/bin/spctoppm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/spctoppm</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-551" comment="/usr/bin/spctoppm is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-734"/>
      <subtest negate="false" test_ref="upt-735"/>
      <subtest negate="false" test_ref="upt-736"/>
    </compound_test>
    <permission_test id="upt-733" comment="/usr/bin/sldtoppm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/sldtoppm</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-732" comment="/usr/bin/sldtoppm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/sldtoppm</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-731" comment="/usr/bin/sldtoppm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/sldtoppm</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-550" comment="/usr/bin/sldtoppm is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-731"/>
      <subtest negate="false" test_ref="upt-732"/>
      <subtest negate="false" test_ref="upt-733"/>
    </compound_test>
    <permission_test id="upt-729" comment="/usr/bin/sirtopnm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/sirtopnm</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-728" comment="/usr/bin/sirtopnm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/sirtopnm</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-727" comment="/usr/bin/sirtopnm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/sirtopnm</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-549" comment="/usr/bin/sirtopnm is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-727"/>
      <subtest negate="false" test_ref="upt-728"/>
      <subtest negate="false" test_ref="upt-729"/>
    </compound_test>
    <permission_test id="upt-726" comment="/usr/bin/sgitopnm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/sgitopnm</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-725" comment="/usr/bin/sgitopnm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/sgitopnm</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-724" comment="/usr/bin/sgitopnm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/sgitopnm</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-548" comment="/usr/bin/sgitopnm is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-724"/>
      <subtest negate="false" test_ref="upt-725"/>
      <subtest negate="false" test_ref="upt-726"/>
    </compound_test>
    <permission_test id="upt-723" comment="/usr/bin/sbigtopgm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/sbigtopgm</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-722" comment="/usr/bin/sbigtopgm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/sbigtopgm</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-721" comment="/usr/bin/sbigtopgm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/sbigtopgm</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-547" comment="/usr/bin/sbigtopgm is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-721"/>
      <subtest negate="false" test_ref="upt-722"/>
      <subtest negate="false" test_ref="upt-723"/>
    </compound_test>
    <permission_test id="upt-720" comment="/usr/bin/rletopnm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/rletopnm</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-719" comment="/usr/bin/rletopnm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/rletopnm</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-718" comment="/usr/bin/rletopnm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/rletopnm</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-546" comment="/usr/bin/rletopnm is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-718"/>
      <subtest negate="false" test_ref="upt-719"/>
      <subtest negate="false" test_ref="upt-720"/>
    </compound_test>
    <permission_test id="upt-717" comment="/usr/bin/rgb3toppm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/rgb3toppm</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-716" comment="/usr/bin/rgb3toppm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/rgb3toppm</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-715" comment="/usr/bin/rgb3toppm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/rgb3toppm</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-545" comment="/usr/bin/rgb3toppm is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-715"/>
      <subtest negate="false" test_ref="upt-716"/>
      <subtest negate="false" test_ref="upt-717"/>
    </compound_test>
    <permission_test id="upt-714" comment="/usr/bin/rawtoppm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/rawtoppm</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-713" comment="/usr/bin/rawtoppm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/rawtoppm</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-712" comment="/usr/bin/rawtoppm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/rawtoppm</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-544" comment="/usr/bin/rawtoppm is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-712"/>
      <subtest negate="false" test_ref="upt-713"/>
      <subtest negate="false" test_ref="upt-714"/>
    </compound_test>
    <permission_test id="upt-711" comment="/usr/bin/rawtopgm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/rawtopgm</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-710" comment="/usr/bin/rawtopgm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/rawtopgm</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-709" comment="/usr/bin/rawtopgm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/rawtopgm</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-543" comment="/usr/bin/rawtopgm is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-709"/>
      <subtest negate="false" test_ref="upt-710"/>
      <subtest negate="false" test_ref="upt-711"/>
    </compound_test>
    <permission_test id="upt-708" comment="/usr/bin/rasttopnm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/rasttopnm</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-707" comment="/usr/bin/rasttopnm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/rasttopnm</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-706" comment="/usr/bin/rasttopnm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/rasttopnm</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-542" comment="/usr/bin/rasttopnm is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-706"/>
      <subtest negate="false" test_ref="upt-707"/>
      <subtest negate="false" test_ref="upt-708"/>
    </compound_test>
    <permission_test id="upt-705" comment="/usr/bin/qrttoppm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/qrttoppm</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-704" comment="/usr/bin/qrttoppm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/qrttoppm</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-703" comment="/usr/bin/qrttoppm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/qrttoppm</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-541" comment="/usr/bin/qrttoppm is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-703"/>
      <subtest negate="false" test_ref="upt-704"/>
      <subtest negate="false" test_ref="upt-705"/>
    </compound_test>
    <permission_test id="upt-702" comment="/usr/bin/pstopnm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pstopnm</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-701" comment="/usr/bin/pstopnm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pstopnm</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-700" comment="/usr/bin/pstopnm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pstopnm</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-540" comment="/usr/bin/pstopnm is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-700"/>
      <subtest negate="false" test_ref="upt-701"/>
      <subtest negate="false" test_ref="upt-702"/>
    </compound_test>
    <permission_test id="upt-699" comment="/usr/bin/psidtopgm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/psidtopgm</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-698" comment="/usr/bin/psidtopgm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/psidtopgm</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-697" comment="/usr/bin/psidtopgm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/psidtopgm</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-539" comment="/usr/bin/psidtopgm is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-697"/>
      <subtest negate="false" test_ref="upt-698"/>
      <subtest negate="false" test_ref="upt-699"/>
    </compound_test>
    <permission_test id="upt-696" comment="/usr/bin/ppmtv is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmtv</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-695" comment="/usr/bin/ppmtv is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmtv</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-694" comment="/usr/bin/ppmtv is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmtv</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-538" comment="/usr/bin/ppmtv is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-694"/>
      <subtest negate="false" test_ref="upt-695"/>
      <subtest negate="false" test_ref="upt-696"/>
    </compound_test>
    <permission_test id="upt-693" comment="/usr/bin/ppmtoyuvsplit is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmtoyuvsplit</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-692" comment="/usr/bin/ppmtoyuvsplit is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmtoyuvsplit</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-691" comment="/usr/bin/ppmtoyuvsplit is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmtoyuvsplit</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-537" comment="/usr/bin/ppmtoyuvsplit is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-691"/>
      <subtest negate="false" test_ref="upt-692"/>
      <subtest negate="false" test_ref="upt-693"/>
    </compound_test>
    <permission_test id="upt-690" comment="/usr/bin/ppmtoyuv is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmtoyuv</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-689" comment="/usr/bin/ppmtoyuv is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmtoyuv</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-688" comment="/usr/bin/ppmtoyuv is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmtoyuv</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-536" comment="/usr/bin/ppmtoyuv is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-688"/>
      <subtest negate="false" test_ref="upt-689"/>
      <subtest negate="false" test_ref="upt-690"/>
    </compound_test>
    <permission_test id="upt-687" comment="/usr/bin/ppmtoxpm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmtoxpm</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-686" comment="/usr/bin/ppmtoxpm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmtoxpm</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-685" comment="/usr/bin/ppmtoxpm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmtoxpm</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-535" comment="/usr/bin/ppmtoxpm is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-685"/>
      <subtest negate="false" test_ref="upt-686"/>
      <subtest negate="false" test_ref="upt-687"/>
    </compound_test>
    <permission_test id="upt-684" comment="/usr/bin/ppmtowinicon is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmtowinicon</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-683" comment="/usr/bin/ppmtowinicon is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmtowinicon</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-682" comment="/usr/bin/ppmtowinicon is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmtowinicon</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-534" comment="/usr/bin/ppmtowinicon is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-682"/>
      <subtest negate="false" test_ref="upt-683"/>
      <subtest negate="false" test_ref="upt-684"/>
    </compound_test>
    <permission_test id="upt-681" comment="/usr/bin/ppmtouil is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmtouil</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-680" comment="/usr/bin/ppmtouil is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmtouil</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-679" comment="/usr/bin/ppmtouil is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmtouil</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-533" comment="/usr/bin/ppmtouil is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-679"/>
      <subtest negate="false" test_ref="upt-680"/>
      <subtest negate="false" test_ref="upt-681"/>
    </compound_test>
    <permission_test id="upt-678" comment="/usr/bin/ppmtotga is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmtotga</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-677" comment="/usr/bin/ppmtotga is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmtotga</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-676" comment="/usr/bin/ppmtotga is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmtotga</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-532" comment="/usr/bin/ppmtotga is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-676"/>
      <subtest negate="false" test_ref="upt-677"/>
      <subtest negate="false" test_ref="upt-678"/>
    </compound_test>
    <permission_test id="upt-675" comment="/usr/bin/ppmtosixel is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmtosixel</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-674" comment="/usr/bin/ppmtosixel is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmtosixel</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-673" comment="/usr/bin/ppmtosixel is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmtosixel</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-531" comment="/usr/bin/ppmtosixel is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-673"/>
      <subtest negate="false" test_ref="upt-674"/>
      <subtest negate="false" test_ref="upt-675"/>
    </compound_test>
    <permission_test id="upt-672" comment="/usr/bin/ppmtorgb3 is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmtorgb3</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-671" comment="/usr/bin/ppmtorgb3 is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmtorgb3</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-670" comment="/usr/bin/ppmtorgb3 is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmtorgb3</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-530" comment="/usr/bin/ppmtorgb3 is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-670"/>
      <subtest negate="false" test_ref="upt-671"/>
      <subtest negate="false" test_ref="upt-672"/>
    </compound_test>
    <permission_test id="upt-669" comment="/usr/bin/ppmtopuzz is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmtopuzz</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-668" comment="/usr/bin/ppmtopuzz is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmtopuzz</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-667" comment="/usr/bin/ppmtopuzz is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmtopuzz</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-529" comment="/usr/bin/ppmtopuzz is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-667"/>
      <subtest negate="false" test_ref="upt-668"/>
      <subtest negate="false" test_ref="upt-669"/>
    </compound_test>
    <permission_test id="upt-666" comment="/usr/bin/ppmtopjxl is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmtopjxl</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-665" comment="/usr/bin/ppmtopjxl is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmtopjxl</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-664" comment="/usr/bin/ppmtopjxl is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmtopjxl</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-528" comment="/usr/bin/ppmtopjxl is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-664"/>
      <subtest negate="false" test_ref="upt-665"/>
      <subtest negate="false" test_ref="upt-666"/>
    </compound_test>
    <permission_test id="upt-663" comment="/usr/bin/ppmtopj is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmtopj</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-662" comment="/usr/bin/ppmtopj is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmtopj</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-661" comment="/usr/bin/ppmtopj is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmtopj</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-527" comment="/usr/bin/ppmtopj is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-661"/>
      <subtest negate="false" test_ref="upt-662"/>
      <subtest negate="false" test_ref="upt-663"/>
    </compound_test>
    <permission_test id="upt-660" comment="/usr/bin/ppmtopict is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmtopict</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-659" comment="/usr/bin/ppmtopict is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmtopict</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-658" comment="/usr/bin/ppmtopict is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ppmtopict</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-526" comment="/usr/bin/ppmtopict is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-658"/>
      <subtest negate="false" test_ref="upt-659"/>
      <subtest negate="false" test_ref="upt-660"/>
    </compound_test>
    <permission_test id="upt-482" comment="/usr/bin/pnmscale is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmscale</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-481" comment="/usr/bin/pnmscale is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmscale</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-480" comment="/usr/bin/pnmscale is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmscale</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-467" comment="/usr/bin/pnmscale is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-480"/>
      <subtest negate="false" test_ref="upt-481"/>
      <subtest negate="false" test_ref="upt-482"/>
    </compound_test>
    <permission_test id="upt-479" comment="/usr/bin/pnmrotate is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmrotate</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-478" comment="/usr/bin/pnmrotate is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmrotate</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-477" comment="/usr/bin/pnmrotate is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmrotate</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-466" comment="/usr/bin/pnmrotate is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-477"/>
      <subtest negate="false" test_ref="upt-478"/>
      <subtest negate="false" test_ref="upt-479"/>
    </compound_test>
    <permission_test id="upt-476" comment="/usr/bin/pnmremap is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmremap</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-475" comment="/usr/bin/pnmremap is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmremap</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-474" comment="/usr/bin/pnmremap is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmremap</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-465" comment="/usr/bin/pnmremap is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-474"/>
      <subtest negate="false" test_ref="upt-475"/>
      <subtest negate="false" test_ref="upt-476"/>
    </compound_test>
    <permission_test id="upt-473" comment="/usr/bin/pnmpsnr is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmpsnr</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-472" comment="/usr/bin/pnmpsnr is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmpsnr</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-471" comment="/usr/bin/pnmpsnr is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmpsnr</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-464" comment="/usr/bin/pnmpsnr is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-471"/>
      <subtest negate="false" test_ref="upt-472"/>
      <subtest negate="false" test_ref="upt-473"/>
    </compound_test>
    <permission_test id="upt-470" comment="/usr/bin/pnmpaste is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmpaste</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-469" comment="/usr/bin/pnmpaste is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmpaste</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-468" comment="/usr/bin/pnmpaste is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmpaste</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-463" comment="/usr/bin/pnmpaste is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-468"/>
      <subtest negate="false" test_ref="upt-469"/>
      <subtest negate="false" test_ref="upt-470"/>
    </compound_test>
    <permission_test id="upt-467" comment="/usr/bin/pnmpad is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmpad</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-466" comment="/usr/bin/pnmpad is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmpad</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-465" comment="/usr/bin/pnmpad is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmpad</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-462" comment="/usr/bin/pnmpad is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-465"/>
      <subtest negate="false" test_ref="upt-466"/>
      <subtest negate="false" test_ref="upt-467"/>
    </compound_test>
    <permission_test id="upt-464" comment="/usr/bin/pnmnoraw is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmnoraw</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-463" comment="/usr/bin/pnmnoraw is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmnoraw</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-462" comment="/usr/bin/pnmnoraw is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmnoraw</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-461" comment="/usr/bin/pnmnoraw is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-462"/>
      <subtest negate="false" test_ref="upt-463"/>
      <subtest negate="false" test_ref="upt-464"/>
    </compound_test>
    <permission_test id="upt-461" comment="/usr/bin/pnmnlfilt is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmnlfilt</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-460" comment="/usr/bin/pnmnlfilt is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmnlfilt</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-459" comment="/usr/bin/pnmnlfilt is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmnlfilt</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-460" comment="/usr/bin/pnmnlfilt is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-459"/>
      <subtest negate="false" test_ref="upt-460"/>
      <subtest negate="false" test_ref="upt-461"/>
    </compound_test>
    <permission_test id="upt-458" comment="/usr/bin/pnmmontage is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmmontage</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-457" comment="/usr/bin/pnmmontage is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmmontage</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-456" comment="/usr/bin/pnmmontage is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmmontage</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-459" comment="/usr/bin/pnmmontage is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-456"/>
      <subtest negate="false" test_ref="upt-457"/>
      <subtest negate="false" test_ref="upt-458"/>
    </compound_test>
    <permission_test id="upt-455" comment="/usr/bin/pnminvert is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnminvert</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-454" comment="/usr/bin/pnminvert is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnminvert</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-453" comment="/usr/bin/pnminvert is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnminvert</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-458" comment="/usr/bin/pnminvert is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-453"/>
      <subtest negate="false" test_ref="upt-454"/>
      <subtest negate="false" test_ref="upt-455"/>
    </compound_test>
    <permission_test id="upt-452" comment="/usr/bin/pnminterp is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnminterp</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-451" comment="/usr/bin/pnminterp is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnminterp</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-450" comment="/usr/bin/pnminterp is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnminterp</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-457" comment="/usr/bin/pnminterp is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-450"/>
      <subtest negate="false" test_ref="upt-451"/>
      <subtest negate="false" test_ref="upt-452"/>
    </compound_test>
    <permission_test id="upt-449" comment="/usr/bin/pnmhistmap is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmhistmap</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-448" comment="/usr/bin/pnmhistmap is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmhistmap</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-447" comment="/usr/bin/pnmhistmap is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmhistmap</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-456" comment="/usr/bin/pnmhistmap is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-447"/>
      <subtest negate="false" test_ref="upt-448"/>
      <subtest negate="false" test_ref="upt-449"/>
    </compound_test>
    <permission_test id="upt-446" comment="/usr/bin/pnmhisteq is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmhisteq</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-445" comment="/usr/bin/pnmhisteq is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmhisteq</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-444" comment="/usr/bin/pnmhisteq is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmhisteq</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-455" comment="/usr/bin/pnmhisteq is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-444"/>
      <subtest negate="false" test_ref="upt-445"/>
      <subtest negate="false" test_ref="upt-446"/>
    </compound_test>
    <permission_test id="upt-443" comment="/usr/bin/pnmgamma is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmgamma</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-442" comment="/usr/bin/pnmgamma is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmgamma</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-441" comment="/usr/bin/pnmgamma is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmgamma</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-454" comment="/usr/bin/pnmgamma is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-441"/>
      <subtest negate="false" test_ref="upt-442"/>
      <subtest negate="false" test_ref="upt-443"/>
    </compound_test>
    <permission_test id="upt-440" comment="/usr/bin/pnmflip is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmflip</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-439" comment="/usr/bin/pnmflip is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmflip</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-438" comment="/usr/bin/pnmflip is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmflip</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-453" comment="/usr/bin/pnmflip is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-438"/>
      <subtest negate="false" test_ref="upt-439"/>
      <subtest negate="false" test_ref="upt-440"/>
    </compound_test>
    <permission_test id="upt-437" comment="/usr/bin/pnmfile is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmfile</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-436" comment="/usr/bin/pnmfile is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmfile</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-435" comment="/usr/bin/pnmfile is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmfile</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-452" comment="/usr/bin/pnmfile is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-435"/>
      <subtest negate="false" test_ref="upt-436"/>
      <subtest negate="false" test_ref="upt-437"/>
    </compound_test>
    <permission_test id="upt-434" comment="/usr/bin/pnmenlarge is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmenlarge</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-433" comment="/usr/bin/pnmenlarge is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmenlarge</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-432" comment="/usr/bin/pnmenlarge is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmenlarge</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-451" comment="/usr/bin/pnmenlarge is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-432"/>
      <subtest negate="false" test_ref="upt-433"/>
      <subtest negate="false" test_ref="upt-434"/>
    </compound_test>
    <permission_test id="upt-431" comment="/usr/bin/pnmdepth is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmdepth</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-430" comment="/usr/bin/pnmdepth is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmdepth</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-429" comment="/usr/bin/pnmdepth is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmdepth</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-450" comment="/usr/bin/pnmdepth is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-429"/>
      <subtest negate="false" test_ref="upt-430"/>
      <subtest negate="false" test_ref="upt-431"/>
    </compound_test>
    <permission_test id="upt-427" comment="/usr/bin/pnmcut is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmcut</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-426" comment="/usr/bin/pnmcut is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmcut</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-425" comment="/usr/bin/pnmcut is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmcut</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-449" comment="/usr/bin/pnmcut is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-425"/>
      <subtest negate="false" test_ref="upt-426"/>
      <subtest negate="false" test_ref="upt-427"/>
    </compound_test>
    <permission_test id="upt-424" comment="/usr/bin/pnmcrop is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmcrop</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-423" comment="/usr/bin/pnmcrop is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmcrop</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-422" comment="/usr/bin/pnmcrop is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmcrop</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-448" comment="/usr/bin/pnmcrop is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-422"/>
      <subtest negate="false" test_ref="upt-423"/>
      <subtest negate="false" test_ref="upt-424"/>
    </compound_test>
    <permission_test id="upt-421" comment="/usr/bin/pnmconvol is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmconvol</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-420" comment="/usr/bin/pnmconvol is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmconvol</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-419" comment="/usr/bin/pnmconvol is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmconvol</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-447" comment="/usr/bin/pnmconvol is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-419"/>
      <subtest negate="false" test_ref="upt-420"/>
      <subtest negate="false" test_ref="upt-421"/>
    </compound_test>
    <permission_test id="upt-418" comment="/usr/bin/pnmcomp is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmcomp</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-417" comment="/usr/bin/pnmcomp is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmcomp</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-416" comment="/usr/bin/pnmcomp is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmcomp</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-446" comment="/usr/bin/pnmcomp is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-416"/>
      <subtest negate="false" test_ref="upt-417"/>
      <subtest negate="false" test_ref="upt-418"/>
    </compound_test>
    <permission_test id="upt-415" comment="/usr/bin/pnmcolormap is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmcolormap</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-414" comment="/usr/bin/pnmcolormap is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmcolormap</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-413" comment="/usr/bin/pnmcolormap is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmcolormap</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-445" comment="/usr/bin/pnmcolormap is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-413"/>
      <subtest negate="false" test_ref="upt-414"/>
      <subtest negate="false" test_ref="upt-415"/>
    </compound_test>
    <permission_test id="upt-412" comment="/usr/bin/pnmcat is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmcat</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-411" comment="/usr/bin/pnmcat is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmcat</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-410" comment="/usr/bin/pnmcat is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmcat</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-444" comment="/usr/bin/pnmcat is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-410"/>
      <subtest negate="false" test_ref="upt-411"/>
      <subtest negate="false" test_ref="upt-412"/>
    </compound_test>
    <permission_test id="upt-409" comment="/usr/bin/pnmarith is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmarith</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-408" comment="/usr/bin/pnmarith is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmarith</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-407" comment="/usr/bin/pnmarith is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmarith</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-443" comment="/usr/bin/pnmarith is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-407"/>
      <subtest negate="false" test_ref="upt-408"/>
      <subtest negate="false" test_ref="upt-409"/>
    </compound_test>
    <permission_test id="upt-406" comment="/usr/bin/pnmalias is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmalias</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-405" comment="/usr/bin/pnmalias is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmalias</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-404" comment="/usr/bin/pnmalias is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pnmalias</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-442" comment="/usr/bin/pnmalias is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-404"/>
      <subtest negate="false" test_ref="upt-405"/>
      <subtest negate="false" test_ref="upt-406"/>
    </compound_test>
    <permission_test id="upt-403" comment="/usr/bin/pngtopnm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pngtopnm</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-402" comment="/usr/bin/pngtopnm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pngtopnm</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-401" comment="/usr/bin/pngtopnm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pngtopnm</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-441" comment="/usr/bin/pngtopnm is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-401"/>
      <subtest negate="false" test_ref="upt-402"/>
      <subtest negate="false" test_ref="upt-403"/>
    </compound_test>
    <permission_test id="upt-400" comment="/usr/bin/pktopbm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pktopbm</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-399" comment="/usr/bin/pktopbm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pktopbm</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-398" comment="/usr/bin/pktopbm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pktopbm</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-440" comment="/usr/bin/pktopbm is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-398"/>
      <subtest negate="false" test_ref="upt-399"/>
      <subtest negate="false" test_ref="upt-400"/>
    </compound_test>
    <permission_test id="upt-397" comment="/usr/bin/pjtoppm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pjtoppm</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-396" comment="/usr/bin/pjtoppm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pjtoppm</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-395" comment="/usr/bin/pjtoppm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pjtoppm</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-439" comment="/usr/bin/pjtoppm is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-395"/>
      <subtest negate="false" test_ref="upt-396"/>
      <subtest negate="false" test_ref="upt-397"/>
    </compound_test>
    <permission_test id="upt-394" comment="/usr/bin/pi3topbm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pi3topbm</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-393" comment="/usr/bin/pi3topbm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pi3topbm</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-392" comment="/usr/bin/pi3topbm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pi3topbm</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-438" comment="/usr/bin/pi3topbm is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-392"/>
      <subtest negate="false" test_ref="upt-393"/>
      <subtest negate="false" test_ref="upt-394"/>
    </compound_test>
    <permission_test id="upt-391" comment="/usr/bin/pi1toppm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pi1toppm</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-390" comment="/usr/bin/pi1toppm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pi1toppm</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-389" comment="/usr/bin/pi1toppm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pi1toppm</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-437" comment="/usr/bin/pi1toppm is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-389"/>
      <subtest negate="false" test_ref="upt-390"/>
      <subtest negate="false" test_ref="upt-391"/>
    </compound_test>
    <permission_test id="upt-388" comment="/usr/bin/pgmtoppm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pgmtoppm</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-387" comment="/usr/bin/pgmtoppm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pgmtoppm</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-386" comment="/usr/bin/pgmtoppm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pgmtoppm</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-436" comment="/usr/bin/pgmtoppm is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-386"/>
      <subtest negate="false" test_ref="upt-387"/>
      <subtest negate="false" test_ref="upt-388"/>
    </compound_test>
    <permission_test id="upt-385" comment="/usr/bin/pgmtopbm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pgmtopbm</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-384" comment="/usr/bin/pgmtopbm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pgmtopbm</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-383" comment="/usr/bin/pgmtopbm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pgmtopbm</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-435" comment="/usr/bin/pgmtopbm is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-383"/>
      <subtest negate="false" test_ref="upt-384"/>
      <subtest negate="false" test_ref="upt-385"/>
    </compound_test>
    <permission_test id="upt-382" comment="/usr/bin/pgmtolispm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pgmtolispm</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-381" comment="/usr/bin/pgmtolispm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pgmtolispm</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-380" comment="/usr/bin/pgmtolispm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pgmtolispm</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-434" comment="/usr/bin/pgmtolispm is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-380"/>
      <subtest negate="false" test_ref="upt-381"/>
      <subtest negate="false" test_ref="upt-382"/>
    </compound_test>
    <permission_test id="upt-379" comment="/usr/bin/pgmtofs is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pgmtofs</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-378" comment="/usr/bin/pgmtofs is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pgmtofs</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-377" comment="/usr/bin/pgmtofs is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pgmtofs</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-433" comment="/usr/bin/pgmtofs is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-377"/>
      <subtest negate="false" test_ref="upt-378"/>
      <subtest negate="false" test_ref="upt-379"/>
    </compound_test>
    <permission_test id="upt-376" comment="/usr/bin/pgmtexture is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pgmtexture</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-375" comment="/usr/bin/pgmtexture is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pgmtexture</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-374" comment="/usr/bin/pgmtexture is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pgmtexture</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-432" comment="/usr/bin/pgmtexture is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-374"/>
      <subtest negate="false" test_ref="upt-375"/>
      <subtest negate="false" test_ref="upt-376"/>
    </compound_test>
    <permission_test id="upt-373" comment="/usr/bin/pgmslice is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pgmslice</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-372" comment="/usr/bin/pgmslice is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pgmslice</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-371" comment="/usr/bin/pgmslice is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pgmslice</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-431" comment="/usr/bin/pgmslice is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-371"/>
      <subtest negate="false" test_ref="upt-372"/>
      <subtest negate="false" test_ref="upt-373"/>
    </compound_test>
    <permission_test id="upt-370" comment="/usr/bin/pgmramp is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pgmramp</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-369" comment="/usr/bin/pgmramp is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pgmramp</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-368" comment="/usr/bin/pgmramp is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pgmramp</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-430" comment="/usr/bin/pgmramp is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-368"/>
      <subtest negate="false" test_ref="upt-369"/>
      <subtest negate="false" test_ref="upt-370"/>
    </compound_test>
    <permission_test id="upt-367" comment="/usr/bin/pgmoil is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pgmoil</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-366" comment="/usr/bin/pgmoil is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pgmoil</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-365" comment="/usr/bin/pgmoil is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pgmoil</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-429" comment="/usr/bin/pgmoil is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-365"/>
      <subtest negate="false" test_ref="upt-366"/>
      <subtest negate="false" test_ref="upt-367"/>
    </compound_test>
    <permission_test id="upt-364" comment="/usr/bin/pgmnorm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pgmnorm</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-363" comment="/usr/bin/pgmnorm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pgmnorm</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-362" comment="/usr/bin/pgmnorm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pgmnorm</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-428" comment="/usr/bin/pgmnorm is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-362"/>
      <subtest negate="false" test_ref="upt-363"/>
      <subtest negate="false" test_ref="upt-364"/>
    </compound_test>
    <permission_test id="upt-361" comment="/usr/bin/pgmnoise is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pgmnoise</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-360" comment="/usr/bin/pgmnoise is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pgmnoise</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-359" comment="/usr/bin/pgmnoise is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pgmnoise</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-427" comment="/usr/bin/pgmnoise is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-359"/>
      <subtest negate="false" test_ref="upt-360"/>
      <subtest negate="false" test_ref="upt-361"/>
    </compound_test>
    <permission_test id="upt-358" comment="/usr/bin/pgmkernel is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pgmkernel</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-357" comment="/usr/bin/pgmkernel is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pgmkernel</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-356" comment="/usr/bin/pgmkernel is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pgmkernel</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-426" comment="/usr/bin/pgmkernel is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-356"/>
      <subtest negate="false" test_ref="upt-357"/>
      <subtest negate="false" test_ref="upt-358"/>
    </compound_test>
    <permission_test id="upt-355" comment="/usr/bin/pgmhist is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pgmhist</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-354" comment="/usr/bin/pgmhist is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pgmhist</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-353" comment="/usr/bin/pgmhist is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pgmhist</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-425" comment="/usr/bin/pgmhist is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-353"/>
      <subtest negate="false" test_ref="upt-354"/>
      <subtest negate="false" test_ref="upt-355"/>
    </compound_test>
    <permission_test id="upt-352" comment="/usr/bin/pgmenhance is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pgmenhance</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-351" comment="/usr/bin/pgmenhance is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pgmenhance</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-350" comment="/usr/bin/pgmenhance is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pgmenhance</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-424" comment="/usr/bin/pgmenhance is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-350"/>
      <subtest negate="false" test_ref="upt-351"/>
      <subtest negate="false" test_ref="upt-352"/>
    </compound_test>
    <permission_test id="upt-349" comment="/usr/bin/pgmedge is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pgmedge</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-348" comment="/usr/bin/pgmedge is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pgmedge</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-347" comment="/usr/bin/pgmedge is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pgmedge</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-423" comment="/usr/bin/pgmedge is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-347"/>
      <subtest negate="false" test_ref="upt-348"/>
      <subtest negate="false" test_ref="upt-349"/>
    </compound_test>
    <permission_test id="upt-346" comment="/usr/bin/pgmcrater is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pgmcrater</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-345" comment="/usr/bin/pgmcrater is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pgmcrater</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-344" comment="/usr/bin/pgmcrater is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pgmcrater</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-422" comment="/usr/bin/pgmcrater is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-344"/>
      <subtest negate="false" test_ref="upt-345"/>
      <subtest negate="false" test_ref="upt-346"/>
    </compound_test>
    <permission_test id="upt-343" comment="/usr/bin/pgmbentley is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pgmbentley</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-342" comment="/usr/bin/pgmbentley is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pgmbentley</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-341" comment="/usr/bin/pgmbentley is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pgmbentley</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-421" comment="/usr/bin/pgmbentley is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-341"/>
      <subtest negate="false" test_ref="upt-342"/>
      <subtest negate="false" test_ref="upt-343"/>
    </compound_test>
    <permission_test id="upt-340" comment="/usr/bin/pcxtoppm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pcxtoppm</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-339" comment="/usr/bin/pcxtoppm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pcxtoppm</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-338" comment="/usr/bin/pcxtoppm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pcxtoppm</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-420" comment="/usr/bin/pcxtoppm is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-338"/>
      <subtest negate="false" test_ref="upt-339"/>
      <subtest negate="false" test_ref="upt-340"/>
    </compound_test>
    <permission_test id="upt-337" comment="/usr/bin/pbmupc is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmupc</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-336" comment="/usr/bin/pbmupc is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmupc</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-335" comment="/usr/bin/pbmupc is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmupc</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-419" comment="/usr/bin/pbmupc is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-335"/>
      <subtest negate="false" test_ref="upt-336"/>
      <subtest negate="false" test_ref="upt-337"/>
    </compound_test>
    <permission_test id="upt-334" comment="/usr/bin/pbmtozinc is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmtozinc</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-333" comment="/usr/bin/pbmtozinc is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmtozinc</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-332" comment="/usr/bin/pbmtozinc is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmtozinc</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-418" comment="/usr/bin/pbmtozinc is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-332"/>
      <subtest negate="false" test_ref="upt-333"/>
      <subtest negate="false" test_ref="upt-334"/>
    </compound_test>
    <permission_test id="upt-331" comment="/usr/bin/pbmtoybm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmtoybm</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-330" comment="/usr/bin/pbmtoybm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmtoybm</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-329" comment="/usr/bin/pbmtoybm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmtoybm</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-417" comment="/usr/bin/pbmtoybm is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-329"/>
      <subtest negate="false" test_ref="upt-330"/>
      <subtest negate="false" test_ref="upt-331"/>
    </compound_test>
    <permission_test id="upt-328" comment="/usr/bin/pbmtoxbm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmtoxbm</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-327" comment="/usr/bin/pbmtoxbm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmtoxbm</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-326" comment="/usr/bin/pbmtoxbm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmtoxbm</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-416" comment="/usr/bin/pbmtoxbm is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-326"/>
      <subtest negate="false" test_ref="upt-327"/>
      <subtest negate="false" test_ref="upt-328"/>
    </compound_test>
    <permission_test id="upt-325" comment="/usr/bin/pbmtox10bm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmtox10bm</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-324" comment="/usr/bin/pbmtox10bm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmtox10bm</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-323" comment="/usr/bin/pbmtox10bm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmtox10bm</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-415" comment="/usr/bin/pbmtox10bm is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-323"/>
      <subtest negate="false" test_ref="upt-324"/>
      <subtest negate="false" test_ref="upt-325"/>
    </compound_test>
    <permission_test id="upt-322" comment="/usr/bin/pbmtowbmp is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmtowbmp</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-321" comment="/usr/bin/pbmtowbmp is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmtowbmp</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-320" comment="/usr/bin/pbmtowbmp is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmtowbmp</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-414" comment="/usr/bin/pbmtowbmp is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-320"/>
      <subtest negate="false" test_ref="upt-321"/>
      <subtest negate="false" test_ref="upt-322"/>
    </compound_test>
    <permission_test id="upt-319" comment="/usr/bin/pbmtoptx is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmtoptx</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-318" comment="/usr/bin/pbmtoptx is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmtoptx</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-317" comment="/usr/bin/pbmtoptx is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmtoptx</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-413" comment="/usr/bin/pbmtoptx is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-317"/>
      <subtest negate="false" test_ref="upt-318"/>
      <subtest negate="false" test_ref="upt-319"/>
    </compound_test>
    <permission_test id="upt-316" comment="/usr/bin/pbmtopsg3 is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmtopsg3</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-315" comment="/usr/bin/pbmtopsg3 is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmtopsg3</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-314" comment="/usr/bin/pbmtopsg3 is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmtopsg3</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-412" comment="/usr/bin/pbmtopsg3 is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-314"/>
      <subtest negate="false" test_ref="upt-315"/>
      <subtest negate="false" test_ref="upt-316"/>
    </compound_test>
    <permission_test id="upt-313" comment="/usr/bin/pbmtoppa is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmtoppa</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-312" comment="/usr/bin/pbmtoppa is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmtoppa</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-311" comment="/usr/bin/pbmtoppa is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmtoppa</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-411" comment="/usr/bin/pbmtoppa is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-311"/>
      <subtest negate="false" test_ref="upt-312"/>
      <subtest negate="false" test_ref="upt-313"/>
    </compound_test>
    <permission_test id="upt-310" comment="/usr/bin/pbmtoplot is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmtoplot</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-309" comment="/usr/bin/pbmtoplot is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmtoplot</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-308" comment="/usr/bin/pbmtoplot is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmtoplot</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-410" comment="/usr/bin/pbmtoplot is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-308"/>
      <subtest negate="false" test_ref="upt-309"/>
      <subtest negate="false" test_ref="upt-310"/>
    </compound_test>
    <permission_test id="upt-307" comment="/usr/bin/pbmtopk is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmtopk</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-306" comment="/usr/bin/pbmtopk is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmtopk</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-305" comment="/usr/bin/pbmtopk is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmtopk</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-409" comment="/usr/bin/pbmtopk is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-305"/>
      <subtest negate="false" test_ref="upt-306"/>
      <subtest negate="false" test_ref="upt-307"/>
    </compound_test>
    <permission_test id="upt-304" comment="/usr/bin/pbmtopi3 is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmtopi3</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-303" comment="/usr/bin/pbmtopi3 is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmtopi3</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-302" comment="/usr/bin/pbmtopi3 is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmtopi3</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-408" comment="/usr/bin/pbmtopi3 is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-302"/>
      <subtest negate="false" test_ref="upt-303"/>
      <subtest negate="false" test_ref="upt-304"/>
    </compound_test>
    <permission_test id="upt-301" comment="/usr/bin/pbmtopgm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmtopgm</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-300" comment="/usr/bin/pbmtopgm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmtopgm</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-299" comment="/usr/bin/pbmtopgm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmtopgm</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-407" comment="/usr/bin/pbmtopgm is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-299"/>
      <subtest negate="false" test_ref="upt-300"/>
      <subtest negate="false" test_ref="upt-301"/>
    </compound_test>
    <permission_test id="upt-298" comment="/usr/bin/pbmtonokia is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmtonokia</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-297" comment="/usr/bin/pbmtonokia is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmtonokia</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-296" comment="/usr/bin/pbmtonokia is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmtonokia</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-406" comment="/usr/bin/pbmtonokia is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-296"/>
      <subtest negate="false" test_ref="upt-297"/>
      <subtest negate="false" test_ref="upt-298"/>
    </compound_test>
    <permission_test id="upt-295" comment="/usr/bin/pbmtomgr is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmtomgr</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-294" comment="/usr/bin/pbmtomgr is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmtomgr</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-293" comment="/usr/bin/pbmtomgr is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmtomgr</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-405" comment="/usr/bin/pbmtomgr is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-293"/>
      <subtest negate="false" test_ref="upt-294"/>
      <subtest negate="false" test_ref="upt-295"/>
    </compound_test>
    <permission_test id="upt-292" comment="/usr/bin/pbmtomda is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmtomda</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-291" comment="/usr/bin/pbmtomda is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmtomda</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-290" comment="/usr/bin/pbmtomda is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmtomda</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-404" comment="/usr/bin/pbmtomda is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-290"/>
      <subtest negate="false" test_ref="upt-291"/>
      <subtest negate="false" test_ref="upt-292"/>
    </compound_test>
    <permission_test id="upt-289" comment="/usr/bin/pbmtomacp is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmtomacp</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-288" comment="/usr/bin/pbmtomacp is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmtomacp</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-287" comment="/usr/bin/pbmtomacp is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmtomacp</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-403" comment="/usr/bin/pbmtomacp is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-287"/>
      <subtest negate="false" test_ref="upt-288"/>
      <subtest negate="false" test_ref="upt-289"/>
    </compound_test>
    <permission_test id="upt-286" comment="/usr/bin/pbmtolps is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmtolps</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-285" comment="/usr/bin/pbmtolps is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmtolps</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-284" comment="/usr/bin/pbmtolps is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmtolps</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-402" comment="/usr/bin/pbmtolps is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-284"/>
      <subtest negate="false" test_ref="upt-285"/>
      <subtest negate="false" test_ref="upt-286"/>
    </compound_test>
    <permission_test id="upt-283" comment="/usr/bin/pbmtoln03 is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmtoln03</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-282" comment="/usr/bin/pbmtoln03 is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmtoln03</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-281" comment="/usr/bin/pbmtoln03 is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmtoln03</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-401" comment="/usr/bin/pbmtoln03 is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-281"/>
      <subtest negate="false" test_ref="upt-282"/>
      <subtest negate="false" test_ref="upt-283"/>
    </compound_test>
    <permission_test id="upt-280" comment="/usr/bin/pbmtolj is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmtolj</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-279" comment="/usr/bin/pbmtolj is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmtolj</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-278" comment="/usr/bin/pbmtolj is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmtolj</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-400" comment="/usr/bin/pbmtolj is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-278"/>
      <subtest negate="false" test_ref="upt-279"/>
      <subtest negate="false" test_ref="upt-280"/>
    </compound_test>
    <permission_test id="upt-277" comment="/usr/bin/pbmtoicon is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmtoicon</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-276" comment="/usr/bin/pbmtoicon is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmtoicon</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-275" comment="/usr/bin/pbmtoicon is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmtoicon</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-399" comment="/usr/bin/pbmtoicon is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-275"/>
      <subtest negate="false" test_ref="upt-276"/>
      <subtest negate="false" test_ref="upt-277"/>
    </compound_test>
    <permission_test id="upt-274" comment="/usr/bin/pbmtogo is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmtogo</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-273" comment="/usr/bin/pbmtogo is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmtogo</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-272" comment="/usr/bin/pbmtogo is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmtogo</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-398" comment="/usr/bin/pbmtogo is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-272"/>
      <subtest negate="false" test_ref="upt-273"/>
      <subtest negate="false" test_ref="upt-274"/>
    </compound_test>
    <permission_test id="upt-271" comment="/usr/bin/pbmtogem is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmtogem</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-270" comment="/usr/bin/pbmtogem is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmtogem</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-269" comment="/usr/bin/pbmtogem is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmtogem</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-397" comment="/usr/bin/pbmtogem is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-269"/>
      <subtest negate="false" test_ref="upt-270"/>
      <subtest negate="false" test_ref="upt-271"/>
    </compound_test>
    <permission_test id="upt-268" comment="/usr/bin/pbmtog3 is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmtog3</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-267" comment="/usr/bin/pbmtog3 is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmtog3</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-266" comment="/usr/bin/pbmtog3 is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmtog3</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-396" comment="/usr/bin/pbmtog3 is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-266"/>
      <subtest negate="false" test_ref="upt-267"/>
      <subtest negate="false" test_ref="upt-268"/>
    </compound_test>
    <permission_test id="upt-265" comment="/usr/bin/pbmtoepson is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmtoepson</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-264" comment="/usr/bin/pbmtoepson is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmtoepson</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-263" comment="/usr/bin/pbmtoepson is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmtoepson</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-395" comment="/usr/bin/pbmtoepson is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-263"/>
      <subtest negate="false" test_ref="upt-264"/>
      <subtest negate="false" test_ref="upt-265"/>
    </compound_test>
    <permission_test id="upt-262" comment="/usr/bin/pbmtoepsi is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmtoepsi</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-261" comment="/usr/bin/pbmtoepsi is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmtoepsi</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-260" comment="/usr/bin/pbmtoepsi is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmtoepsi</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-394" comment="/usr/bin/pbmtoepsi is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-260"/>
      <subtest negate="false" test_ref="upt-261"/>
      <subtest negate="false" test_ref="upt-262"/>
    </compound_test>
    <permission_test id="upt-259" comment="/usr/bin/pbmtocmuwm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmtocmuwm</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-258" comment="/usr/bin/pbmtocmuwm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmtocmuwm</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-257" comment="/usr/bin/pbmtocmuwm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmtocmuwm</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-393" comment="/usr/bin/pbmtocmuwm is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-257"/>
      <subtest negate="false" test_ref="upt-258"/>
      <subtest negate="false" test_ref="upt-259"/>
    </compound_test>
    <permission_test id="upt-256" comment="/usr/bin/pbmtobbnbg is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmtobbnbg</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-255" comment="/usr/bin/pbmtobbnbg is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmtobbnbg</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-254" comment="/usr/bin/pbmtobbnbg is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmtobbnbg</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-392" comment="/usr/bin/pbmtobbnbg is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-254"/>
      <subtest negate="false" test_ref="upt-255"/>
      <subtest negate="false" test_ref="upt-256"/>
    </compound_test>
    <permission_test id="upt-253" comment="/usr/bin/pbmtoatk is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmtoatk</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-252" comment="/usr/bin/pbmtoatk is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmtoatk</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-251" comment="/usr/bin/pbmtoatk is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmtoatk</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-391" comment="/usr/bin/pbmtoatk is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-251"/>
      <subtest negate="false" test_ref="upt-252"/>
      <subtest negate="false" test_ref="upt-253"/>
    </compound_test>
    <permission_test id="upt-250" comment="/usr/bin/pbmtoascii is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmtoascii</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-249" comment="/usr/bin/pbmtoascii is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmtoascii</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-248" comment="/usr/bin/pbmtoascii is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmtoascii</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-390" comment="/usr/bin/pbmtoascii is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-248"/>
      <subtest negate="false" test_ref="upt-249"/>
      <subtest negate="false" test_ref="upt-250"/>
    </compound_test>
    <permission_test id="upt-247" comment="/usr/bin/pbmto4425 is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmto4425</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-246" comment="/usr/bin/pbmto4425 is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmto4425</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-245" comment="/usr/bin/pbmto4425 is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmto4425</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-389" comment="/usr/bin/pbmto4425 is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-245"/>
      <subtest negate="false" test_ref="upt-246"/>
      <subtest negate="false" test_ref="upt-247"/>
    </compound_test>
    <permission_test id="upt-244" comment="/usr/bin/pbmto10x is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmto10x</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-243" comment="/usr/bin/pbmto10x is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmto10x</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-242" comment="/usr/bin/pbmto10x is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmto10x</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-388" comment="/usr/bin/pbmto10x is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-242"/>
      <subtest negate="false" test_ref="upt-243"/>
      <subtest negate="false" test_ref="upt-244"/>
    </compound_test>
    <permission_test id="upt-241" comment="/usr/bin/pbmtext is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmtext</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-240" comment="/usr/bin/pbmtext is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmtext</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-239" comment="/usr/bin/pbmtext is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmtext</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-387" comment="/usr/bin/pbmtext is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-239"/>
      <subtest negate="false" test_ref="upt-240"/>
      <subtest negate="false" test_ref="upt-241"/>
    </compound_test>
    <permission_test id="upt-238" comment="/usr/bin/pbmreduce is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmreduce</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-237" comment="/usr/bin/pbmreduce is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmreduce</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-236" comment="/usr/bin/pbmreduce is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmreduce</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-386" comment="/usr/bin/pbmreduce is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-236"/>
      <subtest negate="false" test_ref="upt-237"/>
      <subtest negate="false" test_ref="upt-238"/>
    </compound_test>
    <permission_test id="upt-235" comment="/usr/bin/pbmpscale is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmpscale</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-234" comment="/usr/bin/pbmpscale is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmpscale</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-233" comment="/usr/bin/pbmpscale is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmpscale</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-385" comment="/usr/bin/pbmpscale is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-233"/>
      <subtest negate="false" test_ref="upt-234"/>
      <subtest negate="false" test_ref="upt-235"/>
    </compound_test>
    <permission_test id="upt-232" comment="/usr/bin/pbmpage is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmpage</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-231" comment="/usr/bin/pbmpage is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmpage</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-230" comment="/usr/bin/pbmpage is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmpage</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-384" comment="/usr/bin/pbmpage is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-230"/>
      <subtest negate="false" test_ref="upt-231"/>
      <subtest negate="false" test_ref="upt-232"/>
    </compound_test>
    <permission_test id="upt-229" comment="/usr/bin/pbmmask is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmmask</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-228" comment="/usr/bin/pbmmask is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmmask</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-226" comment="/usr/bin/pbmmask is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmmask</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-383" comment="/usr/bin/pbmmask is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-226"/>
      <subtest negate="false" test_ref="upt-228"/>
      <subtest negate="false" test_ref="upt-229"/>
    </compound_test>
    <permission_test id="upt-225" comment="/usr/bin/pbmmake is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmmake</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-224" comment="/usr/bin/pbmmake is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmmake</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-223" comment="/usr/bin/pbmmake is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmmake</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-382" comment="/usr/bin/pbmmake is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-223"/>
      <subtest negate="false" test_ref="upt-224"/>
      <subtest negate="false" test_ref="upt-225"/>
    </compound_test>
    <permission_test id="upt-222" comment="/usr/bin/pbmlife is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmlife</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-221" comment="/usr/bin/pbmlife is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmlife</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-220" comment="/usr/bin/pbmlife is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmlife</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-381" comment="/usr/bin/pbmlife is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-220"/>
      <subtest negate="false" test_ref="upt-221"/>
      <subtest negate="false" test_ref="upt-222"/>
    </compound_test>
    <permission_test id="upt-219" comment="/usr/bin/pbmclean is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmclean</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-218" comment="/usr/bin/pbmclean is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmclean</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-217" comment="/usr/bin/pbmclean is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pbmclean</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-380" comment="/usr/bin/pbmclean is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-217"/>
      <subtest negate="false" test_ref="upt-218"/>
      <subtest negate="false" test_ref="upt-219"/>
    </compound_test>
    <permission_test id="upt-216" comment="/usr/bin/pamtopnm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pamtopnm</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-215" comment="/usr/bin/pamtopnm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pamtopnm</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-214" comment="/usr/bin/pamtopnm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pamtopnm</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-379" comment="/usr/bin/pamtopnm is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-214"/>
      <subtest negate="false" test_ref="upt-215"/>
      <subtest negate="false" test_ref="upt-216"/>
    </compound_test>
    <permission_test id="upt-213" comment="/usr/bin/pamstretch is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pamstretch</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-212" comment="/usr/bin/pamstretch is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pamstretch</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-211" comment="/usr/bin/pamstretch is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pamstretch</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-378" comment="/usr/bin/pamstretch is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-211"/>
      <subtest negate="false" test_ref="upt-212"/>
      <subtest negate="false" test_ref="upt-213"/>
    </compound_test>
    <permission_test id="upt-210" comment="/usr/bin/pamoil is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pamoil</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-209" comment="/usr/bin/pamoil is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pamoil</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-208" comment="/usr/bin/pamoil is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pamoil</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-377" comment="/usr/bin/pamoil is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-208"/>
      <subtest negate="false" test_ref="upt-209"/>
      <subtest negate="false" test_ref="upt-210"/>
    </compound_test>
    <permission_test id="upt-207" comment="/usr/bin/pamfile is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pamfile</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-206" comment="/usr/bin/pamfile is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pamfile</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-205" comment="/usr/bin/pamfile is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pamfile</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-376" comment="/usr/bin/pamfile is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-205"/>
      <subtest negate="false" test_ref="upt-206"/>
      <subtest negate="false" test_ref="upt-207"/>
    </compound_test>
    <permission_test id="upt-204" comment="/usr/bin/pamdeinterlace is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pamdeinterlace</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-203" comment="/usr/bin/pamdeinterlace is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pamdeinterlace</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-202" comment="/usr/bin/pamdeinterlace is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pamdeinterlace</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-375" comment="/usr/bin/pamdeinterlace is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-202"/>
      <subtest negate="false" test_ref="upt-203"/>
      <subtest negate="false" test_ref="upt-204"/>
    </compound_test>
    <permission_test id="upt-201" comment="/usr/bin/pamcut is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pamcut</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-200" comment="/usr/bin/pamcut is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pamcut</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-199" comment="/usr/bin/pamcut is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pamcut</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-374" comment="/usr/bin/pamcut is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-199"/>
      <subtest negate="false" test_ref="upt-200"/>
      <subtest negate="false" test_ref="upt-201"/>
    </compound_test>
    <permission_test id="upt-198" comment="/usr/bin/pamchannel is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pamchannel</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-197" comment="/usr/bin/pamchannel is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pamchannel</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-196" comment="/usr/bin/pamchannel is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pamchannel</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-373" comment="/usr/bin/pamchannel is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-196"/>
      <subtest negate="false" test_ref="upt-197"/>
      <subtest negate="false" test_ref="upt-198"/>
    </compound_test>
    <permission_test id="upt-195" comment="/usr/bin/palmtopnm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/palmtopnm</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-194" comment="/usr/bin/palmtopnm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/palmtopnm</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-193" comment="/usr/bin/palmtopnm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/palmtopnm</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-372" comment="/usr/bin/palmtopnm is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-193"/>
      <subtest negate="false" test_ref="upt-194"/>
      <subtest negate="false" test_ref="upt-195"/>
    </compound_test>
    <permission_test id="upt-192" comment="/usr/bin/neotoppm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/neotoppm</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-191" comment="/usr/bin/neotoppm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/neotoppm</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-190" comment="/usr/bin/neotoppm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/neotoppm</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-371" comment="/usr/bin/neotoppm is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-190"/>
      <subtest negate="false" test_ref="upt-191"/>
      <subtest negate="false" test_ref="upt-192"/>
    </compound_test>
    <permission_test id="upt-189" comment="/usr/bin/mtvtoppm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/mtvtoppm</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-188" comment="/usr/bin/mtvtoppm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/mtvtoppm</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-187" comment="/usr/bin/mtvtoppm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/mtvtoppm</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-370" comment="/usr/bin/mtvtoppm is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-187"/>
      <subtest negate="false" test_ref="upt-188"/>
      <subtest negate="false" test_ref="upt-189"/>
    </compound_test>
    <permission_test id="upt-186" comment="/usr/bin/mgrtopbm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/mgrtopbm</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-185" comment="/usr/bin/mgrtopbm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/mgrtopbm</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-184" comment="/usr/bin/mgrtopbm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/mgrtopbm</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-369" comment="/usr/bin/mgrtopbm is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-184"/>
      <subtest negate="false" test_ref="upt-185"/>
      <subtest negate="false" test_ref="upt-186"/>
    </compound_test>
    <permission_test id="upt-183" comment="/usr/bin/mdatopbm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/mdatopbm</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-182" comment="/usr/bin/mdatopbm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/mdatopbm</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-181" comment="/usr/bin/mdatopbm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/mdatopbm</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-368" comment="/usr/bin/mdatopbm is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-181"/>
      <subtest negate="false" test_ref="upt-182"/>
      <subtest negate="false" test_ref="upt-183"/>
    </compound_test>
    <permission_test id="upt-180" comment="/usr/bin/macptopbm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/macptopbm</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-179" comment="/usr/bin/macptopbm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/macptopbm</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-178" comment="/usr/bin/macptopbm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/macptopbm</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-367" comment="/usr/bin/macptopbm is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-178"/>
      <subtest negate="false" test_ref="upt-179"/>
      <subtest negate="false" test_ref="upt-180"/>
    </compound_test>
    <permission_test id="upt-177" comment="/usr/bin/lispmtopgm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/lispmtopgm</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-176" comment="/usr/bin/lispmtopgm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/lispmtopgm</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-175" comment="/usr/bin/lispmtopgm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/lispmtopgm</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-366" comment="/usr/bin/lispmtopgm is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-175"/>
      <subtest negate="false" test_ref="upt-176"/>
      <subtest negate="false" test_ref="upt-177"/>
    </compound_test>
    <permission_test id="upt-174" comment="/usr/bin/leaftoppm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/leaftoppm</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-173" comment="/usr/bin/leaftoppm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/leaftoppm</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-172" comment="/usr/bin/leaftoppm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/leaftoppm</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-365" comment="/usr/bin/leaftoppm is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-172"/>
      <subtest negate="false" test_ref="upt-173"/>
      <subtest negate="false" test_ref="upt-174"/>
    </compound_test>
    <permission_test id="upt-171" comment="/usr/bin/jpegtopnm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/jpegtopnm</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-170" comment="/usr/bin/jpegtopnm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/jpegtopnm</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-169" comment="/usr/bin/jpegtopnm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/jpegtopnm</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-364" comment="/usr/bin/jpegtopnm is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-169"/>
      <subtest negate="false" test_ref="upt-170"/>
      <subtest negate="false" test_ref="upt-171"/>
    </compound_test>
    <permission_test id="upt-168" comment="/usr/bin/imgtoppm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/imgtoppm</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-167" comment="/usr/bin/imgtoppm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/imgtoppm</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-166" comment="/usr/bin/imgtoppm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/imgtoppm</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-363" comment="/usr/bin/imgtoppm is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-166"/>
      <subtest negate="false" test_ref="upt-167"/>
      <subtest negate="false" test_ref="upt-168"/>
    </compound_test>
    <permission_test id="upt-165" comment="/usr/bin/ilbmtoppm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ilbmtoppm</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-164" comment="/usr/bin/ilbmtoppm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ilbmtoppm</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-163" comment="/usr/bin/ilbmtoppm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/ilbmtoppm</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-362" comment="/usr/bin/ilbmtoppm is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-163"/>
      <subtest negate="false" test_ref="upt-164"/>
      <subtest negate="false" test_ref="upt-165"/>
    </compound_test>
    <permission_test id="upt-162" comment="/usr/bin/icontopbm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/icontopbm</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-161" comment="/usr/bin/icontopbm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/icontopbm</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-160" comment="/usr/bin/icontopbm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/icontopbm</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-361" comment="/usr/bin/icontopbm is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-160"/>
      <subtest negate="false" test_ref="upt-161"/>
      <subtest negate="false" test_ref="upt-162"/>
    </compound_test>
    <permission_test id="upt-159" comment="/usr/bin/hpcdtoppm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/hpcdtoppm</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-158" comment="/usr/bin/hpcdtoppm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/hpcdtoppm</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-157" comment="/usr/bin/hpcdtoppm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/hpcdtoppm</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-360" comment="/usr/bin/hpcdtoppm is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-157"/>
      <subtest negate="false" test_ref="upt-158"/>
      <subtest negate="false" test_ref="upt-159"/>
    </compound_test>
    <permission_test id="upt-156" comment="/usr/bin/hipstopgm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/hipstopgm</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-155" comment="/usr/bin/hipstopgm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/hipstopgm</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-154" comment="/usr/bin/hipstopgm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/hipstopgm</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-359" comment="/usr/bin/hipstopgm is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-154"/>
      <subtest negate="false" test_ref="upt-155"/>
      <subtest negate="false" test_ref="upt-156"/>
    </compound_test>
    <permission_test id="upt-153" comment="/usr/bin/gouldtoppm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/gouldtoppm</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-152" comment="/usr/bin/gouldtoppm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/gouldtoppm</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-151" comment="/usr/bin/gouldtoppm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/gouldtoppm</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-358" comment="/usr/bin/gouldtoppm is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-151"/>
      <subtest negate="false" test_ref="upt-152"/>
      <subtest negate="false" test_ref="upt-153"/>
    </compound_test>
    <permission_test id="upt-150" comment="/usr/bin/giftopnm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/giftopnm</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-149" comment="/usr/bin/giftopnm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/giftopnm</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-148" comment="/usr/bin/giftopnm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/giftopnm</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-357" comment="/usr/bin/giftopnm is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-148"/>
      <subtest negate="false" test_ref="upt-149"/>
      <subtest negate="false" test_ref="upt-150"/>
    </compound_test>
    <permission_test id="upt-147" comment="/usr/bin/gemtopnm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/gemtopnm</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-146" comment="/usr/bin/gemtopnm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/gemtopnm</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-145" comment="/usr/bin/gemtopnm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/gemtopnm</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-356" comment="/usr/bin/gemtopnm is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-145"/>
      <subtest negate="false" test_ref="upt-146"/>
      <subtest negate="false" test_ref="upt-147"/>
    </compound_test>
    <permission_test id="upt-144" comment="/usr/bin/gemtopbm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/gemtopbm</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-143" comment="/usr/bin/gemtopbm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/gemtopbm</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-142" comment="/usr/bin/gemtopbm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/gemtopbm</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-355" comment="/usr/bin/gemtopbm is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-142"/>
      <subtest negate="false" test_ref="upt-143"/>
      <subtest negate="false" test_ref="upt-144"/>
    </compound_test>
    <permission_test id="upt-141" comment="/usr/bin/g3topbm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/g3topbm</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-140" comment="/usr/bin/g3topbm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/g3topbm</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-139" comment="/usr/bin/g3topbm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/g3topbm</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-354" comment="/usr/bin/g3topbm is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-139"/>
      <subtest negate="false" test_ref="upt-140"/>
      <subtest negate="false" test_ref="upt-141"/>
    </compound_test>
    <permission_test id="upt-138" comment="/usr/bin/fstopgm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/fstopgm</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-137" comment="/usr/bin/fstopgm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/fstopgm</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-136" comment="/usr/bin/fstopgm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/fstopgm</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-353" comment="/usr/bin/fstopgm is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-136"/>
      <subtest negate="false" test_ref="upt-137"/>
      <subtest negate="false" test_ref="upt-138"/>
    </compound_test>
    <permission_test id="upt-135" comment="/usr/bin/fitstopnm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/fitstopnm</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-134" comment="/usr/bin/fitstopnm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/fitstopnm</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-133" comment="/usr/bin/fitstopnm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/fitstopnm</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-352" comment="/usr/bin/fitstopnm is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-133"/>
      <subtest negate="false" test_ref="upt-134"/>
      <subtest negate="false" test_ref="upt-135"/>
    </compound_test>
    <permission_test id="upt-132" comment="/usr/bin/fiascotopnm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/fiascotopnm</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-131" comment="/usr/bin/fiascotopnm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/fiascotopnm</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-130" comment="/usr/bin/fiascotopnm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/fiascotopnm</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-351" comment="/usr/bin/fiascotopnm is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-130"/>
      <subtest negate="false" test_ref="upt-131"/>
      <subtest negate="false" test_ref="upt-132"/>
    </compound_test>
    <permission_test id="upt-129" comment="/usr/bin/eyuvtoppm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/eyuvtoppm</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-128" comment="/usr/bin/eyuvtoppm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/eyuvtoppm</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-127" comment="/usr/bin/eyuvtoppm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/eyuvtoppm</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-350" comment="/usr/bin/eyuvtoppm is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-127"/>
      <subtest negate="false" test_ref="upt-128"/>
      <subtest negate="false" test_ref="upt-129"/>
    </compound_test>
    <permission_test id="upt-126" comment="/usr/bin/cmuwmtopbm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/cmuwmtopbm</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-125" comment="/usr/bin/cmuwmtopbm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/cmuwmtopbm</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-124" comment="/usr/bin/cmuwmtopbm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/cmuwmtopbm</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-349" comment="/usr/bin/cmuwmtopbm is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-124"/>
      <subtest negate="false" test_ref="upt-125"/>
      <subtest negate="false" test_ref="upt-126"/>
    </compound_test>
    <permission_test id="upt-123" comment="/usr/bin/brushtopbm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/brushtopbm</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-122" comment="/usr/bin/brushtopbm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/brushtopbm</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-121" comment="/usr/bin/brushtopbm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/brushtopbm</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-348" comment="/usr/bin/brushtopbm is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-121"/>
      <subtest negate="false" test_ref="upt-122"/>
      <subtest negate="false" test_ref="upt-123"/>
    </compound_test>
    <permission_test id="upt-120" comment="/usr/bin/bmptoppm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/bmptoppm</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-119" comment="/usr/bin/bmptoppm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/bmptoppm</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-118" comment="/usr/bin/bmptoppm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/bmptoppm</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-347" comment="/usr/bin/bmptoppm is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-118"/>
      <subtest negate="false" test_ref="upt-119"/>
      <subtest negate="false" test_ref="upt-120"/>
    </compound_test>
    <permission_test id="upt-117" comment="/usr/bin/bioradtopgm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/bioradtopgm</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-116" comment="/usr/bin/bioradtopgm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/bioradtopgm</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-115" comment="/usr/bin/bioradtopgm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/bioradtopgm</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-346" comment="/usr/bin/bioradtopgm is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-115"/>
      <subtest negate="false" test_ref="upt-116"/>
      <subtest negate="false" test_ref="upt-117"/>
    </compound_test>
    <permission_test id="upt-114" comment="/usr/bin/atktopbm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/atktopbm</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-113" comment="/usr/bin/atktopbm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/atktopbm</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-112" comment="/usr/bin/atktopbm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/atktopbm</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-345" comment="/usr/bin/atktopbm is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-112"/>
      <subtest negate="false" test_ref="upt-113"/>
      <subtest negate="false" test_ref="upt-114"/>
    </compound_test>
    <permission_test id="upt-111" comment="/usr/bin/asciitopgm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/asciitopgm</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-110" comment="/usr/bin/asciitopgm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/asciitopgm</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-109" comment="/usr/bin/asciitopgm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/asciitopgm</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-344" comment="/usr/bin/asciitopgm is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-109"/>
      <subtest negate="false" test_ref="upt-110"/>
      <subtest negate="false" test_ref="upt-111"/>
    </compound_test>
    <permission_test id="upt-108" comment="/usr/bin/411toppm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/411toppm</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-107" comment="/usr/bin/411toppm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/411toppm</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-106" comment="/usr/bin/411toppm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/411toppm</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-343" comment="/usr/bin/411toppm is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-106"/>
      <subtest negate="false" test_ref="upt-107"/>
      <subtest negate="false" test_ref="upt-108"/>
    </compound_test>
    <compound_test id="cmp-342" comment="Vulnerable configuration" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-343"/>
      <subtest negate="false" test_ref="cmp-344"/>
      <subtest negate="false" test_ref="cmp-345"/>
      <subtest negate="false" test_ref="cmp-346"/>
      <subtest negate="false" test_ref="cmp-347"/>
      <subtest negate="false" test_ref="cmp-348"/>
      <subtest negate="false" test_ref="cmp-349"/>
      <subtest negate="false" test_ref="cmp-350"/>
      <subtest negate="false" test_ref="cmp-351"/>
      <subtest negate="false" test_ref="cmp-352"/>
      <subtest negate="false" test_ref="cmp-353"/>
      <subtest negate="false" test_ref="cmp-354"/>
      <subtest negate="false" test_ref="cmp-355"/>
      <subtest negate="false" test_ref="cmp-356"/>
      <subtest negate="false" test_ref="cmp-357"/>
      <subtest negate="false" test_ref="cmp-358"/>
      <subtest negate="false" test_ref="cmp-359"/>
      <subtest negate="false" test_ref="cmp-360"/>
      <subtest negate="false" test_ref="cmp-361"/>
      <subtest negate="false" test_ref="cmp-362"/>
      <subtest negate="false" test_ref="cmp-363"/>
      <subtest negate="false" test_ref="cmp-364"/>
      <subtest negate="false" test_ref="cmp-365"/>
      <subtest negate="false" test_ref="cmp-366"/>
      <subtest negate="false" test_ref="cmp-367"/>
      <subtest negate="false" test_ref="cmp-368"/>
      <subtest negate="false" test_ref="cmp-369"/>
      <subtest negate="false" test_ref="cmp-370"/>
      <subtest negate="false" test_ref="cmp-371"/>
      <subtest negate="false" test_ref="cmp-372"/>
      <subtest negate="false" test_ref="cmp-373"/>
      <subtest negate="false" test_ref="cmp-374"/>
      <subtest negate="false" test_ref="cmp-375"/>
      <subtest negate="false" test_ref="cmp-376"/>
      <subtest negate="false" test_ref="cmp-377"/>
      <subtest negate="false" test_ref="cmp-378"/>
      <subtest negate="false" test_ref="cmp-379"/>
      <subtest negate="false" test_ref="cmp-380"/>
      <subtest negate="false" test_ref="cmp-381"/>
      <subtest negate="false" test_ref="cmp-382"/>
      <subtest negate="false" test_ref="cmp-383"/>
      <subtest negate="false" test_ref="cmp-384"/>
      <subtest negate="false" test_ref="cmp-385"/>
      <subtest negate="false" test_ref="cmp-386"/>
      <subtest negate="false" test_ref="cmp-387"/>
      <subtest negate="false" test_ref="cmp-388"/>
      <subtest negate="false" test_ref="cmp-389"/>
      <subtest negate="false" test_ref="cmp-390"/>
      <subtest negate="false" test_ref="cmp-391"/>
      <subtest negate="false" test_ref="cmp-392"/>
      <subtest negate="false" test_ref="cmp-393"/>
      <subtest negate="false" test_ref="cmp-394"/>
      <subtest negate="false" test_ref="cmp-395"/>
      <subtest negate="false" test_ref="cmp-396"/>
      <subtest negate="false" test_ref="cmp-397"/>
      <subtest negate="false" test_ref="cmp-398"/>
      <subtest negate="false" test_ref="cmp-399"/>
      <subtest negate="false" test_ref="cmp-400"/>
      <subtest negate="false" test_ref="cmp-401"/>
      <subtest negate="false" test_ref="cmp-402"/>
      <subtest negate="false" test_ref="cmp-403"/>
      <subtest negate="false" test_ref="cmp-404"/>
      <subtest negate="false" test_ref="cmp-405"/>
      <subtest negate="false" test_ref="cmp-406"/>
      <subtest negate="false" test_ref="cmp-407"/>
      <subtest negate="false" test_ref="cmp-408"/>
      <subtest negate="false" test_ref="cmp-409"/>
      <subtest negate="false" test_ref="cmp-410"/>
      <subtest negate="false" test_ref="cmp-411"/>
      <subtest negate="false" test_ref="cmp-412"/>
      <subtest negate="false" test_ref="cmp-413"/>
      <subtest negate="false" test_ref="cmp-414"/>
      <subtest negate="false" test_ref="cmp-415"/>
      <subtest negate="false" test_ref="cmp-416"/>
      <subtest negate="false" test_ref="cmp-417"/>
      <subtest negate="false" test_ref="cmp-418"/>
      <subtest negate="false" test_ref="cmp-419"/>
      <subtest negate="false" test_ref="cmp-420"/>
      <subtest negate="false" test_ref="cmp-421"/>
      <subtest negate="false" test_ref="cmp-422"/>
      <subtest negate="false" test_ref="cmp-423"/>
      <subtest negate="false" test_ref="cmp-424"/>
      <subtest negate="false" test_ref="cmp-425"/>
      <subtest negate="false" test_ref="cmp-426"/>
      <subtest negate="false" test_ref="cmp-427"/>
      <subtest negate="false" test_ref="cmp-428"/>
      <subtest negate="false" test_ref="cmp-429"/>
      <subtest negate="false" test_ref="cmp-430"/>
      <subtest negate="false" test_ref="cmp-431"/>
      <subtest negate="false" test_ref="cmp-432"/>
      <subtest negate="false" test_ref="cmp-433"/>
      <subtest negate="false" test_ref="cmp-434"/>
      <subtest negate="false" test_ref="cmp-435"/>
      <subtest negate="false" test_ref="cmp-436"/>
      <subtest negate="false" test_ref="cmp-437"/>
      <subtest negate="false" test_ref="cmp-438"/>
      <subtest negate="false" test_ref="cmp-439"/>
      <subtest negate="false" test_ref="cmp-440"/>
      <subtest negate="false" test_ref="cmp-441"/>
      <subtest negate="false" test_ref="cmp-442"/>
      <subtest negate="false" test_ref="cmp-443"/>
      <subtest negate="false" test_ref="cmp-444"/>
      <subtest negate="false" test_ref="cmp-445"/>
      <subtest negate="false" test_ref="cmp-446"/>
      <subtest negate="false" test_ref="cmp-447"/>
      <subtest negate="false" test_ref="cmp-448"/>
      <subtest negate="false" test_ref="cmp-449"/>
      <subtest negate="false" test_ref="cmp-450"/>
      <subtest negate="false" test_ref="cmp-451"/>
      <subtest negate="false" test_ref="cmp-452"/>
      <subtest negate="false" test_ref="cmp-453"/>
      <subtest negate="false" test_ref="cmp-454"/>
      <subtest negate="false" test_ref="cmp-455"/>
      <subtest negate="false" test_ref="cmp-456"/>
      <subtest negate="false" test_ref="cmp-457"/>
      <subtest negate="false" test_ref="cmp-458"/>
      <subtest negate="false" test_ref="cmp-459"/>
      <subtest negate="false" test_ref="cmp-460"/>
      <subtest negate="false" test_ref="cmp-461"/>
      <subtest negate="false" test_ref="cmp-462"/>
      <subtest negate="false" test_ref="cmp-463"/>
      <subtest negate="false" test_ref="cmp-464"/>
      <subtest negate="false" test_ref="cmp-465"/>
      <subtest negate="false" test_ref="cmp-466"/>
      <subtest negate="false" test_ref="cmp-467"/>
      <subtest negate="false" test_ref="cmp-526"/>
      <subtest negate="false" test_ref="cmp-527"/>
      <subtest negate="false" test_ref="cmp-528"/>
      <subtest negate="false" test_ref="cmp-529"/>
      <subtest negate="false" test_ref="cmp-530"/>
      <subtest negate="false" test_ref="cmp-531"/>
      <subtest negate="false" test_ref="cmp-532"/>
      <subtest negate="false" test_ref="cmp-533"/>
      <subtest negate="false" test_ref="cmp-534"/>
      <subtest negate="false" test_ref="cmp-535"/>
      <subtest negate="false" test_ref="cmp-536"/>
      <subtest negate="false" test_ref="cmp-537"/>
      <subtest negate="false" test_ref="cmp-538"/>
      <subtest negate="false" test_ref="cmp-539"/>
      <subtest negate="false" test_ref="cmp-540"/>
      <subtest negate="false" test_ref="cmp-541"/>
      <subtest negate="false" test_ref="cmp-542"/>
      <subtest negate="false" test_ref="cmp-543"/>
      <subtest negate="false" test_ref="cmp-544"/>
      <subtest negate="false" test_ref="cmp-545"/>
      <subtest negate="false" test_ref="cmp-546"/>
      <subtest negate="false" test_ref="cmp-547"/>
      <subtest negate="false" test_ref="cmp-548"/>
      <subtest negate="false" test_ref="cmp-549"/>
      <subtest negate="false" test_ref="cmp-550"/>
      <subtest negate="false" test_ref="cmp-551"/>
      <subtest negate="false" test_ref="cmp-552"/>
      <subtest negate="false" test_ref="cmp-553"/>
      <subtest negate="false" test_ref="cmp-554"/>
      <subtest negate="false" test_ref="cmp-555"/>
      <subtest negate="false" test_ref="cmp-556"/>
      <subtest negate="false" test_ref="cmp-557"/>
      <subtest negate="false" test_ref="cmp-558"/>
      <subtest negate="false" test_ref="cmp-559"/>
      <subtest negate="false" test_ref="cmp-560"/>
      <subtest negate="false" test_ref="cmp-561"/>
      <subtest negate="false" test_ref="cmp-562"/>
      <subtest negate="false" test_ref="cmp-563"/>
      <subtest negate="false" test_ref="cmp-564"/>
      <subtest negate="false" test_ref="cmp-565"/>
      <subtest negate="false" test_ref="cmp-566"/>
      <subtest negate="false" test_ref="cmp-567"/>
      <subtest negate="false" test_ref="cmp-468"/>
      <subtest negate="false" test_ref="cmp-469"/>
      <subtest negate="false" test_ref="cmp-470"/>
      <subtest negate="false" test_ref="cmp-471"/>
      <subtest negate="false" test_ref="cmp-472"/>
      <subtest negate="false" test_ref="cmp-473"/>
      <subtest negate="false" test_ref="cmp-474"/>
      <subtest negate="false" test_ref="cmp-475"/>
      <subtest negate="false" test_ref="cmp-476"/>
      <subtest negate="false" test_ref="cmp-477"/>
      <subtest negate="false" test_ref="cmp-478"/>
      <subtest negate="false" test_ref="cmp-479"/>
      <subtest negate="false" test_ref="cmp-480"/>
      <subtest negate="false" test_ref="cmp-481"/>
      <subtest negate="false" test_ref="cmp-482"/>
      <subtest negate="false" test_ref="cmp-483"/>
      <subtest negate="false" test_ref="cmp-484"/>
      <subtest negate="false" test_ref="cmp-485"/>
      <subtest negate="false" test_ref="cmp-486"/>
      <subtest negate="false" test_ref="cmp-487"/>
      <subtest negate="false" test_ref="cmp-488"/>
      <subtest negate="false" test_ref="cmp-489"/>
      <subtest negate="false" test_ref="cmp-490"/>
      <subtest negate="false" test_ref="cmp-491"/>
      <subtest negate="false" test_ref="cmp-492"/>
      <subtest negate="false" test_ref="cmp-493"/>
      <subtest negate="false" test_ref="cmp-494"/>
      <subtest negate="false" test_ref="cmp-495"/>
      <subtest negate="false" test_ref="cmp-496"/>
      <subtest negate="false" test_ref="cmp-497"/>
      <subtest negate="false" test_ref="cmp-498"/>
      <subtest negate="false" test_ref="cmp-499"/>
      <subtest negate="false" test_ref="cmp-500"/>
      <subtest negate="false" test_ref="cmp-501"/>
      <subtest negate="false" test_ref="cmp-502"/>
      <subtest negate="false" test_ref="cmp-503"/>
      <subtest negate="false" test_ref="cmp-504"/>
      <subtest negate="false" test_ref="cmp-505"/>
      <subtest negate="false" test_ref="cmp-506"/>
      <subtest negate="false" test_ref="cmp-507"/>
      <subtest negate="false" test_ref="cmp-508"/>
      <subtest negate="false" test_ref="cmp-509"/>
      <subtest negate="false" test_ref="cmp-510"/>
      <subtest negate="false" test_ref="cmp-511"/>
      <subtest negate="false" test_ref="cmp-512"/>
      <subtest negate="false" test_ref="cmp-513"/>
      <subtest negate="false" test_ref="cmp-514"/>
      <subtest negate="false" test_ref="cmp-515"/>
      <subtest negate="false" test_ref="cmp-516"/>
      <subtest negate="false" test_ref="cmp-517"/>
      <subtest negate="false" test_ref="cmp-518"/>
      <subtest negate="false" test_ref="cmp-519"/>
      <subtest negate="false" test_ref="cmp-520"/>
      <subtest negate="false" test_ref="cmp-521"/>
      <subtest negate="false" test_ref="cmp-522"/>
      <subtest negate="false" test_ref="cmp-523"/>
      <subtest negate="false" test_ref="cmp-524"/>
      <subtest negate="false" test_ref="cmp-525"/>
    </compound_test>
    <rpmversioncompare_test id="rvt-260" comment="netpbm-progs version is less than 9.24-10.90.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">netpbm-progs</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">9.24</tested_version>
        <tested_release operator="equals">10.90.1</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <rpmversioncompare_test id="rvt-259" comment="netpbm-devel version is less than 9.24-10.90.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">netpbm-devel</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">9.24</tested_version>
        <tested_release operator="equals">10.90.1</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <rpmversioncompare_test id="rvt-258" comment="netpbm version is less than 9.24-10.90.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">netpbm</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">9.24</tested_version>
        <tested_release operator="equals">10.90.1</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <compound_test id="cmp-341" comment="Vulnerable Config" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="rvt-258"/>
      <subtest negate="false" test_ref="rvt-259"/>
      <subtest negate="false" test_ref="rvt-260"/>
    </compound_test>
    <inetlisteningservers_test id="rlt-217" comment="a program is listening on TCP or UDP port 1720" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <program_name operator="pattern match">.*</program_name>
      </object>
      <data operation="AND">
        <local_port datatype="int" operator="equals">1720</local_port>
      </data>
    </inetlisteningservers_test>
    <rpmversioncompare_test id="rvt-257" comment="pwlib version is less than 1.4.7-4.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">pwlib</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">1.4.7</tested_version>
        <tested_release operator="equals">4.1</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <file_test id="wft-112" comment="the version of wins.exe is less than 5.2.3790.99" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\wins.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>2</minor>
          <build>3790</build>
          <private>99</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-111" comment="the version of wins.exe is less than 4.0.1381.33554" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\wins.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>4</major>
          <minor>0</minor>
          <build>1381</build>
          <private>33554</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-110" comment="the version of wins.exe is less than 4.0.1381.7255" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\wins.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>4</major>
          <minor>0</minor>
          <build>1381</build>
          <private>7255</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-106" comment="the version of msasn1.dll is less than 5.2.3790.88" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\msasn1.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>2</minor>
          <build>3790</build>
          <private>88</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-772" comment="the version of Winword.exe is less than 10.0.6775.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Winword.exe\Path</component>
          <component type="literal">winword.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>10</major>
          <minor>0</minor>
          <build>6775</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-10013" comment="Microsoft Office XP is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key operator="pattern match">Software\\Microsoft\\Office\\10\.0\\Registration\\.*</key>
        <name>ProductID</name>
      </object>
      <data>
        <value>.*-OEM-.*</value>
      </data>
    </registry_test>
    <file_test id="wft-109" comment="the version of msasn1.dll is less than 5.1.2600.1274" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\msasn1.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>1274</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-52" comment="service pack 1 is installed and msasn1.dll is less than 5.1.2600.1274" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-4"/>
      <subtest negate="false" test_ref="wft-109"/>
    </compound_test>
    <file_test id="wft-107" comment="the version of msasn1.dll is less than 5.1.2600.119" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\msasn1.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>119</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-51" comment="no service pack is installed and msasn1.dll is less than 5.1.2600.119" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="true" test_ref="wrt-3"/>
      <subtest negate="false" test_ref="wft-107"/>
    </compound_test>
    <compound_test id="cmp-53" comment="a vulnerable version of msasn1.dll exists" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-51"/>
      <subtest negate="false" test_ref="cmp-52"/>
    </compound_test>
    <file_test id="wft-108" comment="the version of msasn1.dll is less than 5.0.2195.6824" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\msasn1.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>2195</build>
          <private>6824</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-626" comment="the version of mshtml.dll is less than 6.0.2900.2722" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mshtml.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>2900</build>
          <private>2722</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-776" comment="the version of mshtml.dll is less than 6.0.2800.1543" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mshtml.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>2800</build>
          <private>1543</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-652" comment="Internet Explorer 6 (any patch level) is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Internet Explorer</key>
        <name>Version</name>
      </object>
      <data>
        <value operator="pattern match">6\..*</value>
      </data>
    </registry_test>
    <compound_test id="cmp-308" comment="a vulnerable version of mshtml.dll exists " operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-22"/>
      <subtest negate="false" test_ref="wrt-4"/>
      <subtest negate="false" test_ref="wft-625"/>
    </compound_test>
    <file_test id="wft-625" comment="the version of mshtml.dll is less than 6.0.3790.2491" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mshtml.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>3790</build>
          <private>2491</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-299" comment=" a vulnerable version of mshtml.dll exists" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-23"/>
      <subtest negate="false" test_ref="wrt-4"/>
      <subtest negate="false" test_ref="wft-625"/>
    </compound_test>
    <file_test id="wft-624" comment="the version of mshtml.dll is less than 6.0.3790.373" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mshtml.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>3790</build>
          <private>373</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-291" comment=" a vulnerable version of mshtml.dll exists" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-23"/>
      <subtest negate="true" test_ref="wrt-3"/>
      <subtest negate="false" test_ref="wft-624"/>
    </compound_test>
    <compound_test id="cmp-315" comment="a vulnerable version of mshtml.dll exisits" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-291"/>
      <subtest negate="false" test_ref="cmp-299"/>
      <subtest negate="false" test_ref="cmp-308"/>
    </compound_test>
    <registry_test id="wrt-440" comment="the patch kb890923  is installed (XP Win2K Hotfix key)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB890923-IE6SP1-20050225.103456</key>
        <name datatype="int" operator="equals">^.*$</name>
      </object>
    </registry_test>
    <file_test id="wft-597" comment="machine has followed the QFE update path and mshtml.dll is less than 6.0.2800.1499" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mshtml.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>2800</build>
          <private>1499</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-596" comment="machine has followed the GDR update path and mshtml.dll is less than 6.0.2800.1498" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mshtml.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>2800</build>
          <private>1498</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-292" comment="a vulnerable version of mshtml.dll exisits GDR/QFE" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wft-596"/>
      <subtest negate="false" test_ref="wft-597"/>
    </compound_test>
    <file_test id="wft-777" comment="the version of mshtml.dll is less than 6.0.2900.2873" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mshtml.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>2900</build>
          <private>2873</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-1066" comment="Windows XP 64-bit with Service Pack 1" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-2"/>
      <subtest negate="false" test_ref="wrt-70"/>
      <subtest negate="false" test_ref="wrt-4"/>
    </compound_test>
    <compound_test id="cmp-692" comment="Windows XP (64-bit,SP1 or 32-bit,SP2) is installed" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="cmp-35"/>
      <subtest test_ref="cmp-1066"/>
    </compound_test>
    <file_test id="wft-696" comment="netman.dll is less than 5.2.3790.2516" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\netman.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>2</minor>
          <build>3790</build>
          <private>2516</private>
        </version>
      </data>
    </file_test>
    <patch_test id="hpt-44" comment="Patch PHSS_34169 or subsequent is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <area_patched>PHSS</area_patched>
        <patch_number operator="greater than or equal">34169</patch_number>
      </object>
    </patch_test>
    <patch_test id="hpt-43" comment="Patch PHCO_32181 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <area_patched>PHCO</area_patched>
        <patch_number operator="equals">32181</patch_number>
      </object>
    </patch_test>
    <patch_test id="hpt-42" comment="Patch PHCO_30275 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <area_patched>PHCO</area_patched>
        <patch_number operator="equals">30275</patch_number>
      </object>
    </patch_test>
    <patch_test id="hpt-41" comment="Patch PHCO_29269 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <area_patched>PHCO</area_patched>
        <patch_number operator="equals">29269</patch_number>
      </object>
    </patch_test>
    <compound_test id="cmp-782" comment="Patch PHCO_29269, PHCO_30275, or PHCO_32181 has been installed" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="hpt-41"/>
      <subtest test_ref="hpt-42"/>
      <subtest test_ref="hpt-43"/>
    </compound_test>
    <file_test id="wft-48" comment="the version of telnet.exe is less than 8.0.1969.33" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\telnet.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>8</major>
          <minor>0</minor>
          <build>1969</build>
          <private>33</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-21" comment="the software Services for UNIX is installed and the version is 3.5" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">SOFTWARE\Microsoft\Services for UNIX</key>
        <name operator="equals">Current_Release</name>
      </object>
      <data operation="AND">
        <value operator="equals">3.5</value>
      </data>
    </registry_test>
    <compound_test id="cmp-46" comment="Services for UNIX version 3.5 and telnet.exe version less than 8.0.1969.33" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-21"/>
      <subtest negate="false" test_ref="wft-48"/>
    </compound_test>
    <file_test id="wft-29" comment="the version of telnet.exe is less than 7.0.1701.44" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\telnet.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>7</major>
          <minor>0</minor>
          <build>1701</build>
          <private>44</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-20" comment="the software Services for UNIX is installed and the version is 3.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">SOFTWARE\Microsoft\Services for UNIX</key>
        <name operator="equals">Current_Release</name>
      </object>
      <data operation="AND">
        <value operator="equals">3.0</value>
      </data>
    </registry_test>
    <compound_test id="cmp-39" comment="Services for UNIX version 3.0 and telnet.exe version less than 7.0.1701.44" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-20"/>
      <subtest negate="false" test_ref="wft-29"/>
    </compound_test>
    <registry_test id="wrt-17" comment="the software Services for UNIX is installed and the version is 2.2" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">SOFTWARE\Microsoft\Services for UNIX</key>
        <name operator="equals">Current_Release</name>
      </object>
      <data operation="AND">
        <value operator="equals">2.2</value>
      </data>
    </registry_test>
    <file_test id="wft-5" comment="the version of telnet.exe is less than 5.3000.2073.13" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\telnet.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>3000</minor>
          <build>2073</build>
          <private>13</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-37" comment="Services for UNIX version 2.2 and telnet.exe version less than 5.3000.2073.13" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wft-5"/>
      <subtest negate="false" test_ref="wrt-17"/>
    </compound_test>
    <compound_test id="cmp-47" comment="Services for UNIX is instaled and a vulnerable version of telnet.exe exists" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-37"/>
      <subtest negate="false" test_ref="cmp-39"/>
      <subtest negate="false" test_ref="cmp-46"/>
    </compound_test>
    <registry_test id="wrt-49" comment="the patch KB896428 for Services for UNIX is installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">SOFTWARE\Microsoft\Updates\Microsoft Services for UNIX\KB896428</key>
        <name operator="equals">Installed</name>
      </object>
    </registry_test>
    <registry_test id="wrt-380" comment="Enable Path MTU Discovery is Disabled" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">SYSTEM\CurrentControlSet\Services\Tcpip\Parameters</key>
        <name operator="equals">EnablePMTUDiscovery</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">0</value>
      </data>
    </registry_test>
    <registry_test id="wrt-443" comment="the patch KB893066 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB893066</key>
        <name operator="equals">Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-600" comment="the version of Tcpip.sys is less than 5.2.3790.336" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\tcpip.sys</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>2</minor>
          <build>3790</build>
          <private>336</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-76" comment="The version of Ntoskrnl.exe is less than 5.1.2600.160" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\System32\Ntoskrnl.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>160</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-547" comment="the patch KB840987 is installed (Hotfix key)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB840987</key>
        <name>Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-328" comment="the version of lsasrv.dll is less than 5.0.2195.6987" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\lsasrv.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>2195</build>
          <private>6987</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-579" comment="The version of Ntoskrnl.exe is less than 5.0.2195.7035" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\System32\Ntoskrnl.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>2195</build>
          <private>7035</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-116" comment="the version of mshtml.dll is less than 5.0.3828.2700" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mshtml.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>3828</build>
          <private>2700</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-111" comment="the patch q832483 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB832483</key>
        <name>Installed</name>
      </object>
      <data operation="AND">
        <value operator="equals">1</value>
      </data>
    </registry_test>
    <compound_test id="cmp-105" comment="64-bit edition of windows and patch q832483 is not installed" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-70"/>
      <subtest negate="true" test_ref="wrt-111"/>
    </compound_test>
    <compound_test id="cmp-104" comment="32-bit edition of windows and patch q832483 is not installed" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-72"/>
      <subtest negate="true" test_ref="wrt-110"/>
    </compound_test>
    <compound_test id="cmp-103" comment="the patch q832483 is not installed" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-104"/>
      <subtest negate="false" test_ref="cmp-105"/>
    </compound_test>
    <file_test id="wft-39" comment="the version of sqlsrv32.dll is less than 2000.85.1025.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\sqlsrv32.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>2000</major>
          <minor>85</minor>
          <build>1025</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-44" comment="the version of odbcbcp.dll is less than 2000.85.1025.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\odbcbcp.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>2000</major>
          <minor>85</minor>
          <build>1025</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-104" comment="MDAC 2.8 (RTM) is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\DataAccess</key>
        <name>FullInstallVer</name>
      </object>
      <data operation="AND">
        <value operator="pattern match">^2\.8.*$</value>
      </data>
    </registry_test>
    <file_test id="wft-105" comment="the version of mshtml.dll is less than 6.0.2800.1506 (RTMQFE)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mshtml.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>2800</build>
          <private>1506</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-104" comment="the version of mshtml.dll is less than 6.0.2800.1505 (RTMGDR)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mshtml.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>2800</build>
          <private>1505</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-158" comment="the version of mshtml.dll is less than 6.0.2800.1505 or 6.0.2800.1506" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wft-104"/>
      <subtest negate="false" test_ref="wft-105"/>
    </compound_test>
    <file_test id="wft-573" comment="the version of mscms.dll is less than 5.2.3790.2476" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mscms.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>2</minor>
          <build>3790</build>
          <private>2476</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-330" comment="Windows Server 2003 with Service Pack 1" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-61"/>
      <subtest negate="false" test_ref="wrt-4"/>
    </compound_test>
    <wmi_test id="wwt-2" comment="Review whether anonymous HTTP access is allowed through IIS" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <oval:notes>
        <oval:note>Non-pejorative check</oval:note>
      </oval:notes>
      <object>
        <namespace operator="equals">root\MicrosoftIISv2</namespace>
        <wql operator="equals">SELECT AuthAnonymous from IIsWebDirectorySetting</wql>
      </object>
    </wmi_test>
    <patch_test id="hpt-8" comment="Patch PHNE_23947 or later is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <area_patched>PHNE</area_patched>
        <patch_number operator="greater than or equal">23947</patch_number>
      </object>
    </patch_test>
    <compound_test id="cmp-628" comment="800 Series OS Release 10.10" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-11"/>
      <subtest test_ref="uut-14"/>
    </compound_test>
    <uname_test id="uut-14" comment="HP Release B.10.10" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <data operation="AND">
        <os_name operator="equals">HP-UX</os_name>
        <os_release operator="equals">B.10.10</os_release>
      </data>
    </uname_test>
    <compound_test id="cmp-627" comment="700 Series OS Release 10.10" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-10"/>
      <subtest test_ref="uut-14"/>
    </compound_test>
    <compound_test id="cmp-635" comment="700 Series or 800 Series OS Release 10.10" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="cmp-627"/>
      <subtest test_ref="cmp-628"/>
    </compound_test>
    <compound_test id="cmp-626" comment="800 Series OS Release 10.01" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-11"/>
      <subtest test_ref="uut-13"/>
    </compound_test>
    <uname_test id="uut-13" comment="HP Release B.10.01" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <data operation="AND">
        <os_name operator="equals">HP-UX</os_name>
        <os_release operator="equals">B.10.01</os_release>
      </data>
    </uname_test>
    <compound_test id="cmp-625" comment="700 Series OS Release 10.01" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-10"/>
      <subtest test_ref="uut-13"/>
    </compound_test>
    <compound_test id="cmp-634" comment="700 Series or 800 Series OS Release 10.01" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="cmp-625"/>
      <subtest test_ref="cmp-626"/>
    </compound_test>
    <compound_test id="cmp-670" comment="700 Series or 800 Series OS Release 10.01 or 10.10" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="cmp-634"/>
      <subtest test_ref="cmp-635"/>
    </compound_test>
    <swlist_test id="hst-18" comment="InternetSrvcs.INET-ENG-A-MAN is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <swlist operator="equals">InternetSrvcs.INET-ENG-A-MAN</swlist>
      </object>
      <data>
        <version operator="equals">B.10.10</version>
      </data>
    </swlist_test>
    <swlist_test id="hst-17" comment="InternetSrvcs.INETSVCS-RUN is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <swlist operator="equals">InternetSrvcs.INETSVCS-RUN</swlist>
      </object>
      <data>
        <version operator="equals">B.10.10</version>
      </data>
    </swlist_test>
    <swlist_test id="hst-16" comment="InternetSrvcs.INET-ENG-A-MAN is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <swlist operator="equals">InternetSrvcs.INET-ENG-A-MAN</swlist>
      </object>
      <data>
        <version operator="equals">B.10.01</version>
      </data>
    </swlist_test>
    <swlist_test id="hst-15" comment="InternetSrvcs.INETSVCS-RUN is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <swlist operator="equals">InternetSrvcs.INETSVCS-RUN</swlist>
      </object>
      <data>
        <version operator="equals">B.10.01</version>
      </data>
    </swlist_test>
    <compound_test id="cmp-669" comment="InternetSrvcs.INETSVCS-RUN or InternetSrvcs.INET-ENG-A-MAN (B.10.20) is installed" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="hst-15"/>
      <subtest test_ref="hst-16"/>
      <subtest test_ref="hst-17"/>
      <subtest test_ref="hst-18"/>
    </compound_test>
    <patch_test id="hpt-12" comment="Patch PHNE_33790 or later is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <area_patched>PHNE</area_patched>
        <patch_number operator="greater than or equal">33790</patch_number>
      </object>
    </patch_test>
    <swlist_test id="hst-10" comment="InternetSrvcs.INET-ENG-A-MAN is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <swlist operator="equals">InternetSrvcs.INET-ENG-A-MAN</swlist>
      </object>
      <data>
        <version operator="equals">B.11.00</version>
      </data>
    </swlist_test>
    <swlist_test id="hst-9" comment="InternetSrvcs.INETSVCS-RUN is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <swlist operator="equals">InternetSrvcs.INETSVCS-RUN</swlist>
      </object>
      <data>
        <version operator="equals">B.11.00</version>
      </data>
    </swlist_test>
    <compound_test id="cmp-666" comment="InternetSrvcs.INETSVCS-RUN or InternetSrvcs.INET-ENG-A-MAN (B.11.00) is installed" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="hst-9"/>
      <subtest test_ref="hst-10"/>
    </compound_test>
    <file_test id="wft-771" comment="the version of excel.exe is less than 10.0.6789.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Excel.exe\Path</component>
          <component type="literal">excel.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>10</major>
          <minor>0</minor>
          <build>6789</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-649" comment="Excel 2002 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Office\10.0\Excel\InstallRoot</key>
        <name operator="pattern match">Path</name>
      </object>
      <data operation="AND">
        <value operator="pattern match">.*</value>
      </data>
    </registry_test>
    <registry_test id="wrt-34" comment="SharePoint Team Services are enabled (2K, XP, 2003)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Shared Tools\Web Server Extensions\Setup Packages</key>
        <name>SharePoint</name>
      </object>
      <data operation="AND">
        <value operator="equals">Installed</value>
      </data>
    </registry_test>
    <file_test id="wft-43" comment="the version of odbcbcp.dll is less than 2000.81.9042.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\odbcbcp.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>2000</major>
          <minor>81</minor>
          <build>9042</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-38" comment="the version of sqlsrv32.dll is less than 2000.81.9042.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\sqlsrv32.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>2000</major>
          <minor>81</minor>
          <build>9042</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-103" comment="MDAC 2.7 (SP1) is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\DataAccess</key>
        <name>FullInstallVer</name>
      </object>
      <data operation="AND">
        <value operator="pattern match">^2\.71.*$</value>
      </data>
    </registry_test>
    <compound_test id="cmp-102" comment="MDAC 2.7 (SP1) is installed and both sqlsrv32.dll and odbcbcp.dll are less than 2000.81.9042.0" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-103"/>
      <subtest negate="false" test_ref="wft-38"/>
      <subtest negate="false" test_ref="wft-43"/>
    </compound_test>
    <file_test id="wft-42" comment="the version of odbcbcp.dll is less than 2000.81.9002.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\odbcbcp.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>2000</major>
          <minor>81</minor>
          <build>9002</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-37" comment="the version of sqlsrv32.dll is less than 2000.81.9002.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\sqlsrv32.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>2000</major>
          <minor>81</minor>
          <build>9002</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-101" comment="MDAC 2.7 (RTM) is installed and both sqlsrv32.dll and odbcbcp.dll are less than 2000.81.9002.0" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-102"/>
      <subtest negate="false" test_ref="wft-37"/>
      <subtest negate="false" test_ref="wft-42"/>
    </compound_test>
    <compound_test id="cmp-100" comment="MDAC 2.7 is installed and a vulnerable version of sqlsrv32.dll and odbcbcp.dll exists" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-101"/>
      <subtest negate="false" test_ref="cmp-102"/>
    </compound_test>
    <permission_test id="upt-55" comment="/usr/bin/bzip2 is executable" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/bzip2</component>
        </path>
      </object>
      <data operation="OR">
        <gexec datatype="boolean" operator="equals">1</gexec>
        <oexec datatype="boolean" operator="equals">1</oexec>
        <uexec datatype="boolean" operator="equals">1</uexec>
      </data>
    </permission_test>
    <rpmversioncompare_test id="rvt-20" comment="bzip2 RPM earlier than 0:1.0.2-11.EL3.4" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name operator="equals">bzip2</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">1.0.2</tested_version>
        <tested_release operator="equals">11.EL3.4</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <swlist_test id="hst-30" comment="hpuxwsAPACHE has a version greater than or equal (A|B).2.0.55.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <swlist operator="equals">hpuxwsAPACHE</swlist>
      </object>
      <data>
        <version operator="pattern match">(((A|B)\.2\.0\.55\.\d+)|((A|B)\.[3-9]\..*)|((A|B)\.[1-9]\d+\..*)|((A|B)\.2\.[1-9]\d*\..*)|((A|B)\.2\.\d+\.[6-9]\d+\..*)|((A|B)\.2\.\d+\.5[6-9]\d*\..*)|((A|B)\.2\.\d+\.\d{3,}\..*))</version>
      </data>
    </swlist_test>
    <swlist_test id="hst-29" comment="hpuxwsAPACHE is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <swlist operator="equals">hpuxwsAPACHE</swlist>
      </object>
    </swlist_test>
    <file_test id="wft-764" comment="the version of Imekr70.ime is less than 7.0.8002.0 (Office 2003 and Accessories)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\Imekr70.ime</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>7</major>
          <minor>0</minor>
          <build>8002</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-705" comment="the version of mshtml.dll is less than 6.0.2800.1528" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mshtml.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>2800</build>
          <private>1528</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-613" comment="Win2K or XP,SP1 is installed" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="wrt-1"/>
      <subtest test_ref="cmp-57"/>
    </compound_test>
    <registry_test id="wrt-124" comment="the patch kb896426 is installed (Hotfix key)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB896426</key>
        <name operator="equals">Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-161" comment="the version of webclnt.dll is less than 5.2.3790.316" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\webclnt.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>2</minor>
          <build>3790</build>
          <private>316</private>
        </version>
      </data>
    </file_test>
    <permission_test id="upt-62" comment="gftp is executable" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/gftp</component>
        </path>
      </object>
      <data operation="OR">
        <gexec datatype="boolean" operator="equals">1</gexec>
        <oexec datatype="boolean" operator="equals">1</oexec>
        <uexec datatype="boolean" operator="equals">1</uexec>
      </data>
    </permission_test>
    <rpmversioncompare_test id="rvt-6" comment="gftp rpm is earlier than 1:2.0.14-4" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name operator="equals">gftp</name>
        <tested_epoch operator="equals">1</tested_epoch>
        <tested_version operator="equals">2.0.14</tested_version>
        <tested_release operator="equals">4</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <file_test id="wft-762" comment="the version of webclnt.dll is less than 5.2.3790.2591 (64-bit,SP1)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\webclnt.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>2</minor>
          <build>3790</build>
          <private>2591</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-723" comment="the version of T2embed.dll is less than 5.0.2195.7073" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\T2embed.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>2195</build>
          <private>7073</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-722" comment="the version of Fontsub.dll is less than 5.0.2195.7071" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\Fontsub.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>2195</build>
          <private>7071</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-707" comment="Fontsub.dll &lt; 5.0.2195.7071 or T2embed.dll &lt;5.0.2195.7073 (Win2k,SP4)" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="wft-722"/>
      <subtest test_ref="wft-723"/>
    </compound_test>
    <registry_test id="wrt-78" comment="the patch kb888113 is installed (Hotfix key)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB888113</key>
        <name operator="equals">Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-369" comment="the version of hlink.dll is less than 5.2.3790.227" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\hlink.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>2</minor>
          <build>3790</build>
          <private>227</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-351" comment="the version of user32.dll is less than 4.0.1381.7342" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\user32.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>4</major>
          <minor>0</minor>
          <build>1381</build>
          <private>7342</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-44" comment="Windows NT Server 4.0 is installed" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-77"/>
      <subtest negate="false" test_ref="cmp-50"/>
    </compound_test>
    <rpmversioncompare_test id="rvt-16" comment="ImageMagick RPM earlier than 0:5.5.6-14" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <oval:notes>
        <oval:note>The ImageMagick-devel, ImageMagick-c++-devel, and ImageMagick-c++ RPMs all require that the exact same version of the ImageMagick RPM is present.  As such, we can test for a vulnerable version of the former alone, rather than testing for the presence of each of these RPMs in particular.</oval:note>
      </oval:notes>
      <object>
        <name operator="equals">ImageMagick</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">5.5.6</tested_version>
        <tested_release operator="equals">14</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <file_test id="wft-500" comment="the version of mshtml.dll is less than 6.0.2900.2604" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mshtml.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>2900</build>
          <private>2604</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-200" comment="Internet Explorer 6.0 Installed XP SP2" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">SOFTWARE\Microsoft\Internet Explorer</key>
        <name operator="equals">Version</name>
      </object>
      <data operation="AND">
        <value operator="equals">6.0.2900.2180</value>
      </data>
    </registry_test>
    <file_test id="wft-686" comment="shell32.dll is less than 6.0.3790.2521" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\shell32.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>3790</build>
          <private>2521</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-98" comment="the wins service is enabled" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SYSTEM\CurrentControlSet\Services\wins</key>
        <name>Start</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="not equal">4</value>
      </data>
    </registry_test>
    <registry_test id="wrt-97" comment="the patch kb830352 is installed (Hotfix key)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB830352</key>
        <name>Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-98" comment="the version of wins.exe is less than 5.0.2195.6870" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\wins.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>2195</build>
          <private>6870</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-41" comment="this is an NT Server (stand-alone)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SYSTEM\CurrentControlSet\Control\Product\Options</key>
        <name>ProductType</name>
      </object>
      <data operation="AND">
        <value operator="pattern match">^.*ServerNT.*$</value>
      </data>
    </registry_test>
    <compound_test id="cmp-50" comment="Windows NT server product option" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-41"/>
      <subtest negate="false" test_ref="wrt-42"/>
    </compound_test>
    <compound_test id="cmp-60" comment="Windows 2000 Server is installed" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-1"/>
      <subtest negate="false" test_ref="cmp-50"/>
    </compound_test>
    <patch_test id="spt-163" comment="Patch 118844-24 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">118844</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">24</version>
      </data>
    </patch_test>
    <compound_test id="cmp-714" comment="Solaris 10 (x86) meets Sun Alert ID 102066 and 102108 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-10001"/>
      <subtest test_ref="uut-10002"/>
      <subtest negate="true" test_ref="spt-163"/>
    </compound_test>
    <patch_test id="spt-162" comment="Patch 118559-19 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">118559</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">19</version>
      </data>
    </patch_test>
    <patch_test id="spt-161" comment="Patch 117172-16 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">117172</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">16</version>
      </data>
    </patch_test>
    <patch_test id="spt-160" comment="Patch 112234-12 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">112234</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="equals">12</version>
      </data>
    </patch_test>
    <patch_test id="spt-159" comment="Patch 112234-11 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">112234</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="equals">11</version>
      </data>
    </patch_test>
    <compound_test id="cmp-712" comment="Contributing factors for Solaris 9, Sun Alert ID 102066 criteria." operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="spt-159"/>
      <subtest test_ref="spt-160"/>
      <subtest test_ref="spt-161"/>
    </compound_test>
    <compound_test id="cmp-713" comment="Solaris 9 (x86) meets Sun Alert ID 102066 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-6"/>
      <subtest test_ref="uut-10002"/>
      <subtest test_ref="cmp-712"/>
      <subtest negate="true" test_ref="spt-162"/>
    </compound_test>
    <file_test id="wft-703" comment="the version of Gdi32.dll is less than 5.2.3790.2542" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\Gdi32.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>2</minor>
          <build>3790</build>
          <private>2542</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-727" comment="the version of T2embed.dll is less than 5.1.2600.2777" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\T2embed.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>2777</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-726" comment="the version of Fontsub.dll is less than 5.1.2600.2777" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\Fontsub.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>2777</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-709" comment="Fontsub.dll &lt; 5.1.2600.2777 or T2embed.dll &lt;5.1.2600.2777 (WinXP,SP2)" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="wft-726"/>
      <subtest test_ref="wft-727"/>
    </compound_test>
    <file_test id="wft-628" comment="the version of mshtml.dll is less than 6.0.2800.1516 (RTMQFE)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mshtml.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>2800</build>
          <private>1516</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-627" comment="the version of mshtml.dll is less than 6.0.2800.1515 (RTMGDR)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mshtml.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>2800</build>
          <private>1515</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-317" comment="the version of mshtml.dll is less than 6.0.2800.1515 or 6.0.2800.1516 " operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wft-627"/>
      <subtest negate="false" test_ref="wft-628"/>
    </compound_test>
    <file_test id="wft-16" comment="the version of excel.exe is less than 10.0.5815.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Excel.exe\Path</component>
          <component type="literal">excel.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>10</major>
          <minor>0</minor>
          <build>5815</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-138" comment="Excel 2002 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Office\10.0\Excel\InstallRoot</key>
        <name operator="pattern match">.*</name>
      </object>
    </registry_test>
    <activedirectory_test id="wat-3" comment="Review global deny list" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <oval:notes>
        <oval:note>Non-perjorative test</oval:note>
      </oval:notes>
      <object>
        <naming_context operator="equals">configuration</naming_context>
        <relative_dn operator="pattern match">^CN=[^,]+,CN=Default Message Filter,CN=Message Delivery,CN=Global Settings,CN=[^,]+,CN=Microsoft Exchange,CN=Services</relative_dn>
        <attribute operator="equals">msExchSMTPGlobalIPDenyList</attribute>
      </object>
      <data operation="AND">
        <value operator="pattern match">.*</value>
      </data>
    </activedirectory_test>
    <activedirectory_test id="wat-2" comment="Review global accept list" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <oval:notes>
        <oval:note>Non-perjorative test</oval:note>
      </oval:notes>
      <object>
        <naming_context operator="equals">configuration</naming_context>
        <relative_dn operator="pattern match">^CN=[^,]+,CN=Default Message Filter,CN=Message Delivery,CN=Global Settings,CN=[^,]+,CN=Microsoft Exchange,CN=Services</relative_dn>
        <attribute operator="equals">msExchSMTPGlobalIPAcceptList</attribute>
      </object>
      <data operation="AND">
        <value operator="pattern match">.*</value>
      </data>
    </activedirectory_test>
    <registry_test id="wrt-35" comment="Word for Windows 6.0 Converter is enabled" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">SOFTWARE\Microsoft\Windows\CurrentVersion\Applets\Wordpad</key>
        <name operator="equals">EnableLegacyConverters</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-300" comment="the version of mswrd6.wpc is less than 10.0.803.2" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir</component>
          <component type="literal">\Common Files\Microsoft Shared\TextConv\mswrd6.wpc</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>10</major>
          <minor>0</minor>
          <build>803</build>
          <private>2</private>
        </version>
      </data>
    </file_test>
    <activedirectory_test id="wat-6" comment="Review list of blocked recipients" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <oval:notes>
        <oval:note>Non-pejorative test</oval:note>
      </oval:notes>
      <object>
        <naming_context operator="equals">configuration</naming_context>
        <relative_dn operator="pattern match">CN=[^,]+,CN=Message Delivery,CN=Global Settings,CN=[^,]+,CN=Microsoft Exchange,CN=Services</relative_dn>
        <attribute operator="equals">msExchRecipTurfListNames</attribute>
      </object>
      <data operation="AND">
        <value operator="equals">.*</value>
      </data>
    </activedirectory_test>
    <file_test id="wft-760" comment="the version of webclnt.dll is less than 5.1.2600.1790 (XP,SP1)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\webclnt.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>1790</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-64" comment="the patch kb890046 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB890046</key>
        <name operator="equals">Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-117" comment="the version of agentdpv.dll is less than 2.0.0.3423" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\agentdpv.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>2</major>
          <minor>0</minor>
          <build>0</build>
          <private>3423</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-502" comment="Patch Q328310 Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q328310</key>
        <name>Installed</name>
      </object>
      <data operation="AND">
        <value>1</value>
      </data>
    </registry_test>
    <file_test id="wft-477" comment="the version of win32k.sys is less than 4.0.1381.7207" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\win32k.sys</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>4</major>
          <minor>0</minor>
          <build>1381</build>
          <private>7207</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-476" comment="the version of winsrv.dll is less than 4.0.1381.7202" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\winsrv.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>4</major>
          <minor>0</minor>
          <build>1381</build>
          <private>7202</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-475" comment="the version of gdi32.dll is less than 4.0.1381.7177" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\gdi32.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>4</major>
          <minor>0</minor>
          <build>1381</build>
          <private>7177</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-474" comment="the version of user32.dll is less than 4.0.1381.7177" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\user32.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>4</major>
          <minor>0</minor>
          <build>1381</build>
          <private>7177</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-758" comment="the version of Tcpip.sys is less than 5.2.3790.2617 (64-bit,SP1)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\drivers\tcpip.sys</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>2</minor>
          <build>3790</build>
          <private>2617</private>
        </version>
      </data>
    </file_test>
    <process_test id="uct-1" comment="postmaster (the PostgreSQL master daemon) is running" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <command operator="pattern match">\bpostmaster\b</command>
      </object>
    </process_test>
    <rpmversioncompare_test id="rvt-9" comment="rh-postgresql-server is earlier than 0:7.3.10-1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name operator="equals">rh-postgresql-server</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">7.3.10</tested_version>
        <tested_release operator="equals">1</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <file_test id="wft-14" comment="the version of excel.exe is less than 8.00.01.9904" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Excel.exe\Path</component>
          <component type="literal">excel.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>8</major>
          <minor>00</minor>
          <build>01</build>
          <private>9904</private>
        </version>
      </data>
    </file_test>
    <unknown_test id="ukn-12" comment="Excel 97 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#independent"/>
    <file_test id="wft-702" comment="the version of Gdi32.dll is less than 5.2.3790.419" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\Gdi32.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>2</minor>
          <build>3790</build>
          <private>419</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-10026" comment="Win2K/XP/2003 is patched" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion</key>
        <name>CSDVersion</name>
      </object>
      <data operation="AND">
        <value operator="pattern match">.*</value>
      </data>
    </registry_test>
    <compound_test id="cmp-646" comment="64-bit XP is installed" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="wrt-2"/>
      <subtest test_ref="wrt-22"/>
    </compound_test>
    <compound_test id="cmp-647" comment="64-bit XP or Server 2003 is installed" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="cmp-646"/>
      <subtest test_ref="wrt-61"/>
    </compound_test>
    <registry_test id="wrt-639" comment="A pre-release of SeaMonkey 1.0 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key datatype="string" operator="equals">SOFTWARE\mozilla.org\SeaMonkey</key>
        <name datatype="string" operator="equals">CurrentVersion</name>
      </object>
      <data operation="AND">
        <value datatype="string" operator="pattern match">1\.0[ab].*</value>
      </data>
    </registry_test>
    <registry_test id="wrt-638" comment="A pre-release of SeaMonkey 1.0 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key datatype="string" operator="pattern match">SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\SeaMonkey \(1\.0[ab]\)</key>
        <name datatype="string" operator="equals">DisplayName</name>
      </object>
      <data operation="AND">
        <value datatype="string" operator="pattern match">SeaMonkey \(1\.0[ab]\)</value>
      </data>
    </registry_test>
    <compound_test id="cmp-747" comment="A pre-release of SeaMonkey 1.0 is installed" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="wrt-638"/>
      <subtest test_ref="wrt-639"/>
    </compound_test>
    <registry_test id="wrt-637" comment="Mozilla Suite is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key datatype="string" operator="pattern match">SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Mozilla \(.*\)</key>
        <name datatype="string" operator="equals">DisplayName</name>
      </object>
      <data operation="AND">
        <value datatype="string" operator="pattern match">Mozilla \(.*\)</value>
      </data>
    </registry_test>
    <registry_test id="wrt-636" comment="Mozilla Suite installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key datatype="string" operator="equals">SOFTWARE\mozilla.org\Mozilla</key>
        <name datatype="string" operator="equals">CurrentVersion</name>
      </object>
      <data operation="AND">
        <value datatype="string" operator="pattern match">.*</value>
      </data>
    </registry_test>
    <compound_test id="cmp-746" comment="Mozilla Suite is installed" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="wrt-636"/>
      <subtest test_ref="wrt-637"/>
    </compound_test>
    <registry_test id="wrt-629" comment="Firefox version 1.5 or earlier is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key datatype="string" operator="equals">SOFTWARE\Mozilla\Mozilla Firefox</key>
        <name datatype="string" operator="equals">CurrentVersion</name>
      </object>
      <data operation="AND">
        <value datatype="string" operator="pattern match">1\.5($|\s).*</value>
      </data>
    </registry_test>
    <registry_test id="wrt-628" comment="Mozilla Firefox version 1.5 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key datatype="string" operator="equals">SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Mozilla Firefox (1.5)</key>
        <name datatype="string" operator="equals">DisplayName</name>
      </object>
      <data operation="AND">
        <value datatype="string" operator="pattern match">Mozilla Firefox \(1\.5\)</value>
      </data>
    </registry_test>
    <compound_test id="cmp-744" comment="Mozilla Firefox version 1.5 is installed and has NOT been patched with version 1.5.0.1" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="wrt-628"/>
      <subtest test_ref="wrt-629"/>
      <subtest negate="true" test_ref="wft-741"/>
    </compound_test>
    <registry_test id="wrt-641" comment="Firefox pre-1.5 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key datatype="string" operator="equals">SOFTWARE\Mozilla\Mozilla Firefox</key>
        <name datatype="string" operator="equals">CurrentVersion</name>
      </object>
      <data operation="AND">
        <value datatype="string" operator="pattern match">(0\..*|1\.0\..*)</value>
      </data>
    </registry_test>
    <registry_test id="wrt-640" comment="Mozilla Firefox pre-1.5" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key datatype="string" operator="pattern match">SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Mozilla Firefox \((0\..*|1\.0\..*\))</key>
        <name datatype="string" operator="equals">DisplayName</name>
      </object>
      <data operation="AND">
        <value datatype="string" operator="pattern match">Mozilla Firefox \((0\..*|1\.0\..*\))</value>
      </data>
    </registry_test>
    <compound_test id="cmp-748" comment="Mozilla Firefox pre-1.5 is installed" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="wrt-640"/>
      <subtest test_ref="wrt-641"/>
    </compound_test>
    <file_test id="wft-741" comment="The version of Firefox.exe is greater than or equal to 1.8.20060.11112" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 1.5\bin\PathToExe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="greater than or equal">
          <major>1</major>
          <minor>8</minor>
          <build>20060</build>
          <private>11112</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-643" comment="Thunderbird pre-1.5 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key datatype="string" operator="equals">SOFTWARE\Mozilla\Mozilla Thunderbird</key>
        <name datatype="string" operator="equals">CurrentVersion</name>
      </object>
      <data operation="AND">
        <value datatype="string" operator="pattern match">(0\..*|1\.0\..*)</value>
      </data>
    </registry_test>
    <registry_test id="wrt-642" comment="Mozilla Thunderbird pre-1.5" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key datatype="string" operator="pattern match">SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Mozilla Thunderbird \((0\..*|1\.0\..*\))</key>
        <name datatype="string" operator="equals">DisplayName</name>
      </object>
      <data operation="AND">
        <value datatype="string" operator="pattern match">Mozilla Thunderbird \((0\..*|1\.0\..*\))</value>
      </data>
    </registry_test>
    <compound_test id="cmp-749" comment="Mozilla Thunderbird pre-1.5 is installed without an upgraded Firefox (1.5.0.1)" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="wrt-642"/>
      <subtest test_ref="wrt-643"/>
      <subtest negate="true" test_ref="wft-741"/>
    </compound_test>
    <file_test id="wft-22" comment="the version of winword.exe is less than 10.0.5815.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Winword.exe\Path</component>
          <component type="literal">winword.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>10</major>
          <minor>0</minor>
          <build>5815</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <inetlisteningservers_test id="rlt-215" comment="ypserv is listening on the network" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <program_name datatype="string" operator="pattern match">^.*ypserv.*</program_name>
      </object>
    </inetlisteningservers_test>
    <rpmversioncompare_test id="rvt-255" comment="ypserv version is less than 2.8-0.9E" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">ypserv</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">2.8</tested_version>
        <tested_release operator="equals">0.9E</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <permission_test id="upt-105" comment="xpdf is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/xpdf</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-104" comment="xpdf is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/xpdf</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-103" comment="xpdf is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/xpdf</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-338" comment="xpdf is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-103"/>
      <subtest negate="false" test_ref="upt-104"/>
      <subtest negate="false" test_ref="upt-105"/>
    </compound_test>
    <rpmversioncompare_test id="rvt-254" comment="xpdf version is less than 2.0.1-11" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">xpdf</name>
        <tested_epoch datatype="int" operator="equals">1</tested_epoch>
        <tested_version operator="equals">2.0.1</tested_version>
        <tested_release datatype="int" operator="equals">11</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <file_test id="uft-32" comment="Target is configured as a print server" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/etc/lp/printers/*</component>
        </path>
      </object>
    </file_test>
    <patch_test id="spt-170" comment="Patch 120468-03 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">120468</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">03</version>
      </data>
    </patch_test>
    <compound_test id="cmp-724" comment="Solaris 10 (x86) meets Sun Alert ID 102033 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-10001"/>
      <subtest test_ref="uut-10002"/>
      <subtest negate="true" test_ref="spt-170"/>
    </compound_test>
    <patch_test id="spt-167" comment="Patch 120467-03 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">120467</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">03</version>
      </data>
    </patch_test>
    <uname_test id="uut-10001" comment="Solaris 10 Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <data operation="AND">
        <os_name operator="equals">SunOS</os_name>
        <os_release operator="equals">5.10</os_release>
      </data>
    </uname_test>
    <compound_test id="cmp-723" comment="Solaris 10 (sparc) meets Sun Alert ID 102033 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-10001"/>
      <subtest test_ref="uut-10003"/>
      <subtest negate="true" test_ref="spt-167"/>
    </compound_test>
    <patch_test id="spt-169" comment="Patch 114980-17 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">114890</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">17</version>
      </data>
    </patch_test>
    <compound_test id="cmp-722" comment="Solaris 9 (x86) meets Sun Alert ID 102033 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-6"/>
      <subtest test_ref="uut-10002"/>
      <subtest negate="true" test_ref="spt-169"/>
    </compound_test>
    <patch_test id="spt-166" comment="Patch 113329-16 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">113329</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">16</version>
      </data>
    </patch_test>
    <compound_test id="cmp-721" comment="Solaris 9 (SPARC) meets Sun Alert ID 102033 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-6"/>
      <subtest test_ref="uut-10003"/>
      <subtest negate="true" test_ref="spt-166"/>
    </compound_test>
    <patch_test id="spt-168" comment="Patch 109321-17 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">109321</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">17</version>
      </data>
    </patch_test>
    <uname_test id="uut-10002" comment="ix86 architecture" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <data operation="AND">
        <processor_type operator="pattern match">^i.*86</processor_type>
      </data>
    </uname_test>
    <compound_test id="cmp-720" comment="Solaris 8 (x86) meets Sun Alert ID 102033 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-4"/>
      <subtest test_ref="uut-10002"/>
      <subtest negate="true" test_ref="spt-168"/>
    </compound_test>
    <patch_test id="spt-165" comment="Patch 109320-17 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">109320</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">17</version>
      </data>
    </patch_test>
    <uname_test id="uut-10003" comment="sparc architecture" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <data operation="AND">
        <processor_type operator="pattern match">[Ss][Pp][Aa][Rr][Cc]</processor_type>
      </data>
    </uname_test>
    <compound_test id="cmp-719" comment="Solaris 8 (SPARC) meets Sun Alert ID 102033 criteria." operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-4"/>
      <subtest test_ref="uut-10003"/>
      <subtest negate="true" test_ref="spt-165"/>
    </compound_test>
    <inetlisteningservers_test id="rlt-214" comment="xinetd is listening to the network" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <program_name datatype="string" operator="pattern match">^.*xinetd.*</program_name>
      </object>
    </inetlisteningservers_test>
    <rpmversioncompare_test id="rvt-253" comment="xinetd version is less than 2:2.3.11-1.9.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">xinetd</name>
        <tested_epoch operator="equals">2</tested_epoch>
        <tested_version operator="equals">2.3.11</tested_version>
        <tested_release operator="equals">1.9.0</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <registry_test id="wrt-99" comment="the patch kb828028 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB828028</key>
        <name>Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-49" comment="the version of msasn1.dll is less than 5.0.2195.6823" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\msasn1.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>2195</build>
          <private>6823</private>
        </version>
      </data>
    </file_test>
    <patch_test id="hpt-34" comment="Patch PHNE_31732 or later is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <area_patched>PHNE</area_patched>
        <patch_number operator="greater than or equal">31732</patch_number>
      </object>
    </patch_test>
    <patch_test id="hpt-33" comment="Patch PHNE_30983 or later is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <area_patched>PHNE</area_patched>
        <patch_number operator="greater than or equal">30983</patch_number>
      </object>
    </patch_test>
    <compound_test id="cmp-725" comment="Either PHNE_30983 or PHNE_31732 is installed" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="hpt-33"/>
      <subtest test_ref="hpt-34"/>
    </compound_test>
    <swlist_test id="hst-26" comment="InternetSrvcs.INETSVCS2-RUN is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <swlist operator="equals">InternetSrvcs.INETSVCS2-RUN</swlist>
      </object>
      <data>
        <version operator="equals">B.11.23</version>
      </data>
    </swlist_test>
    <permission_test id="upt-730" comment="/usr/bin/mikmod is executable by any user" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/mikmod</component>
        </path>
      </object>
      <data operation="OR">
        <gexec datatype="boolean" operator="equals">1</gexec>
        <oexec datatype="boolean" operator="equals">1</oexec>
        <uexec datatype="boolean" operator="equals">1</uexec>
      </data>
    </permission_test>
    <rpmversioncompare_test id="rvt-8" comment="mikmod RPM prior to 0:3.1.6-22.EL3" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name operator="equals">mikmod</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">3.1.6</tested_version>
        <tested_release operator="equals">22.EL3</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <registry_test id="wrt-344" comment="license logging service is enabled" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">SYSTEM\CurrentControlSet\Services\LicenseService</key>
        <name operator="equals">Start</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="not equal">4</value>
      </data>
    </registry_test>
    <file_test id="wft-393" comment="the version of Llssrv.exe is less than 4.0.1381.33632" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\llssrv.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>4</major>
          <minor>0</minor>
          <build>1381</build>
          <private>33632</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-96" comment="the patch kb885834 is installed (Hotfix key)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB885834</key>
        <name operator="equals">Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <compound_test id="cmp-45" comment="Windows NT Server 4.0, Terminal Server Edition is installed" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-77"/>
      <subtest negate="false" test_ref="wrt-43"/>
    </compound_test>
    <swlist_test id="hst-44" comment="CIFS-Server.CIFS-LIB with version equal A.02.01 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <swlist operator="equals">CIFS-Server.CIFS-LIB</swlist>
      </object>
      <data>
        <version operator="equals">A.02.01</version>
      </data>
    </swlist_test>
    <swlist_test id="hst-43" comment="CIFS-Server.CIFS-ADMIN with version equal A.02.01 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <swlist operator="equals">CIFS-Server.CIFS-ADMIN</swlist>
      </object>
      <data>
        <version operator="equals">A.02.01</version>
      </data>
    </swlist_test>
    <swlist_test id="hst-42" comment="CIFS-Server.CIFS-UTIL with version equal A.02.01 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <swlist operator="equals">CIFS-Server.CIFS-UTIL</swlist>
      </object>
      <data>
        <version operator="equals">A.02.01</version>
      </data>
    </swlist_test>
    <swlist_test id="hst-41" comment="CIFS-Server.CIFS-RUN with version equal A.02.01 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <swlist operator="equals">CIFS-Server.CIFS-RUN</swlist>
      </object>
      <data>
        <version operator="equals">A.02.01</version>
      </data>
    </swlist_test>
    <compound_test id="cmp-718" comment="Any of the CIFS components has a version equal to A.02.01" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="hst-41"/>
      <subtest test_ref="hst-42"/>
      <subtest test_ref="hst-43"/>
      <subtest test_ref="hst-44"/>
    </compound_test>
    <compound_test id="cmp-716" comment="An HPUX 11.11 or 11.23 is installed" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="cmp-618"/>
      <subtest test_ref="cmp-682"/>
    </compound_test>
    <rpmversioncompare_test id="rvt-31" comment="mozilla RPM is earlier than 37:1.7.10-1.1.3.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <oval:notes>
        <oval:note>Multiple RPMs were updated in this release, but all but mozilla-nspr have mozilla-with-their-same-version as an installation dependency.  So, if mozilla is up to date, mozilla-chat, mozilla-devel, ... , mozilla-js-debugger are all up to date.  Mozilla itself requires that mozilla-nspr and mozilla-nss be installed with the same version as itself.  This closes the loop -- if mozilla is up to date, so are the other mozilla-FOO RPMs.</oval:note>
      </oval:notes>
      <object>
        <name datatype="string" operator="equals">mozilla</name>
        <tested_epoch datatype="string" operator="equals">37</tested_epoch>
        <tested_version datatype="string" operator="equals">1.7.10</tested_version>
        <tested_release datatype="string" operator="equals">1.1.3.1</tested_release>
      </object>
      <data operation="AND">
        <installed_version datatype="string" operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <rpminfo_test id="rrt-216" comment="Red Hat Enterprise 3 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">redhat-release</name>
      </object>
      <data operation="AND">
        <version operator="pattern match">^.*3.S</version>
      </data>
    </rpminfo_test>
    <file_test id="wft-15" comment="the version of excel.exe is less than 9.0.0.8216" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Excel.exe\Path</component>
          <component type="literal">excel.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>9</major>
          <minor>0</minor>
          <build>0</build>
          <private>8216</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-137" comment="Excel 2000 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Office\9.0\Excel\InstallRoot</key>
        <name operator="pattern match">.*</name>
      </object>
    </registry_test>
    <inetlisteningservers_test id="rlt-213" comment="vsftpd is listening to the network" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <program_name datatype="string" operator="pattern match">^.*vsftpd.*</program_name>
      </object>
      <data operation="AND">
        <protocol operator="equals">TCP</protocol>
      </data>
    </inetlisteningservers_test>
    <rpmversioncompare_test id="rvt-252" comment="vsftpd version is less than 1.1.3-8" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">vsftpd</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">1.1.3</tested_version>
        <tested_release datatype="int" operator="equals">8</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <process_test id="uct-2" comment="rhnsd is running" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <command datatype="string" operator="pattern match">^.*rhnsd.*$</command>
      </object>
    </process_test>
    <rpmversioncompare_test id="rvt-251" comment="up2date version is less than 3.1.23.1-5" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">up2date</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">3.1.23.1</tested_version>
        <tested_release datatype="int" operator="equals">5</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <unknown_test id="ukn-13" comment="a vulnerable version of shtml.dll exists (FPSE 2002 or SPTS 2003)" xmlns="http://oval.mitre.org/XMLSchema/oval#independent"/>
    <file_test id="wft-734" comment="the version of Mapi32.dll is less than 5.5.2658.34" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\Mapi32.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>5</minor>
          <build>2658</build>
          <private>34</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-504" comment="Exchange 5.5 with SP4 Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Exchange\Setup</key>
        <name>ServicePackBuild</name>
      </object>
      <data operation="AND">
        <value>2653</value>
      </data>
    </registry_test>
    <permission_test id="upt-58" comment="/tmp is world-writable" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <oval:notes>
        <oval:note>For "/tmp is readable by non-root users," use a compound test.</oval:note>
      </oval:notes>
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/tmp</component>
        </path>
      </object>
      <data operation="AND">
        <owrite datatype="boolean" operator="equals">1</owrite>
      </data>
    </permission_test>
    <rpmversioncompare_test id="rvt-24" comment="sysreport RPM earlier than 0:1.3.7.2-6" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name operator="equals">sysreport</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">1.3.7.2</tested_version>
        <tested_release operator="equals">6</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <permission_test id="upt-102" comment="/usr/bin/unzip is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/unzip</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-101" comment="/usr/bin/unzip is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/unzip</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-100" comment="/usr/bin/unzip is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/unzip</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-335" comment="/usr/bin/unzip is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-100"/>
      <subtest negate="false" test_ref="upt-101"/>
      <subtest negate="false" test_ref="upt-102"/>
    </compound_test>
    <rpmversioncompare_test id="rvt-250" comment="unzip version is less than 5.50-33" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">unzip</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">5.50</tested_version>
        <tested_release datatype="int" operator="equals">33</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <rpmversioncompare_test id="rvt-249" comment="squirrelmail version is less than 1.2.11-1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">squirrelmail</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">1.2.11</tested_version>
        <tested_release datatype="int" operator="equals">1</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <compound_test id="cmp-176" comment="    a vulnerable version of mshtml.dll exists " operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-22"/>
      <subtest negate="true" test_ref="wrt-3"/>
      <subtest negate="false" test_ref="wft-97"/>
    </compound_test>
    <file_test id="wft-97" comment="the version of mshtml.dll is less than 6.0.3790.2440" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mshtml.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>3790</build>
          <private>2440</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-169" comment=" a vulnerable version of mshtml.dll exists" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-23"/>
      <subtest negate="false" test_ref="wrt-4"/>
      <subtest negate="false" test_ref="wft-97"/>
    </compound_test>
    <file_test id="wft-96" comment="the version of mshtml.dll is less than 6.0.3790.327" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mshtml.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>3790</build>
          <private>327</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-168" comment="a vulnerable version of mshtml.dll exists" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-23"/>
      <subtest negate="true" test_ref="wrt-3"/>
      <subtest negate="false" test_ref="wft-96"/>
    </compound_test>
    <compound_test id="cmp-179" comment="a vulnerable version of mshtml.dll exisits" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-168"/>
      <subtest negate="false" test_ref="cmp-169"/>
      <subtest negate="false" test_ref="cmp-176"/>
    </compound_test>
    <registry_test id="wrt-27" comment="the patch KB896428 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB896428</key>
        <name operator="equals">Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <compound_test id="cmp-189" comment="  for 64-bit (x64 arch) Windows (gold edition) a vulnerable version of telnet.exe exists" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-22"/>
      <subtest negate="true" test_ref="wrt-3"/>
      <subtest negate="false" test_ref="wft-74"/>
    </compound_test>
    <file_test id="wft-74" comment="the version of telnet.exe is less than 5.2.3790.2442" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\telnet.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>2</minor>
          <build>3790</build>
          <private>2442</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-186" comment="  for specific Windows configurations a vulnerable version of telnet.exe exists " operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-4"/>
      <subtest negate="false" test_ref="cmp-23"/>
      <subtest negate="false" test_ref="wft-74"/>
    </compound_test>
    <file_test id="wft-75" comment="the version of telnet.exe is less than 5.2.3790.329" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\telnet.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>2</minor>
          <build>3790</build>
          <private>329</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-184" comment="for specific Windows configurations a vulnerable version of telnet.exe exists" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="true" test_ref="wrt-3"/>
      <subtest negate="false" test_ref="cmp-23"/>
      <subtest negate="false" test_ref="wft-75"/>
    </compound_test>
    <compound_test id="cmp-167" comment="a vulnerable version of telnet.exe exists" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-184"/>
      <subtest negate="false" test_ref="cmp-186"/>
      <subtest negate="false" test_ref="cmp-189"/>
    </compound_test>
    <patch_test id="hpt-19" comment="Patch PHSS_32366 or later is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <area_patched>PHSS</area_patched>
        <patch_number operator="equals">32366</patch_number>
      </object>
    </patch_test>
    <patch_test id="hpt-18" comment="Patch PHSS_31833 or later is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <area_patched>PHSS</area_patched>
        <patch_number operator="equals">31833</patch_number>
      </object>
    </patch_test>
    <patch_test id="hpt-17" comment="Patch PHSS_33589 or later is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <area_patched>PHSS</area_patched>
        <patch_number operator="equals">33589</patch_number>
      </object>
    </patch_test>
    <patch_test id="hpt-16" comment="Patch PHSS_30791 or later is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <area_patched>PHSS</area_patched>
        <patch_number operator="equals">30791</patch_number>
      </object>
    </patch_test>
    <patch_test id="hpt-15" comment="Patch PHSS_32109 or later is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <area_patched>PHSS</area_patched>
        <patch_number operator="equals">32109</patch_number>
      </object>
    </patch_test>
    <compound_test id="cmp-685" comment="A vulnerable patch to xterm is installed" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="hpt-15"/>
      <subtest test_ref="hpt-16"/>
      <subtest test_ref="hpt-17"/>
      <subtest test_ref="hpt-18"/>
      <subtest test_ref="hpt-19"/>
    </compound_test>
    <swlist_test id="hst-28" comment="X11.X11-RUN-CL is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#hpux">
      <object>
        <swlist operator="equals">X11.X11-RUN-CL</swlist>
      </object>
    </swlist_test>
    <compound_test id="cmp-681" comment="800 Series OS Release 11.23" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-11"/>
      <subtest test_ref="uut-19"/>
    </compound_test>
    <uname_test id="uut-19" comment="HP Release B.11.23" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <data operation="AND">
        <os_name operator="equals">HP-UX</os_name>
        <os_release operator="equals">B.11.23</os_release>
      </data>
    </uname_test>
    <compound_test id="cmp-680" comment="700 Series OS Release 11.23" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-10"/>
      <subtest test_ref="uut-19"/>
    </compound_test>
    <compound_test id="cmp-682" comment="700 Series or 800 Series OS Release 11.23" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="cmp-680"/>
      <subtest test_ref="cmp-681"/>
    </compound_test>
    <compound_test id="cmp-617" comment="800 Series OS Release 11.00" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-11"/>
      <subtest test_ref="uut-8"/>
    </compound_test>
    <uname_test id="uut-8" comment="HP Release B.11.00" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <data operation="AND">
        <os_name operator="equals">HP-UX</os_name>
        <os_release operator="equals">B.11.00</os_release>
      </data>
    </uname_test>
    <compound_test id="cmp-616" comment="700 Series OS Release 11.00" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-10"/>
      <subtest test_ref="uut-8"/>
    </compound_test>
    <compound_test id="cmp-619" comment="700 Series or 800 Series OS Release 11.00" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="cmp-616"/>
      <subtest test_ref="cmp-617"/>
    </compound_test>
    <uname_test id="uut-11" comment="800-series HP" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <data operation="AND">
        <machine_class operator="pattern match">\d+/8\d+</machine_class>
        <os_name operator="equals">HP-UX</os_name>
      </data>
    </uname_test>
    <compound_test id="cmp-615" comment="800 Series OS Release 11.11" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-11"/>
      <subtest test_ref="uut-9"/>
    </compound_test>
    <uname_test id="uut-9" comment="HP Release B.11.11" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <data operation="AND">
        <os_name operator="equals">HP-UX</os_name>
        <os_release operator="equals">B.11.11</os_release>
      </data>
    </uname_test>
    <uname_test id="uut-10" comment="700-series HP" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <data operation="AND">
        <machine_class operator="pattern match">\d+/7\d+</machine_class>
        <os_name operator="equals">HP-UX</os_name>
      </data>
    </uname_test>
    <compound_test id="cmp-614" comment="700 Series OS Release 11.11" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="uut-10"/>
      <subtest test_ref="uut-9"/>
    </compound_test>
    <compound_test id="cmp-618" comment="700 Series or 800 Series OS Release 11.11" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="cmp-614"/>
      <subtest test_ref="cmp-615"/>
    </compound_test>
    <compound_test id="cmp-684" comment="700 Series or 800 Series OS Release 11.00, 11.11, or 11.23" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="cmp-618"/>
      <subtest test_ref="cmp-619"/>
      <subtest test_ref="cmp-682"/>
    </compound_test>
    <inetlisteningservers_test id="rlt-212" comment="sendmail is listening to the network" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <program_name datatype="string" operator="pattern match">^.*sendmail.*</program_name>
      </object>
    </inetlisteningservers_test>
    <rpmversioncompare_test id="rvt-248" comment="sendmail version is less than 8.12.8-6.90" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">sendmail</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">8.12.8</tested_version>
        <tested_release operator="equals">6.90</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <rpmversioncompare_test id="rvt-247" comment="sendmail version is less than 8.12.8-9.90" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">sendmail</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">8.12.8</tested_version>
        <tested_release operator="equals">9.90</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <registry_test id="wrt-195" comment="MSN Messenger 6.2.0205 or later is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="pattern match">SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\.*</key>
        <name operator="equals">DisplayVersion</name>
      </object>
      <data operation="AND">
        <value operator="pattern match">6\.2\.020[5-9]</value>
      </data>
    </registry_test>
    <registry_test id="wrt-620" comment="MSN Messenger 6.2 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="pattern match">SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\.*</key>
        <name operator="equals">DisplayName</name>
      </object>
      <data operation="AND">
        <value operator="equals">MSN Messenger 6.2</value>
      </data>
    </registry_test>
    <process_test id="uct-19" comment="in.rwhod is running" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <command operator="equals">/usr/sbin/in.rwhod</command>
      </object>
    </process_test>
    <patch_test id="spt-70" comment="Patch 117455-01 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">117455</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">01</version>
      </data>
    </patch_test>
    <patch_test id="spt-69" comment="Patch 116984-01 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">116984</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">01</version>
      </data>
    </patch_test>
    <patch_test id="spt-68" comment="Patch 118239-01 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">118239</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">01</version>
      </data>
    </patch_test>
    <package_test id="sat-38" comment="Remote Network Server Commands - Usr (SUNWrcmds) installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <pkginst operator="equals">SUNWrcmds</pkginst>
      </object>
    </package_test>
    <compound_test id="cmp-85" comment="Solaris 9 and Remote Network Server Commands (SUNWrcmds) installed" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="uut-6"/>
      <subtest negate="false" test_ref="sat-38"/>
    </compound_test>
    <compound_test id="cmp-87" comment="Solaris 7 or 8 OR Solaris 9 and Remote Network Server Commands (SUNWrcmds) installed" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-43"/>
      <subtest negate="false" test_ref="cmp-85"/>
    </compound_test>
    <registry_test id="wrt-33" comment="FrontPage Server Extensions 2000 are enabled (WinNT)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Shared Tools\Web Server Extensions\Setup Packages</key>
        <name operator="equals">FrontPage 2000 Server Extensions SR</name>
      </object>
    </registry_test>
    <file_test id="wft-589" comment="the version of shell32.dll is less than 6.0.3790.274" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\shell32.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>3790</build>
          <private>274</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-34" comment="Microsoft Windows Server 2003 64-Bit Edition " operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-61"/>
      <subtest negate="false" test_ref="wrt-70"/>
    </compound_test>
    <compound_test id="cmp-183" comment="Windows Server 2003 64-Bit Edition or Windows XP 64-Bit Edition Version 2003 " operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-34"/>
      <subtest negate="false" test_ref="cmp-1112"/>
    </compound_test>
    <file_test id="wft-18" comment="the version of winword.exe is less than 8.0.0.9716" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Winword.exe\Path</component>
          <component type="literal">\winword.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>8</major>
          <minor>0</minor>
          <build>0</build>
          <private>9716</private>
        </version>
      </data>
    </file_test>
    <unknown_test id="ukn-11" comment="Word 98 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#independent"/>
    <file_test id="wft-17" comment="the version of winword.exe is less than 8.0.0.9315" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Winword.exe\Path</component>
          <component type="literal">winword.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>8</major>
          <minor>0</minor>
          <build>0</build>
          <private>9315</private>
        </version>
      </data>
    </file_test>
    <unknown_test id="ukn-10" comment="Word 97 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <oval:notes>
        <oval:note>We think, but are not sure that the affected version of bkupexec.exe is 3.60.1.298 The file should be found in C:Program Files\VERITAS\Backup Exec\NT\bkupexec.exe</oval:note>
      </oval:notes>
    </unknown_test>
    <registry_test id="wrt-617" comment="Mozilla Firefox version 1.0.6 or earlier is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key datatype="string" operator="pattern match">SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Mozilla Firefox (\(0\.[0-9].*\)|\(1\.0\)|\(1\.0\.[0-6]\))</key>
        <name datatype="string" operator="equals">DisplayName</name>
      </object>
      <data operation="AND">
        <value datatype="string" operator="pattern match">Mozilla Firefox (\(0\.[0-9].*\)|\(1\.0\)|\(1\.0\.[0-6]\))</value>
      </data>
    </registry_test>
    <registry_test id="wrt-616" comment="Firefox version 1.0.6 or earlier is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key datatype="string" operator="equals">SOFTWARE\Mozilla\Mozilla Firefox</key>
        <name datatype="string" operator="equals">CurrentVersion</name>
      </object>
      <data operation="AND">
        <value datatype="string" operator="pattern match">(0\.[0-9].*|1\.0($|\s).*|1\.0\.[1-6]($|\s).*)</value>
      </data>
    </registry_test>
    <compound_test id="cmp-631" comment="Mozilla Firefox version 1.0.6 or earlier is installed" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="wrt-616"/>
      <subtest test_ref="wrt-617"/>
    </compound_test>
    <registry_test id="wrt-615" comment="Mozilla Suite version 1.7.10 or earlier is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key datatype="string" operator="equals">SOFTWARE\mozilla.org\Mozilla</key>
        <name datatype="string" operator="equals">CurrentVersion</name>
      </object>
      <data operation="AND">
        <value datatype="string" operator="pattern match">([0-1]\.[0-7]($|\s).*|[0-1]\.[0-7]\.[0-8]($|\s).*|1\.7\.10($|\s).*)</value>
      </data>
    </registry_test>
    <registry_test id="wrt-614" comment="Mozilla Suite version 1.7.10 or earlier is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key datatype="string" operator="pattern match">SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Mozilla (\([0-1]\.[0-7]\)|\([0-1]\.[0-7]\.[0-9]\)|\(1\.7\.10\))</key>
        <name datatype="string" operator="equals">DisplayName</name>
      </object>
      <data operation="AND">
        <value datatype="string" operator="pattern match">Mozilla (\([0-1]\.[0-7]\)|\([0-1]\.[0-7]\.[0-9]\)|\(1\.7\.10\))</value>
      </data>
    </registry_test>
    <compound_test id="cmp-621" comment="Mozilla Suite version 1.7.10 or earlier is installed" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="wrt-614"/>
      <subtest test_ref="wrt-615"/>
    </compound_test>
    <file_test id="wft-302" comment="the version of msjava.dll is less than 5.0.3809.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\msjava.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>3809</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-680" comment="cdosys.dll is less than 6.5.6756.0" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\cdosys.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>5</minor>
          <build>6756</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-660" comment="the version of rpcss.dll is less than 5.2.3790.2492" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\rpcss.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>2</minor>
          <build>3790</build>
          <private>2492</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-659" comment="the version of ole32.dll is less than 5.2.3790.2492" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\ole32.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>2</minor>
          <build>3790</build>
          <private>2492</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-608" comment="Either ole32.dll or rpcss.dll has a version less than 5.2.3790.2492" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="wft-659"/>
      <subtest test_ref="wft-660"/>
    </compound_test>
    <registry_test id="wrt-86" comment="the patch q828748 is installed (Hotfix key)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB828749</key>
        <name>Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-8" comment="the version of wkssvc.dll is less than 5.00.2195.6862" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\wkssvc.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>00</minor>
          <build>2195</build>
          <private>6862</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-435" comment="the patch  KB893086 is installed " check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">SOFTWARE\Microsoft\Updates\Windows XP\SP3\KB893086\Filelist</key>
        <name operator="pattern match">^.*$</name>
      </object>
    </registry_test>
    <file_test id="wft-591" comment="the version of shell32.dll is less than 6.0.2900.2620" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\shell32.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>2900</build>
          <private>2620</private>
        </version>
      </data>
    </file_test>
    <inetlisteningservers_test id="rlt-211" comment="sendmail listening" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <program_name datatype="string" operator="pattern match">^.*sendmail.*</program_name>
      </object>
      <data operation="AND">
        <protocol operator="equals">TCP</protocol>
      </data>
    </inetlisteningservers_test>
    <permission_test id="upt-99" comment="sendmail is Set-GID" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/sbin/sendmail.sendmail</component>
        </path>
      </object>
      <data operation="AND">
        <sgid datatype="int" operator="equals">1</sgid>
      </data>
    </permission_test>
    <compound_test id="cmp-326" comment="sendmail is Set-GID" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-99"/>
      <subtest negate="false" test_ref="upt-98"/>
    </compound_test>
    <permission_test id="upt-98" comment="sendmail is Set-UID" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/sbin/sendmail.sendmail</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-97" comment="sendmail is Set-UID" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/sbin/sendmail.sendmail</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <compound_test id="cmp-325" comment="sendmail is Set-UID" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-97"/>
      <subtest negate="false" test_ref="upt-98"/>
    </compound_test>
    <permission_test id="upt-96" comment="sendmail is Set-UID" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/sbin/sendmail.sendmail</component>
        </path>
      </object>
      <data operation="AND">
        <suid datatype="int" operator="equals">1</suid>
      </data>
    </permission_test>
    <compound_test id="cmp-324" comment="sendmail is Set-UID" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-96"/>
      <subtest negate="false" test_ref="cmp-325"/>
    </compound_test>
    <compound_test id="cmp-323" comment="Vulnerable Config" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-324"/>
      <subtest negate="false" test_ref="cmp-326"/>
      <subtest negate="false" test_ref="rlt-211"/>
    </compound_test>
    <rpmversioncompare_test id="rvt-246" comment="sendmail version is less than 8.12.8-5.90" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">sendmail</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">8.12.8</tested_version>
        <tested_release operator="equals">5.90</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <permission_test id="upt-95" comment="/usr/bin/xemacs is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/xemacs</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-94" comment="/usr/bin/xemacs is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/xemacs</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-93" comment="/usr/bin/xemacs is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/xemacs</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-322" comment="/usr/bin/xemacs is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-93"/>
      <subtest negate="false" test_ref="upt-94"/>
      <subtest negate="false" test_ref="upt-95"/>
    </compound_test>
    <permission_test id="upt-92" comment="/usr/bin/emacs is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/emacs</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-91" comment="/usr/bin/emacs is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/emacs</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-90" comment="/usr/bin/emacs is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/emacs</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-321" comment="/usr/bin/emacs is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-90"/>
      <subtest negate="false" test_ref="upt-91"/>
      <subtest negate="false" test_ref="upt-92"/>
    </compound_test>
    <compound_test id="cmp-320" comment="Vulnerable Config" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-321"/>
      <subtest negate="false" test_ref="cmp-322"/>
    </compound_test>
    <rpmversioncompare_test id="rvt-245" comment="wl-xemacs version is less than 2.10.1-1.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">wl-xemacs</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">2.10.1</tested_version>
        <tested_release operator="equals">1.1</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <rpmversioncompare_test id="rvt-244" comment="wl version is less than 2.10.1-1.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">wl</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">2.10.1</tested_version>
        <tested_release operator="equals">1.1</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <compound_test id="cmp-319" comment="Vulnerable Config" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="rvt-244"/>
      <subtest negate="false" test_ref="rvt-245"/>
    </compound_test>
    <inetlisteningservers_test id="rlt-210" comment="smbd is listening on the network" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <program_name datatype="string" operator="pattern match">^.*smbd.*</program_name>
      </object>
    </inetlisteningservers_test>
    <rpmversioncompare_test id="rvt-243" comment="samba version is less than 2.2.7a-8.9.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">samba</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">2.2.7a</tested_version>
        <tested_release operator="equals">8.9.0</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <package_test id="sat-12" comment="X Window System platform software (SUNWxwplt) installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <pkginst operator="equals">SUNWxwplt</pkginst>
      </object>
    </package_test>
    <patch_test id="spt-5" comment="Patch 108652-30 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">108652</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">30</version>
      </data>
    </patch_test>
    <patch_test id="spt-4" comment="Patch 108376-25 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">108376</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">25</version>
      </data>
    </patch_test>
    <compound_test id="cmp-43" comment="Solaris 7 or 8 installed" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="uut-5"/>
      <subtest negate="false" test_ref="uut-4"/>
    </compound_test>
    <file_test id="wft-36" comment="the version of sqlsrv32.dll is less than 2000.80.747.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\sqlsrv32.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>2000</major>
          <minor>80</minor>
          <build>747</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-41" comment="the version of odbcbcp.dll is less than 2000.80.747.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\odbcbcp.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>2000</major>
          <minor>80</minor>
          <build>747</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <inetlisteningservers_test id="rlt-209" comment="smbd listens on the network" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <program_name datatype="string" operator="pattern match">^.*smbd.*</program_name>
      </object>
      <data operation="AND">
        <protocol operator="equals">TCP</protocol>
      </data>
    </inetlisteningservers_test>
    <rpmversioncompare_test id="rvt-242" comment="samba version is less than 2.2.7a-7.9.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">samba</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">2.2.7a</tested_version>
        <tested_release operator="equals">7.9.0</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <file_test id="wft-654" comment="the version of rpcss.dll is less than 5.0.2195.7059" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\rpcss.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>2195</build>
          <private>7059</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-653" comment="the version of ole32.dll is less than 5.0.2195.7059" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\ole32.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>2195</build>
          <private>7059</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-605" comment="Either ole32.dll or rpcss.dll has a version less than 5.0.2195.7059" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest test_ref="wft-653"/>
      <subtest test_ref="wft-654"/>
    </compound_test>
    <registry_test id="wrt-432" comment="Win2K/XP/2003 service pack 4 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion</key>
        <name>CSDVersion</name>
      </object>
      <data operation="AND">
        <value operator="equals">^Service Pack 4</value>
      </data>
    </registry_test>
    <file_test id="wft-713" comment="the version of wordpad.exe is less than 5.2.3790.224" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir</component>
          <component type="literal">\Windows NT\Accessories\wordpad.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>2</minor>
          <build>3790</build>
          <private>224</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-1112" comment="Windows XP 64-bit" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-2"/>
      <subtest negate="false" test_ref="wrt-70"/>
    </compound_test>
    <registry_test id="wrt-140" comment="the patch q832894 is installed (Hotfix key)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB832894</key>
        <name>Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-95" comment="the version of mshtml.dll is less than 6.0.3790.118" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mshtml.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>3790</build>
          <private>118</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-110" comment="the patch q832483 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Updates\DataAccess\Q832483</key>
        <name>IsInstalled</name>
      </object>
      <data operation="AND">
        <value operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-35" comment="the version of sqlsrv32.dll is less than 3.70.11.46" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\sqlsrv32.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>3</major>
          <minor>70</minor>
          <build>11</build>
          <private>46</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-40" comment="the version of odbcbcp.dll is less than 3.70.11.46" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\odbcbcp.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>3</major>
          <minor>70</minor>
          <build>11</build>
          <private>46</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-100" comment="MDAC 2.5 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\DataAccess</key>
        <name>FullInstallVer</name>
      </object>
      <data operation="AND">
        <value operator="pattern match">^2\.5.*$</value>
      </data>
    </registry_test>
    <inetlisteningservers_test id="rlt-208" comment="smtpd listens on the network" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <program_name datatype="string" operator="pattern match">^.*smtpd.*</program_name>
      </object>
    </inetlisteningservers_test>
    <rpmversioncompare_test id="rvt-241" comment="postfix version is less than 1.1.12-1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">postfix</name>
        <tested_epoch datatype="int" operator="equals">2</tested_epoch>
        <tested_version operator="equals">1.1.12</tested_version>
        <tested_release datatype="int" operator="equals">1</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <file_test id="wft-94" comment="the version of mshtml.dll is less than 6.0.2800.1400" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mshtml.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>2800</build>
          <private>1400</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-93" comment="the version of mshtml.dll is less than 6.0.2737.800" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mshtml.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>2737</build>
          <private>800</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-92" comment="the version of mshtml.dll is less than 5.50.4937.800" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mshtml.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>50</minor>
          <build>4937</build>
          <private>800</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-91" comment="the version of mshtml.dll is less than 5.0.3813.800" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mshtml.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>3813</build>
          <private>800</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-268" comment="the version of mshtml.dll is less than 6.0.2743.600" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mshtml.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>2743</build>
          <private>600</private>
        </version>
      </data>
    </file_test>
    <permission_test id="upt-89" comment="/usr/bin/pine is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pine</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-88" comment="/usr/bin/pine is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pine</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-87" comment="/usr/bin/pine is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/pine</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-314" comment="/usr/bin/pine is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-87"/>
      <subtest negate="false" test_ref="upt-88"/>
      <subtest negate="false" test_ref="upt-89"/>
    </compound_test>
    <rpmversioncompare_test id="rvt-240" comment="pine version is less than 4.44-19.90.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">pine</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">4.44</tested_version>
        <tested_release operator="equals">19.90.0</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <registry_test id="wrt-141" comment="the patch q832894 is installed (Installed Components key)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Active Setup\Installed Components\{eddbec60-89cb-44ef-8291-0850fd28ff6a}</key>
        <name>IsInstalled</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-90" comment="the version of mshtml.dll is less than 5.0.3526.800" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mshtml.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>3526</build>
          <private>800</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-102" comment="MDAC 2.7 (RTM) is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\DataAccess</key>
        <name>FullInstallVer</name>
      </object>
      <data operation="AND">
        <value operator="pattern match">^2\.70.*$</value>
      </data>
    </registry_test>
    <registry_test id="wrt-460" comment="SQL Server 2000 installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\MSSQLServer\MSSQLServer\CurrentVersion</key>
        <name>CurrentVersion</name>
      </object>
      <data operation="AND">
        <value operator="equals">8.00.194</value>
      </data>
    </registry_test>
    <rpmversioncompare_test id="rvt-239" comment="php version is less than 4.2.2-17.2" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">php</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">4.2.2</tested_version>
        <tested_release operator="equals">17.2</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <file_test id="wft-492" comment="the version of sqlservr.exe is less than 2000.80.760.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
          <component type="literal">\sqlservr.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>2000</major>
          <minor>80</minor>
          <build>760</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-491" comment="the version of sqlisapi.dll is less than 2000.80.309.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\System\Ole DB folder\sqlisapi.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>2000</major>
          <minor>80</minor>
          <build>309</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-296" comment="File %windir%\system32\inetsrv\ssinc.dll version is less than 5.0.2195.6624" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\inetsrv\ssinc.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>2195</build>
          <private>6624</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-107" comment="Microsoft Firewall Service is not disabled" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SYSTEM\CurrentControlSet\Services\Fwsrv</key>
        <name>Start</name>
      </object>
      <data operation="AND">
        <value operator="not equal">4</value>
      </data>
    </registry_test>
    <registry_test id="wrt-108" comment="H.323 filter is enabled" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="pattern match">^SOFTWARE\\Microsoft\\Fpc\\Arrays\\\{[^\\]+\}\\Extensions\\Proxy-Plugins\\\{FE440D49-AB26-11D2-A101-00C04FB6CFB6\}$</key>
        <name>msFPCEnabled</name>
      </object>
      <data operation="AND">
        <value operator="equals">1</value>
      </data>
    </registry_test>
    <registry_test id="wrt-112" comment="the patch q816458 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Fpc\Hotfixes\SP1\291</key>
        <name>Installed</name>
      </object>
      <data operation="AND">
        <value operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-33" comment="the version of h32fltr.dll is less than 3.0.1200.291" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fpc\InstallDirectory</component>
          <component type="literal">h323fltr.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>3</major>
          <minor>0</minor>
          <build>1200</build>
          <private>291</private>
        </version>
      </data>
    </file_test>
    <unknown_test id="ukn-20" comment="Kerberos is disabled on the virtual server that hosts OWA on the Exchange Server 2003 back-end server" xmlns="http://oval.mitre.org/XMLSchema/oval#independent"/>
    <registry_test id="wrt-106" comment="HTTP connection reuse is disabled" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SYSTEM\CurrentControlSet\Services\MSExchangeWEB\DAV</key>
        <name>ReuseConnections</name>
      </object>
      <data operation="AND">
        <value operator="equals">0</value>
      </data>
    </registry_test>
    <unknown_test id="ukn-22" comment="the back-end server is Exchange Server 2003 running on Windows 2003" xmlns="http://oval.mitre.org/XMLSchema/oval#independent"/>
    <unknown_test id="ukn-21" comment="this is a front-end server providing Outlook Web Access" xmlns="http://oval.mitre.org/XMLSchema/oval#independent"/>
    <registry_test id="wrt-109" comment="the patch KB832759 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">SOFTWARE\Microsoft\Updates\Exchange Server 2003\SP1\832759</key>
        <name operator="pattern match">.*</name>
      </object>
    </registry_test>
    <file_test id="wft-34" comment="the version of exprox.dll is less than 6.5.6980.57" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Exchange\Setup\Services</component>
          <component type="literal">\bin\exprox.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>5</minor>
          <build>6980</build>
          <private>57</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-293" comment="File %windir%\system32\mshtml.dll version is less than 5.0.3510.1100" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mshtml.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>3510</build>
          <private>1100</private>
        </version>
      </data>
    </file_test>
    <rpmversioncompare_test id="rvt-238" comment="perl-CGI version is less than 2.81-88.3" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">perl-CGI</name>
        <tested_epoch datatype="int" operator="equals">2</tested_epoch>
        <tested_version operator="equals">2.81</tested_version>
        <tested_release operator="equals">88.3</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <rpmversioncompare_test id="rvt-237" comment="pam_smb version is less than 1.1.6-9.9" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">pam_smb</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">1.1.6</tested_version>
        <tested_release operator="equals">9.9</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <registry_test id="wrt-52" comment="the patch KB899753 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">SOFTWARE\Microsoft\FPC\Hotfixes\SP1\430</key>
        <name operator="equals">kbs</name>
      </object>
      <data operation="AND">
        <value operator="equals">KB899753</value>
      </data>
    </registry_test>
    <file_test id="wft-81" comment="the version of w3proxy.exe is less than 3.0.1200.430" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Microsoft ISA Server</component>
          <component type="literal">\w3proxy.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>3</major>
          <minor>0</minor>
          <build>1200</build>
          <private>430</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-11" comment="ISA Server 2000 SP2 (or earlier) is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Microsoft ISA Server SP</key>
        <name operator="equals">DisplayName</name>
      </object>
      <data operation="AND">
        <value operator="equals">Microsoft ISA Server 2000 Updates</value>
      </data>
    </registry_test>
    <file_test id="wft-145" comment="the version of srv.sys is less than 5.0.2195.7044" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\SYSTEM32\DRIVERS\srv.sys</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>2195</build>
          <private>7044</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-4" comment="the version of hh.exe is less than 5.2.3790.309" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\hh.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>2</minor>
          <build>3790</build>
          <private>309</private>
        </version>
      </data>
    </file_test>
    <rpmversioncompare_test id="rvt-236" comment="openssl096b version is less than 0.9.6b-6" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">openssl096b</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">0.9.6b</tested_version>
        <tested_release datatype="int" operator="equals">6</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <rpmversioncompare_test id="rvt-235" comment="openssl096 version is less than 0.9.6-17" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">openssl096</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">0.9.6</tested_version>
        <tested_release datatype="int" operator="equals">17</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <rpmversioncompare_test id="rvt-234" comment="openssl-perl version is less than 0.9.7a-5" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">openssl-perl</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">0.9.7a</tested_version>
        <tested_release datatype="int" operator="equals">5</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <rpmversioncompare_test id="rvt-233" comment="openssl-devel version is less than 0.9.7a-5" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">openssl-devel</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">0.9.7a</tested_version>
        <tested_release datatype="int" operator="equals">5</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <rpmversioncompare_test id="rvt-232" comment="openssl version is less than 0.9.7a-5" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">openssl</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">0.9.7a</tested_version>
        <tested_release datatype="int" operator="equals">5</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <compound_test id="cmp-914" comment="affected version of SSL and TLS components for OpenSSL" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="rvt-232"/>
      <subtest negate="false" test_ref="rvt-233"/>
      <subtest negate="false" test_ref="rvt-234"/>
      <subtest negate="false" test_ref="rvt-235"/>
      <subtest negate="false" test_ref="rvt-236"/>
    </compound_test>
    <registry_test id="wrt-335" comment="Patch KB822679 Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB822679</key>
        <name>Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-292" comment="the version of umandlg.dll is less than 1.0.0.3" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\umandlg.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>1</major>
          <minor>0</minor>
          <build>0</build>
          <private>3</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-291" comment="the version of sp3res.dll is less than 5.0.2195.6713" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\sp3res.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>2195</build>
          <private>6713</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-36" comment="the patch kb885835is installed (Hotfix key)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB885835</key>
        <name operator="equals">Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-327" comment="the version of lsasrv.dll is less than 5.1.2600.2525" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\lsasrv.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>2525</private>
        </version>
      </data>
    </file_test>
    <process_test id="uct-14" comment="in.named running" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <command operator="equals">/usr/sbin/in.named</command>
      </object>
    </process_test>
    <patch_test id="spt-26" comment="Patch 112970-03 or later installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">112970</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">03</version>
      </data>
    </patch_test>
    <package_test id="sat-19" comment="Internet Domain Name Server (BIND, SUNWinamd) installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <pkginst operator="equals">SUNWinamd</pkginst>
      </object>
    </package_test>
    <rpmversioncompare_test id="rvt-231" comment="openssh-server version is less than 3.5p1-11" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">openssh-server</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">3.5p1</tested_version>
        <tested_release datatype="int" operator="equals">11</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <inetlisteningservers_test id="rlt-207" comment="sshd listens on the network" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <program_name datatype="string" operator="pattern match">^.*sshd.*</program_name>
      </object>
    </inetlisteningservers_test>
    <rpmversioncompare_test id="rvt-230" comment="openssh-server version is less than 3.5p1-6.9" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">openssh-server</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">3.5p1</tested_version>
        <tested_release operator="equals">6.9</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <inetlisteningservers_test id="rlt-206" comment="rpc.mountd listens on the network" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <program_name datatype="string" operator="pattern match">^.*rpc\.mountd.*</program_name>
      </object>
    </inetlisteningservers_test>
    <rpmversioncompare_test id="rvt-229" comment="nfs-utils version is less than 1.0.1-3.9" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">nfs-utils</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">1.0.1</tested_version>
        <tested_release operator="equals">3.9</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <file_test id="wft-411" comment="the version of mscms.dll is less than 5.1.2600.1710" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mscms.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>1710</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-57" comment="Windows XP 32-bit SP1 is installed" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-1058"/>
      <subtest negate="false" test_ref="wrt-4"/>
    </compound_test>
    <inetlisteningservers_test id="rlt-205" comment="mysqld is listening to the network" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <program_name datatype="string" operator="pattern match">^.*mysqld.*</program_name>
      </object>
    </inetlisteningservers_test>
    <rpmversioncompare_test id="rvt-228" comment="mysql-server version is less than 3.23.56-1.9" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">mysql-server</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">3.23.56</tested_version>
        <tested_release operator="equals">1.9</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <permission_test id="upt-86" comment="/usr/bin/mutt is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/mutt</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-85" comment="/usr/bin/mutt is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/mutt</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-84" comment="/usr/bin/mutt is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/mutt</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-305" comment="/usr/bin/mutt is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-84"/>
      <subtest negate="false" test_ref="upt-85"/>
      <subtest negate="false" test_ref="upt-86"/>
    </compound_test>
    <rpmversioncompare_test id="rvt-227" comment="mutt version is less than 1.4.1-1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">mutt</name>
        <tested_epoch datatype="int" operator="equals">5</tested_epoch>
        <tested_version operator="equals">1.4.1</tested_version>
        <tested_release datatype="int" operator="equals">1</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <rpmversioncompare_test id="rvt-226" comment="lv version is less than 4.49.4-9.9.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">lv</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">4.49.4</tested_version>
        <tested_release operator="equals">9.9.1</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <file_test id="wft-484" comment="the version of msohev.dll less than 10.0.2609.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\10.0\Common\InstallRoot\Path</component>
          <component type="literal">msohev.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>10</major>
          <minor>0</minor>
          <build>2609</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-133" comment="Word 2002 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Office\10.0\Word\InstallRoot</key>
        <name operator="pattern match">.*</name>
      </object>
    </registry_test>
    <registry_test id="wrt-334" comment="the telnet service is enabled" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SYSTEM\CurrentControlSet\Services\Tlntsvr</key>
        <name>Start</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="not equal">4</value>
      </data>
    </registry_test>
    <registry_test id="wrt-333" comment="Patch Q307298 Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q307298</key>
        <name>IsInstalled</name>
      </object>
      <data operation="AND">
        <value datatype="binary" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-290" comment="the version of tlntsvr.exe is less than 5.0.33668.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\tlntsvr.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>33668</build>
          <private>1</private>
        </version>
      </data>
    </file_test>
    <inetlisteningservers_test id="rlt-204" comment="lpd listening on the network" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <program_name datatype="string" operator="pattern match">^.*lpd.*</program_name>
      </object>
    </inetlisteningservers_test>
    <permission_test id="upt-83" comment="psbanner is world-executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/libexec/filters/psbanner</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <rpmversioncompare_test id="rvt-225" comment="lprng version is less than 3.8.19-3.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">lprng</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">3.8.19</tested_version>
        <tested_release operator="equals">3.1</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <file_test id="wft-639" comment="the version of wordview.exe is less than 11.0.6506.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Winword.exe\Path</component>
          <component type="literal">wordview.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>11</major>
          <minor>0</minor>
          <build>6506</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-607" comment="Word 2003 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key datatype="string" operator="equals">SOFTWARE\Microsoft\Office\11.0\Word\InstallRoot</key>
        <name datatype="string" operator="pattern match">.*</name>
      </object>
    </registry_test>
    <permission_test id="upt-859" comment="/usr/bin/mozilla is executable" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/mozilla</component>
        </path>
      </object>
      <data operation="OR">
        <gexec datatype="boolean" operator="equals">1</gexec>
        <oexec datatype="boolean" operator="equals">1</oexec>
        <uexec datatype="boolean" operator="equals">1</uexec>
      </data>
    </permission_test>
    <rpmversioncompare_test id="rvt-32" comment="mozilla RPM is earlier than 37:1.7.10-1.4.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <oval:notes>
        <oval:note>Multiple RPMs were updated in this release, but all but mozilla-nspr have mozilla-with-their-same-version as an installation dependency.  So, if mozilla is up to date, mozilla-chat, mozilla-devel, ... , mozilla-js-debugger are all up to date.  Mozilla itself requires that mozilla-nspr and mozilla-nss be installed with the same version as itself.  This closes the loop -- if mozilla is up to date, so are the other mozilla-FOO RPMs.</oval:note>
      </oval:notes>
      <object>
        <name datatype="string" operator="equals">mozilla</name>
        <tested_epoch datatype="string" operator="equals">37</tested_epoch>
        <tested_version datatype="string" operator="equals">1.7.10</tested_version>
        <tested_release datatype="string" operator="equals">1.4.1</tested_release>
      </object>
      <data operation="AND">
        <installed_version datatype="string" operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <rpminfo_test id="rrt-1" comment="Red Hat Enterprise 4 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">redhat-release</name>
      </object>
      <data operation="AND">
        <version datatype="string" operator="pattern match">^.*4.S</version>
      </data>
    </rpminfo_test>
    <permission_test id="upt-82" comment="/usr/bin/konqueror is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/konqueror</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-81" comment="/usr/bin/konqueror is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/konqueror</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-80" comment="/usr/bin/konqueror is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/konqueror</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-304" comment="/usr/bin/konqueror is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-80"/>
      <subtest negate="false" test_ref="upt-81"/>
      <subtest negate="false" test_ref="upt-82"/>
    </compound_test>
    <rpmversioncompare_test id="rvt-224" comment="kdelibs version is less than 3.1-12" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">kdelibs</name>
        <tested_epoch datatype="int" operator="equals">6</tested_epoch>
        <tested_version operator="equals">3.1</tested_version>
        <tested_release datatype="int" operator="equals">12</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <registry_test id="wrt-434" comment="the patch  KB893086 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">SOFTWARE\Microsoft\Updates\Windows Server 2003\SP1\KB893086\ Filelist</key>
        <name operator="pattern match">^.*$</name>
      </object>
    </registry_test>
    <file_test id="wft-588" comment="the version of shell32.dll is less than 6.0.3790.280" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\shell32.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>3790</build>
          <private>280</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-182" comment="Microsoft Windows Server 2003 32-Bit Edition" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-61"/>
      <subtest negate="false" test_ref="wrt-72"/>
    </compound_test>
    <registry_test id="wrt-332" comment="Microsoft Firewall Service Enabled" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SYSTEM\CurrentControlSet\Services\Fwsrv</key>
        <name>Start</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">2</value>
      </data>
    </registry_test>
    <registry_test id="wrt-331" comment="Patch isahf257 installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Fpc\Hotfixes\SP1\257</key>
        <name>Kbs</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">331066</value>
      </data>
    </registry_test>
    <file_test id="wft-101" comment="the version of wpsrv.exe is less than 3.0.1200.257" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Microsoft ISA Server\InstallationLocation</component>
          <component type="literal">\wspsrv.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>3</major>
          <minor>0</minor>
          <build>1200</build>
          <private>257</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-100" comment="the version of w3proxy.exe is less than 3.0.1200.257" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Microsoft ISA Server\InstallationLocation</component>
          <component type="literal">\w3proxy.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>3</major>
          <minor>0</minor>
          <build>1200</build>
          <private>257</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-26" comment="the version of mshtml.dll is less than 6.0.2734.1600" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mshtml.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>2734</build>
          <private>1600</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-629" comment="the version of mshtml.dll is less than 5.0.3831.1800" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mshtml.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>3831</build>
          <private>1800</private>
        </version>
      </data>
    </file_test>
    <permission_test id="upt-428" comment="/usr/bin/gunzip is executable" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/gunzip</component>
        </path>
      </object>
      <data operation="OR">
        <gexec datatype="boolean" operator="equals">1</gexec>
        <oexec datatype="boolean" operator="equals">1</oexec>
        <uexec datatype="boolean" operator="equals">1</uexec>
      </data>
    </permission_test>
    <permission_test id="upt-529" comment="/usr/bin/gzip is executable" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/gzip</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="boolean" operator="equals">1</gexec>
        <oexec datatype="boolean" operator="equals">1</oexec>
        <uexec datatype="boolean" operator="equals">1</uexec>
      </data>
    </permission_test>
    <rpmversioncompare_test id="rvt-7" comment="gzip RPM earlier than 0:1.3.3-12rhel3" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name operator="equals">gzip</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">1.3.3</tested_version>
        <tested_release operator="equals">12.rhel3</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <registry_test id="wrt-57" comment="the patch kb896358 is installed (Hotfix key)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB885836</key>
        <name operator="equals">Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-11" comment="the version of hh.exe is less than 5.2.3790.2435" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\hh.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>2</minor>
          <build>3790</build>
          <private>2435</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-67" comment=" for 64-bit (x64 arch) Windows (gold edition) a vulnerable version of hh.exe exists" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-22"/>
      <subtest negate="true" test_ref="wrt-3"/>
      <subtest negate="false" test_ref="wft-11"/>
    </compound_test>
    <file_test id="wft-13" comment="the version of hh.exe is less than 5.2.3790.2427" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\hh.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>2</minor>
          <build>3790</build>
          <private>2427</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-58" comment="   for specific Windows configurations a vulnerable version of hh.exe exists " operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-23"/>
      <subtest negate="false" test_ref="wrt-4"/>
      <subtest negate="false" test_ref="wft-13"/>
    </compound_test>
    <file_test id="wft-9" comment="the version of hh.exe is less than 5.2.3790.315" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\hh.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>2</minor>
          <build>3790</build>
          <private>315</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-55" comment="for specific Windows configurations a vulnerable version of hh.exe exists " operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-23"/>
      <subtest negate="true" test_ref="wrt-3"/>
      <subtest negate="false" test_ref="wft-9"/>
    </compound_test>
    <compound_test id="cmp-84" comment="a vulnerable version of hh.exe exists" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-55"/>
      <subtest negate="false" test_ref="cmp-58"/>
      <subtest negate="false" test_ref="cmp-67"/>
    </compound_test>
    <registry_test id="wrt-328" comment="the patch q323255 is installed (Hotfix key)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q323255</key>
        <name>Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-103" comment="the version of itss.dll is less than 5.2.3644.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\itss.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>2</minor>
          <build>3644</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-102" comment="the version of itircl.dll is less than 5.2.3644.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\itircl.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>2</minor>
          <build>3644</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-287" comment="the version of hhsetup.dll is less than 5.2.3644.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\hhsetup.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>2</minor>
          <build>3644</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-286" comment="the version of hhctrl.ocx is less than 5.2.3669.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\hhctrl.ocx</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>2</minor>
          <build>3669</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-78" comment="Windows 2000, XP, or 2003 is installed" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-1"/>
      <subtest negate="false" test_ref="wrt-2"/>
      <subtest negate="false" test_ref="wrt-61"/>
    </compound_test>
    <registry_test id="wrt-32" comment="FrontPage Server Extensions 2002 are enabled (NT, 2K, XP)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Shared Tools\Web Server Extensions\5.0\Setup Packages</key>
        <name operator="equals">Microsoft FrontPage Server Extensions 2002</name>
      </object>
    </registry_test>
    <file_test id="wft-113" comment="the version of fp30reg.dll is less than 10.00.4205.0000" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir</component>
          <component type="literal">\Microsoft Shared\web server extensions\50\bin\fp30reg.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>10</major>
          <minor>00</minor>
          <build>4205</build>
          <private>0000</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-32" comment="the version of fp5areg.dll is less than 10.00.4205.0000" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir</component>
          <component type="literal">\Microsoft Shared\web server extensions\50\bin\fp5areg.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>10</major>
          <minor>00</minor>
          <build>4205</build>
          <private>0000</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-113" comment="a vulnerable version of fp30reg.dll or fp5areg.dll exists" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wft-32"/>
      <subtest negate="false" test_ref="wft-113"/>
    </compound_test>
    <compound_test id="cmp-77" comment="Windows NT, 2000, or XP is installed" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-77"/>
      <subtest negate="false" test_ref="wrt-1"/>
      <subtest negate="false" test_ref="wrt-2"/>
    </compound_test>
    <file_test id="wft-114" comment="the version of fp30reg.dll is less than 4.00.02.7523" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir</component>
          <component type="literal">\Microsoft Shared\web server extensions\40\bin\fp30reg.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>4</major>
          <minor>00</minor>
          <build>02</build>
          <private>7523</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-31" comment="the version of fp4areg.dll is less than 4.0.02.7523" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir</component>
          <component type="literal">\Microsoft Shared\web server extensions\40\bin\fp4areg.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>4</major>
          <minor>0</minor>
          <build>02</build>
          <private>7523</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-112" comment="a vulnerable version of fp30reg.dll or fp4areg.dll exists" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wft-31"/>
      <subtest negate="false" test_ref="wft-114"/>
    </compound_test>
    <permission_test id="upt-61" comment="/bin/cpio is executable by all" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/bin/cpio</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="boolean" operator="equals">1</oexec>
      </data>
    </permission_test>
    <rpmversioncompare_test id="rvt-28" comment="cpio rpm is older than 0:2.5-4.RHEL3" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name operator="equals">cpio</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">2.5</tested_version>
        <tested_release operator="equals">4.RHEL3</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <file_test id="uft-4" comment="/etc/httpd/conf.d/php.conf exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/etc/httpd/conf.d/php.conf</component>
        </path>
      </object>
    </file_test>
    <registry_test id="wrt-60" comment="the patch q824145 is installed (Hotfix key)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB824245</key>
        <name>Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-28" comment="the version of mshtml.dll is less than 6.0.3790.94" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mshtml.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>3790</build>
          <private>94</private>
        </version>
      </data>
    </file_test>
    <rpmversioncompare_test id="rvt-27" comment="php RPM prior to  0:4.3.2-24.ent" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name operator="equals">php</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">4.3.2</tested_version>
        <tested_release operator="equals">24.ent</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <file_test id="wft-27" comment="the version of mshtml.dll is less than 6.0.2800.1276" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mshtml.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>2800</build>
          <private>1276</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-25" comment="the version of mshtml.dll is less than 5.50.4934.1600" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mshtml.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>50</minor>
          <build>4934</build>
          <private>1600</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-24" comment="the version of mshtml.dll is less than 5.0.3810.1700" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mshtml.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>3810</build>
          <private>1700</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-285" comment="File %windir%\system32\user32.dll version is less than 5.0.2195.6799" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\user32.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>2195</build>
          <private>6799</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-19" comment="the version of winword.exe is less than 9.0.0.8216" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Winword.exe\Path</component>
          <component type="literal">winword.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>9</major>
          <minor>0</minor>
          <build>0</build>
          <private>8216</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-23" comment="the version of mshtml.dll is less than 5.0.3523.1700" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mshtml.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>3523</build>
          <private>1700</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-325" comment="Patch Q303984 Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q303984</key>
        <name>Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-283" comment="the version of nntpsvc.dll is less than 5.0.2195.3881" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\inetsrv\nntpsvc.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>2195</build>
          <private>3881</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-71" comment="the workstation service is enabled" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SYSTEM\CurrentControlSet\Services\lanmanworkstation</key>
        <name>Start</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="not equal">4</value>
      </data>
    </registry_test>
    <registry_test id="wrt-128" comment="the patch KB901214 is installed " check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB901214</key>
        <name operator="equals">IsInstalled</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-409" comment="the version of mscms.dll is less than 5.1.2600.2709" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mscms.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>2709</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-324" comment="Patch WindowsMedia8-KB817787-x86-ENU.exe Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Updates\Windows Media Player\wm817787</key>
        <name>IsInstalled</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-144" comment="the version of wmplayer.exe is less than 8.0.0.4490" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir</component>
          <component type="literal">\Windows Media Player\wmplayer.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>8</major>
          <minor>0</minor>
          <build>0</build>
          <private>4490</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-323" comment="Patch Q823803 Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q823803</key>
        <name>Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-282" comment="the version of kernel32.dll is less than 4.0.1381.7224" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\kernel32.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>4</major>
          <minor>0</minor>
          <build>1381</build>
          <private>7224</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-40" comment="this is an NT Workstation" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SYSTEM\CurrentControlSet\Control\ProductOptions</key>
        <name>ProductType</name>
      </object>
      <data operation="AND">
        <value operator="equals">WinNT</value>
      </data>
    </registry_test>
    <file_test id="wft-58" comment="the version of impprov.dll is less than 2000.80.650.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
          <component type="literal">\impprov.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>2000</major>
          <minor>80</minor>
          <build>650</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <metabase_test id="wmt-2" comment="SmartHTML interpreter is enabled" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <key>LM\W3SVC</key>
        <id datatype="int">6014</id>
      </object>
      <data operation="AND"/>
    </metabase_test>
    <registry_test id="wrt-31" comment="FrontPage Server Extensions 2000 are enabled (2K, XP)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\OC Manager\Subcomponents</key>
        <name>fp_extensions</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <registry_test id="wrt-88" comment="the patch q810217 is installed (Hotfix key)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB810217</key>
        <name>Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-12" comment="the version of shtml.dll is less than 4.00.02.7523" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir</component>
          <component type="literal">\Microsoft Shared\web server extensions\40\isapi\shtml.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>4</major>
          <minor>00</minor>
          <build>02</build>
          <private>7523</private>
        </version>
      </data>
    </file_test>
    <rpmversioncompare_test id="rvt-223" comment="kernel version is less than 2.4.20-19.9" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">kernel</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">2.4.20</tested_version>
        <tested_release operator="equals">19.9</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <file_test id="wft-57" comment="the version of sqlvdi.dll is less than 2000.80.765.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Microsoft SQL Server\80\SharedCode</component>
          <component type="literal">sqlvdi.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>2000</major>
          <minor>80</minor>
          <build>765</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-56" comment="the version of replrec.dll is less than 2000.80.765.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Microsoft SQL Server\80\SharedCode</component>
          <component type="literal">replrec.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>2000</major>
          <minor>80</minor>
          <build>765</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-55" comment="the version of msgprox.dll is less than 2000.80.765.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Microsoft SQL Server\80\SharedCode</component>
          <component type="literal">msgprox.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>2000</major>
          <minor>80</minor>
          <build>765</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-50" comment="the version of dbmslpcn.dll is less than 2000.80.818.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\dbmslpcn.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>2000</major>
          <minor>80</minor>
          <build>818</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-280" comment="File %windir%\system32\rpcrt4.dll version is less than 5.0.2195.6753" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\rpcrt4.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>2195</build>
          <private>6753</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-503" comment="Patch Q329414 Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q329414</key>
        <name>Installed</name>
      </object>
      <data operation="AND">
        <value>1</value>
      </data>
    </registry_test>
    <file_test id="wft-481" comment="the version of msadco.dll is less than 2.62.9119.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir</component>
          <component type="literal">\Common Files\System\msadc\msadco.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>2</major>
          <minor>62</minor>
          <build>9119</build>
          <private>1</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-101" comment="MDAC 2.6 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\DataAccess</key>
        <name>FullInstallVer</name>
      </object>
      <data operation="AND">
        <value operator="pattern match">^2\.6.*$</value>
      </data>
    </registry_test>
    <file_test id="wft-278" comment="the version of sqlservr.exe is less than 2000.80.650.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
          <component type="literal">\sqlservr.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>2000</major>
          <minor>80</minor>
          <build>650</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-318" comment="Patch wm308567 Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Updates\Windows Media Player\wm308567</key>
        <name>IsInstalled</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-143" comment="the version of msdxm.ocx is less than 6.4.9.1121" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\msdxm.ocx</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>4</minor>
          <build>9</build>
          <private>1121</private>
        </version>
      </data>
    </file_test>
    <rpmversioncompare_test id="rvt-222" comment="kernel version is less than 2.4.20-18.9" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">kernel</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">2.4.20</tested_version>
        <tested_release operator="equals">18.9</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <registry_test id="wrt-317" comment="Patch wm320920_8.exe Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Updates\Windows Media Player\wm320920</key>
        <name>IsInstalled</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-142" comment="the version of wmplayer.exe is less than 8.0.0.4482" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir</component>
          <component type="literal">\Windows Media Player\wmplayer.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>8</major>
          <minor>0</minor>
          <build>0</build>
          <private>4482</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-141" comment="the version of wmpcore.dll is less than 8.0.0.4482" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\wmpcore.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>8</major>
          <minor>0</minor>
          <build>0</build>
          <private>4482</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-140" comment="the version of msdxm.ocx is less than 6.4.9.1124" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\msdxm.ocx</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>4</minor>
          <build>9</build>
          <private>1124</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-277" comment="the version of dxmasf.dll is less than 6.4.9.1121" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\dxmasf.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>4</minor>
          <build>9</build>
          <private>1121</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-316" comment="Windows Media Player for Windows XP is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\MediaPlayer\8.0\Registration</key>
        <name>UDBVersion</name>
      </object>
      <data operation="AND">
        <value operator="equals">8.0.0.4477</value>
      </data>
    </registry_test>
    <registry_test id="wrt-315" comment="SMB Signing enabled" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SYSTEM\CurrentControlSet\Services\lanmanserver\parameters</key>
        <name>enablesecuritysignature</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <registry_test id="wrt-314" comment="Patch Q329170 Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q329170</key>
        <name>Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-276" comment="the version of srvsvc.dll is less than 5.0.2195.6110" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\srvsvc.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>2195</build>
          <private>6110</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-275" comment="File xpstar.dll version3 is less than 2000.80.561.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
          <component type="literal">\xpstar.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>2000</major>
          <minor>80</minor>
          <build>561</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-274" comment="File sqlservr.exe version3 is less than 2000.80.578.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
          <component type="literal">\sqlservr.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>2000</major>
          <minor>80</minor>
          <build>578</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-273" comment="the version of msgsvc.dll is less than 5.1.2600.1301" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\msgsvc.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>1301</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-296" comment="service pack 1 is installed and msgsvc.dll is less than 5.1.2600.1301" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-4"/>
      <subtest negate="false" test_ref="wft-273"/>
    </compound_test>
    <file_test id="wft-272" comment="the version of msgsvc.dll is less than 5.1.2600.120" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\msgsvc.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>120</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-119" comment="no service pack is installed and msgsvc.dll is less than 5.1.2600.120" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="true" test_ref="wrt-3"/>
      <subtest negate="false" test_ref="wft-272"/>
    </compound_test>
    <compound_test id="cmp-295" comment="a vulnerable version of msgsvc.dll exists" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-119"/>
      <subtest negate="false" test_ref="cmp-296"/>
    </compound_test>
    <file_test id="wft-21" comment="the version of wkssvc.dll is less than 5.1.2600.1301" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\wkssvc.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>1301</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-32" comment="service pack 1 is installed and wkssvc.dll is less than 5.1.2600.1301" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-4"/>
      <subtest negate="false" test_ref="wft-21"/>
    </compound_test>
    <file_test id="wft-20" comment="the version of wkssvc.dll is less than 5.1.2600.120" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\wkssvc.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>120</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-31" comment="no service pack is installed and wkssvc.dll is less than 5.1.2600.120" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="true" test_ref="wrt-3"/>
      <subtest negate="false" test_ref="wft-20"/>
    </compound_test>
    <compound_test id="cmp-30" comment="a vulnerable version of wkssvc.dll exists" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-31"/>
      <subtest negate="false" test_ref="cmp-32"/>
    </compound_test>
    <registry_test id="wrt-427" comment="the patch KB890859 is installed (Hotfix key)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB890859</key>
        <name operator="equals">Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-581" comment="The version of Ntoskrnl.exe is less than 5.1.2600.2622" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\System32\Ntoskrnl.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>2622</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-1058" comment="Windows XP 32-bit edition is installed" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-2"/>
      <subtest negate="false" test_ref="wrt-72"/>
    </compound_test>
    <compound_test id="cmp-35" comment="Windows XP 32 bit Service Pack 2" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-250"/>
      <subtest negate="false" test_ref="cmp-1058"/>
    </compound_test>
    <permission_test id="upt-56" comment="/usr/bin/gaim is executable by any user" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/gaim</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="boolean" operator="equals">1</gexec>
        <oexec datatype="boolean" operator="equals">1</oexec>
        <uexec datatype="boolean" operator="equals">1</uexec>
      </data>
    </permission_test>
    <rpmversioncompare_test id="rvt-21" comment="gaim RPM earlier than 1:1.3.1-0.el3" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name operator="equals">gaim</name>
        <tested_epoch operator="equals">1</tested_epoch>
        <tested_version operator="equals">1.3.1</tested_version>
        <tested_release operator="equals">0.el3</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <file_test id="wft-570" comment="the version of kernel32.dll is less than 5.0.2195.6011" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\kernel32.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>2195</build>
          <private>6011</private>
        </version>
      </data>
    </file_test>
    <rpmversioncompare_test id="rvt-221" comment="kernel version is less than 2.4.20-13.9" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">kernel</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">2.4.20</tested_version>
        <tested_release operator="equals">13.9</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <registry_test id="wrt-63" comment="the patch KB896422 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB896422</key>
        <name operator="equals">Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <registry_test id="wrt-22" comment="64-Bit (x64 architecture) version of Windows is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">SYSTEM\CurrentControlSet\Control\Session Manager\Environment</key>
        <name operator="equals">PROCESSOR_ARCHITECTURE</name>
      </object>
      <data operation="AND">
        <value operator="equals">x64</value>
      </data>
    </registry_test>
    <compound_test id="cmp-228" comment="for 64-bit (x64 arch) Windows (gold edition) a vulnerable version of srv.sys exists" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-22"/>
      <subtest negate="true" test_ref="wrt-3"/>
      <subtest negate="false" test_ref="wft-126"/>
    </compound_test>
    <file_test id="wft-126" comment="the version of srv.sys is less than 5.2.3790.2437" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\SYSTEM32\DRIVERS\srv.sys</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>2</minor>
          <build>3790</build>
          <private>2437</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-227" comment="for specific Windows configurations a vulnerable version of srv.sys exists " operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-4"/>
      <subtest negate="false" test_ref="cmp-23"/>
      <subtest negate="false" test_ref="wft-126"/>
    </compound_test>
    <file_test id="wft-125" comment="the version of srv.sys is less than 5.2.3790.324" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\SYSTEM32\DRIVERS\srv.sys</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>2</minor>
          <build>3790</build>
          <private>324</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-70" comment="64-Bit version of Windows is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SYSTEM\CurrentControlSet\Control\Session Manager\Environment</key>
        <name>PROCESSOR_ARCHITECTURE</name>
      </object>
      <data operation="AND">
        <value operator="equals">ia64</value>
      </data>
    </registry_test>
    <registry_test id="wrt-72" comment="32-Bit version of Windows is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SYSTEM\CurrentControlSet\Control\Session Manager\Environment</key>
        <name>PROCESSOR_ARCHITECTURE</name>
      </object>
      <data operation="AND">
        <value operator="equals">x86</value>
      </data>
    </registry_test>
    <compound_test id="cmp-23" comment="32-bit version of Windows or 64-bit (itanium architecture) version of Windows is installed" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-72"/>
      <subtest negate="false" test_ref="wrt-70"/>
    </compound_test>
    <compound_test id="cmp-226" comment="for specific Windows configurations a vulnerable version of srv.sys exists" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="true" test_ref="wrt-3"/>
      <subtest negate="false" test_ref="cmp-23"/>
      <subtest negate="false" test_ref="wft-125"/>
    </compound_test>
    <compound_test id="cmp-231" comment="a vulnerable version of srv.sys exists" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-226"/>
      <subtest negate="false" test_ref="cmp-227"/>
      <subtest negate="false" test_ref="cmp-228"/>
    </compound_test>
    <registry_test id="wrt-59" comment="PNG image rendering enabled in Internet Explorer" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">SOFTWARE\CLASSES</key>
        <name operator="equals">PNGFilter.CoPNGFilter</name>
      </object>
      <data operation="AND">
        <value operator="equals">CoPNGFilter Class</value>
      </data>
    </registry_test>
    <registry_test id="wrt-62" comment="the patch kb883939 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB883939</key>
        <name operator="equals">Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-115" comment="the version of mshtml.dll is less than 5.0.3541.2700" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mshtml.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>3541</build>
          <private>2700</private>
        </version>
      </data>
    </file_test>
    <uname_test id="uut-2" comment="kernel 2.4.20-6 or earlier is running" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <data operation="AND">
        <os_release datatype="string" operator="equals">2.4.20-6</os_release>
      </data>
    </uname_test>
    <rpminfo_test id="rrt-202" comment="kernel version = 2.4.20-6" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name operator="equals">kernel</name>
      </object>
      <data operation="AND">
        <epoch datatype="string" operator="equals">NULL</epoch>
        <release datatype="int" operator="equals">6</release>
        <version operator="equals">2.4.20</version>
      </data>
    </rpminfo_test>
    <registry_test id="wrt-312" comment="Patch Q305601 Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\Q305601</key>
        <name>Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <rpmversioncompare_test id="rvt-220" comment="krb5-workstation version is less than 1.2.7-14" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">krb5-workstation</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">1.2.7</tested_version>
        <tested_release datatype="int" operator="equals">14</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <compound_test id="cmp-289" comment="krb5-server or krb5-workstation installed" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="rvt-218"/>
      <subtest negate="false" test_ref="rvt-220"/>
    </compound_test>
    <rpmversioncompare_test id="rvt-219" comment="krb5-libs version is less than 1.2.7-14" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">krb5-libs</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">1.2.7</tested_version>
        <tested_release datatype="int" operator="equals">14</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <registry_test id="wrt-326" comment="the NNTP service is enabled" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SYSTEM\CurrentControlSet\Services\NntpSvc</key>
        <name>Start</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="not equal">4</value>
      </data>
    </registry_test>
    <registry_test id="wrt-548" comment="the patch WindowsServer2003-KB883935-ia64-enu.exe is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key datatype="string" operator="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB883935</key>
        <name datatype="string" operator="equals">Installed</name>
      </object>
      <data operation="AND">
        <value datatype="string" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-506" comment="the version of nntpsvc.dll is less than 6.0.3790.206" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\inetsrv\nntpsvc.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>3790</build>
          <private>206</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-61" comment="Windows Server 2003 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion</key>
        <name>CurrentVersion</name>
      </object>
      <data operation="AND">
        <value operator="equals">5.2</value>
      </data>
    </registry_test>
    <compound_test id="cmp-1153" comment="Exchange Server 2003 is installed on Windows Server 2003" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-61"/>
      <subtest negate="false" test_ref="wrt-113"/>
    </compound_test>
    <file_test id="wft-269" comment="the version of mshtml.dll is less than 5.50.4943.400" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mshtml.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>50</minor>
          <build>4943</build>
          <private>400</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-310" comment="the patch kb826232 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB826232</key>
        <name>Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-271" comment="the version of tshoot.ocx is less than 1.0.1.2125" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\tshoot.ocx</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>1</major>
          <minor>0</minor>
          <build>1</build>
          <private>2125</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-267" comment="the version of mshtml.dll is less than 6.0.2800.1458" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mshtml.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>2800</build>
          <private>1458</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-64" comment="File sqlvdi.dll version3 is less than 2000.80.765.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
          <component type="literal">\sqlvdi.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>2000</major>
          <minor>80</minor>
          <build>765</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-63" comment="File replrec.dll version3 is less than 2000.80.765.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
          <component type="literal">\replrec.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>2000</major>
          <minor>80</minor>
          <build>765</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-62" comment="the version of replprov.dll is less than 2000.80.798.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Microsoft SQL Server\80\SharedCode</component>
          <component type="literal">replprov.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>2000</major>
          <minor>80</minor>
          <build>798</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-61" comment="File msgprox.dll version3 is less than 2000.80.765.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
          <component type="literal">\msgprox.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>2000</major>
          <minor>80</minor>
          <build>765</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-60" comment="the version of xpweb70.dll is less than 2000.80.778.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
          <component type="literal">\xpweb70.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>2000</major>
          <minor>80</minor>
          <build>778</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-79" comment="the version of odsole70.dll is less than 2000.80.800.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
          <component type="literal">\odsole70.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>2000</major>
          <minor>80</minor>
          <build>800</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-78" comment="the version of ums.dll is less than 2000.80.816.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
          <component type="literal">\ums.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>2000</major>
          <minor>80</minor>
          <build>816</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-54" comment="the version of ssnmpn70.dll is less than 2000.80.818.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
          <component type="literal">\ssnmpn70.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>2000</major>
          <minor>80</minor>
          <build>818</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-53" comment="the version of ssnetlib.dll is less than 2000.80.818.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
          <component type="literal">\ssnetlib.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>2000</major>
          <minor>80</minor>
          <build>818</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-52" comment="the version of ssmslpcn.dll is less than 2000.80.818.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
          <component type="literal">\ssmslpcn.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>2000</major>
          <minor>80</minor>
          <build>818</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-51" comment="the version of sqlservr.exe is less than 2000.80.818.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
          <component type="literal">\sqlservr.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>2000</major>
          <minor>80</minor>
          <build>818</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-73" comment="File sqlrepss.dll version3 is less than 2000.80.765.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
          <component type="literal">\sqlrepss.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>2000</major>
          <minor>80</minor>
          <build>765</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-72" comment="File sqlmap70.dll version3 is less than 2000.80.811.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
          <component type="literal">\sqlmap70.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>2000</major>
          <minor>80</minor>
          <build>811</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-71" comment="File dbmslpcn.dll version3 is less than 2000.80.818.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\dbmslpcn.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>2000</major>
          <minor>80</minor>
          <build>818</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-70" comment="File console.exe version3 is less than 2000.80.818.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
          <component type="literal">\console.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>2000</major>
          <minor>80</minor>
          <build>818</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-88" comment="File xpstar.dll Version3 is less than 2000.80.223.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
          <component type="literal">\xpstar.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>2000</major>
          <minor>80</minor>
          <build>223</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-87" comment="File xprepl.dll Version3 is less than 2000.80.223.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
          <component type="literal">\xprepl.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>2000</major>
          <minor>80</minor>
          <build>223</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-86" comment="File xpqueue.dll Version3 is less than 2000.80.223.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
          <component type="literal">\xpqueue.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>2000</major>
          <minor>80</minor>
          <build>223</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-85" comment="File odsole70.dll Version3 is less than 2000.80.223.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
          <component type="literal">\odsole70.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>2000</major>
          <minor>80</minor>
          <build>223</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <rpmversioncompare_test id="rvt-218" comment="krb5-server version is less than 1.2.7-14" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">krb5-server</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">1.2.7</tested_version>
        <tested_release datatype="int" operator="equals">14</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <file_test id="wft-262" comment="the version of mshtml.dll is less than 5.50.4922.900" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mshtml.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>50</minor>
          <build>4922</build>
          <private>900</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-571" comment="Patch Q19696 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q19696</key>
        <name>Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-569" comment="the version of quartz.dll is less than 6.1.5.132" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\quartz.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>1</minor>
          <build>5</build>
          <private>132</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-309" comment="HCP Protocol" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_CLASSES_ROOT</hive>
        <key>HCP</key>
        <name operator="pattern match">.*</name>
      </object>
    </registry_test>
    <registry_test id="wrt-539" comment="Win2K/XP/2003 service pack 5 (or later) is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion</key>
        <name>CSDVersion</name>
      </object>
      <data operation="AND">
        <value operator="pattern match">^Service Pack [5-9]|\d{2,}$</value>
      </data>
    </registry_test>
    <compound_test id="cmp-1106" comment="Windows 2000 (sp4 or earlier) is installed" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-1"/>
      <subtest negate="true" test_ref="wrt-539"/>
    </compound_test>
    <registry_test id="wrt-308" comment="Patch KB825119 Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB825119</key>
        <name>Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-261" comment="the version of itircl.dll is less than 5.2.3790.80" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\itircl.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>2</minor>
          <build>3790</build>
          <private>80</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-279" comment="the version of mshtml.dll is less than 5.0.3819.300" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mshtml.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>3819</build>
          <private>300</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-54" comment="Internet Explorer 5.01 Service Pack 4 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Internet Explorer</key>
        <name>Version</name>
      </object>
      <data operation="AND">
        <value operator="equals">5.00.3700.1000</value>
      </data>
    </registry_test>
    <registry_test id="wrt-307" comment="the messenger service is enabled" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SYSTEM\CurrentControlSet\Services\Messenger</key>
        <name>Start</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="not equal">4</value>
      </data>
    </registry_test>
    <registry_test id="wrt-83" comment="the patch q828035 is installed (Hotfix key)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB828035</key>
        <name>Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-260" comment="the version of wkssvc.dll is less than 5.0.2195.6861" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\wkssvc.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>2195</build>
          <private>6861</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-122" comment="the version of msgsvc.dll is less than 5.0.2195.6861" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\msgsvc.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>2195</build>
          <private>6861</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-99" comment="local machine settings are being used and ActiveX controls and active scripting are enabled" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-30"/>
      <subtest negate="false" test_ref="wrt-120"/>
      <subtest negate="false" test_ref="wrt-125"/>
    </compound_test>
    <compound_test id="cmp-98" comment="current user settings are being used and ActiveX controls and active scripting are enabled" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="true" test_ref="wrt-30"/>
      <subtest negate="false" test_ref="wrt-121"/>
      <subtest negate="false" test_ref="wrt-126"/>
    </compound_test>
    <compound_test id="cmp-97" comment="ActiveX controls and active scripting are enabled" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-98"/>
      <subtest negate="false" test_ref="cmp-99"/>
    </compound_test>
    <registry_test id="wrt-237" comment="the patch kb867801 is installed (Hotfix key)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB867801</key>
        <name>Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-266" comment="the version of mshtml.dll is less than 6.0.3790.191" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mshtml.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>3790</build>
          <private>191</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-51" comment="Internet Explorer 6  for Windows Server 2003 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">SOFTWARE\Microsoft\Internet Explorer</key>
        <name operator="equals">Version</name>
      </object>
      <data operation="AND">
        <value operator="equals">6.00.3790.0000</value>
      </data>
    </registry_test>
    <registry_test id="wrt-245" comment="the patch kb832894 is installed (Installed Components key)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Active Setup\Installed Components\{2298d453-bcae-4519-bf33-1cbf3faf1524}</key>
        <name>IsInstalled</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-270" comment="the version of mshtml.dll is less than 5.0.3532.300" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mshtml.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>3532</build>
          <private>300</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-486" comment="the version of winword.exe is less than 9.0.0.6328" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Winword.exe\Path</component>
          <component type="literal">winword.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>9</major>
          <minor>0</minor>
          <build>0</build>
          <private>6328</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-478" comment="the version of winword.exe is less than 9.0.0.6926" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Winword.exe\Path</component>
          <component type="literal">winword.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>9</major>
          <minor>0</minor>
          <build>0</build>
          <private>6926</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-305" comment="the utility manager Service is enabled" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SYSTEM\CurrentControlSet\Services\UtilMan</key>
        <name>Start</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="not equal">4</value>
      </data>
    </registry_test>
    <registry_test id="wrt-68" comment="the patch kb891711 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB891711</key>
        <name operator="equals">Installed</name>
      </object>
      <data operation="AND">
        <value operator="equals">1</value>
      </data>
    </registry_test>
    <registry_test id="wrt-304" comment="the patch kb824141 is installed (Hotfix key)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB824141</key>
        <name>Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-259" comment="the version of user32.dll is less than 5.1.2600.1255" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\user32.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>1255</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-283" comment="service pack 1 is installed and user32.dll is less than 5.1.2600.1255" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-4"/>
      <subtest negate="false" test_ref="wft-259"/>
    </compound_test>
    <file_test id="wft-258" comment="the version of user32.dll is less than 5.1.2600.118" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\user32.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>2600</build>
          <private>118</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-117" comment="no service pack is installed and user32.dll is less than 5.1.2600.118" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="true" test_ref="wrt-3"/>
      <subtest negate="false" test_ref="wft-258"/>
    </compound_test>
    <compound_test id="cmp-282" comment="a vulnerable version of user32.dll exists" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-117"/>
      <subtest negate="false" test_ref="cmp-283"/>
    </compound_test>
    <registry_test id="wrt-125" comment="active scripting is enabled for the local machine" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key operator="pattern match">^SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\[0-4]$</key>
        <name>1400</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="not equal">3</value>
      </data>
    </registry_test>
    <compound_test id="cmp-95" comment="local machine settings are being used and active scripting is enabled" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-30"/>
      <subtest negate="false" test_ref="wrt-125"/>
    </compound_test>
    <registry_test id="wrt-126" comment="active scripting is enabled for the current user" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_CURRENT_USER</hive>
        <key operator="pattern match">^SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\[0-4]$</key>
        <name>1400</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="not equal">3</value>
      </data>
    </registry_test>
    <compound_test id="cmp-94" comment="current user settings are being used and active scripting is enabled" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="true" test_ref="wrt-30"/>
      <subtest negate="false" test_ref="wrt-126"/>
    </compound_test>
    <compound_test id="cmp-76" comment="active scripting is enabled" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-94"/>
      <subtest negate="false" test_ref="cmp-95"/>
    </compound_test>
    <registry_test id="wrt-302" comment="RDP Enabled" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SYSTEM\CurrentControlSet\Services\RDPWD</key>
        <name>Start</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="not equal">4</value>
      </data>
    </registry_test>
    <registry_test id="wrt-301" comment="Patch Q324380 installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q324380</key>
        <name>Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-256" comment="File %windir%\system32\drivers\rdpwd.sys version is less than 5.0.2195.5880" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\drivers\rdpwd.sys</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>2195</build>
          <private>5880</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-300" comment="Terminal Server Version" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SYSTEM\CurrentControlSet\Control\Terminal Server</key>
        <name>ProductVersion</name>
      </object>
      <data operation="AND">
        <value operator="equals">5.0</value>
      </data>
    </registry_test>
    <file_test id="wft-255" comment="File %windir%\system32\cryptui.dll version is less than 5.131.2195.6758" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\cryptui.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>131</minor>
          <build>2195</build>
          <private>6758</private>
        </version>
      </data>
    </file_test>
    <metabase_test id="wmt-205" comment="idq.dll mapping exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <key datatype="string" operator="equals">LM\W3SVC</key>
        <id datatype="int" operator="equals">6014</id>
      </object>
      <data operation="AND">
        <data operator="pattern match">^.*idq\.dll.*$</data>
      </data>
    </metabase_test>
    <registry_test id="wrt-299" comment="Patch Q300972 Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q300972</key>
        <name>Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-254" comment="File %windir%\system32\idq.dll version is less than 5.0.2195.3645" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\idq.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>2195</build>
          <private>3645</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-567" comment="the version of rpcss.dll is less than 4.0.1381.7224" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\rpcss.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>4</major>
          <minor>0</minor>
          <build>1381</build>
          <private>7224</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-570" comment="Patch Q823980 Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q823980</key>
        <name>Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <permission_test id="upt-79" comment="/usr/bin/kdm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/kdm</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-78" comment="/usr/bin/kdm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/kdm</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-77" comment="/usr/bin/kdm is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/kdm</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-278" comment="/usr/bin/kdm is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-77"/>
      <subtest negate="false" test_ref="upt-78"/>
      <subtest negate="false" test_ref="upt-79"/>
    </compound_test>
    <rpmversioncompare_test id="rvt-217" comment="kdebase version is less than 3.1-15" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">kdebase</name>
        <tested_epoch datatype="int" operator="equals">6</tested_epoch>
        <tested_version operator="equals">3.1</tested_version>
        <tested_release datatype="int" operator="equals">15</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <patch_test id="spt-230" comment="Patch 110286-10 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">110286</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">10</version>
      </data>
    </patch_test>
    <file_test id="wft-253" comment="File %windir%\system32\inetsrv\w3svc.dll version is less than 5.0.2195.2784" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\inetsrv\w3svc.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>2195</build>
          <private>2784</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-298" comment="ActiveX Enabled In At Least One Zone" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key operator="pattern match">^SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\[0-4]$</key>
        <name datatype="int">1200</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">0</value>
      </data>
    </registry_test>
    <compound_test id="cmp-276" comment="ActiveX Enabled" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-30"/>
      <subtest negate="false" test_ref="wrt-298"/>
    </compound_test>
    <registry_test id="wrt-297" comment="Patch Q323172 Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q323172</key>
        <name>Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-252" comment="the version of xenroll.dll is less than 5.131.3659.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\xenroll.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>131</minor>
          <build>3659</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-296" comment="Lanman enabled" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SYSTEM\CurrentControlSet\Services\lanmanserver</key>
        <name>Start</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="not equal">2</value>
      </data>
    </registry_test>
    <registry_test id="wrt-295" comment="Patch Q326830 Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q326830</key>
        <name>Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-251" comment="the version of xactsrv.dll is less than 5.0.2195.5971" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\xactsrv.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>2195</build>
          <private>5971</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-470" comment="the version of winword.exe is less than 9.0.0.7924" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Winword.exe\Path</component>
          <component type="literal">winword.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>9</major>
          <minor>0</minor>
          <build>0</build>
          <private>7924</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-132" comment="Word 2000 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Office\9.0\Word\InstallRoot</key>
        <name operator="pattern match">.*</name>
      </object>
    </registry_test>
    <registry_test id="wrt-29" comment="Win2K/XP/2003 service pack 2 (or later) is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion</key>
        <name>CSDVersion</name>
      </object>
      <data operation="AND">
        <value operator="pattern match">^Service Pack [2-9]|\d{2,}$</value>
      </data>
    </registry_test>
    <registry_test id="wrt-2" comment="Windows XP is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion</key>
        <name>CurrentVersion</name>
      </object>
      <data operation="AND">
        <value operator="equals">5.1</value>
      </data>
    </registry_test>
    <compound_test id="cmp-66" comment="Windows XP (sp1 or earlier) is installed" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-2"/>
      <subtest negate="true" test_ref="wrt-29"/>
    </compound_test>
    <registry_test id="wrt-190" comment="downloading of signed ActiveX controls is enabled for the current user" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_CURRENT_USER</hive>
        <key operator="pattern match">^SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\[0-4]$</key>
        <name>1001</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="not equal">3</value>
      </data>
    </registry_test>
    <compound_test id="cmp-107" comment="local machine settings are being used and the downloading of signed ActiveX controls is enabled" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-30"/>
      <subtest negate="false" test_ref="wrt-190"/>
    </compound_test>
    <registry_test id="wrt-294" comment="downloading of signed ActiveX controls is enabled for the local machine" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="pattern match">^SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\[0-4]$</key>
        <name>1001</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="not equal">3</value>
      </data>
    </registry_test>
    <compound_test id="cmp-106" comment="current user settings are being used and the downloading of signed ActiveX controls is enabled" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="true" test_ref="wrt-30"/>
      <subtest negate="false" test_ref="wrt-294"/>
    </compound_test>
    <compound_test id="cmp-275" comment="downloading of signed ActiveX controls is enabled" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-106"/>
      <subtest negate="false" test_ref="cmp-107"/>
    </compound_test>
    <registry_test id="wrt-293" comment="Patch WindowsXP-KB823182-x86-ENU Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB823182</key>
        <name>Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-250" comment="the version of cryptui.dll is less than 5.131.2600.1243" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\cryptui.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>131</minor>
          <build>2600</build>
          <private>1243</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-4" comment="Win2K/XP/2003 service pack 1 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion</key>
        <name>CSDVersion</name>
      </object>
      <data operation="AND">
        <value operator="equals">Service Pack 1</value>
      </data>
    </registry_test>
    <compound_test id="cmp-274" comment="service pack 1 is installed and cryptui.dll is less than 5.131.2600.1243" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-4"/>
      <subtest negate="false" test_ref="wft-250"/>
    </compound_test>
    <file_test id="wft-249" comment="the version of cryptui.dll is less than 5.131.2600.117" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\cryptui.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>131</minor>
          <build>2600</build>
          <private>117</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-3" comment="a Win2K/XP/2003 service pack is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion</key>
        <name>CSDVersion</name>
      </object>
    </registry_test>
    <compound_test id="cmp-115" comment="no service pack is installed and cryptui.dll is less than 5.131.2600.117" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="true" test_ref="wrt-3"/>
      <subtest negate="false" test_ref="wft-249"/>
    </compound_test>
    <compound_test id="cmp-273" comment="a vulnerable version of cryptui.dll exists" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-115"/>
      <subtest negate="false" test_ref="cmp-274"/>
    </compound_test>
    <registry_test id="wrt-289" comment="Patch Q321599 Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q321599</key>
        <name>Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-248" comment="File %windir%\system32\inetsrv\ism.dll version is less than 4.2.776.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\inetsrv\ism.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>4</major>
          <minor>2</minor>
          <build>776</build>
          <private>1</private>
        </version>
      </data>
    </file_test>
    <patch_test id="spt-229" comment="Patch 107654-10 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">107654</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">10</version>
      </data>
    </patch_test>
    <file_test id="wft-247" comment="the version of mshtml.dll is less than 5.50.4923.2500" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mshtml.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>50</minor>
          <build>4923</build>
          <private>2500</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-271" comment="Internet Explorer 5.5 Installed" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-225"/>
      <subtest negate="false" test_ref="wrt-226"/>
      <subtest negate="false" test_ref="wrt-227"/>
      <subtest negate="false" test_ref="wrt-53"/>
    </compound_test>
    <patch_test id="spt-228" comment="Patch 107893-20 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">107893</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">20</version>
      </data>
    </patch_test>
    <inetlisteningservers_test id="rlt-203" comment="httpd.worker is listening on the network" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <program_name datatype="string" operator="pattern match">^.*httpd\.worker.*</program_name>
      </object>
    </inetlisteningservers_test>
    <rpmversioncompare_test id="rvt-216" comment="httpd version is less than 2.0.40-21.5" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">httpd</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">2.0.40</tested_version>
        <tested_release operator="equals">21.5</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <registry_test id="wrt-58" comment="Patch KB897715 Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key datatype="string" operator="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB897715</key>
        <name datatype="string" operator="equals">Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-83" comment="the version of inetcomm.dll is less than 6.0.3790.326" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\inetcomm.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>3790</build>
          <private>326</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-172" comment="Outlook Express 6 for Windows 2003 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Outlook Express\Version Info</key>
        <name>Current</name>
      </object>
      <data operation="AND">
        <value operator="equals">6,0,3790,0</value>
      </data>
    </registry_test>
    <permission_test id="upt-1" comment="/tmp is writable by everyone" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/tmp</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="boolean" operator="equals">1</oexec>
      </data>
    </permission_test>
    <rpmversioncompare_test id="rvt-1" comment="openssl096b package is older than 0.9.6b-16.22.3.i386.rpm" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name operator="equals">openssl096b</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">0.9.6b</tested_version>
        <tested_release operator="equals">16.22.3</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <rpmversioncompare_test id="rvt-5" comment="openssl older than 0.9.7a-33.15" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name operator="equals">openssl</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">0.9.7a</tested_version>
        <tested_release operator="equals">33.15</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <rpmversioncompare_test id="rvt-4" comment="openssl-devel older than 0.9.7a-33.15" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name operator="equals">openssl-devel</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">0.9.7a</tested_version>
        <tested_release operator="equals">33.15</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <rpmversioncompare_test id="rvt-3" comment="openssl-perl is older than 0.9.7a-33.15" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name operator="equals">openssl-perl</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">0.9.7a</tested_version>
        <tested_release operator="equals">33.15</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <compound_test id="cmp-22" comment="openssl, openssl-devel, OR openssl-perl older than 0.9.7a-33.15 or openssl096b older than 0.9.6b-16.22.3" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="rvt-3"/>
      <subtest negate="false" test_ref="rvt-4"/>
      <subtest negate="false" test_ref="rvt-5"/>
      <subtest negate="false" test_ref="rvt-1"/>
    </compound_test>
    <rpminfo_test id="rrt-206" comment="Red Hat Enterprise 3 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name operator="equals">redhat-release</name>
      </object>
      <data operation="AND">
        <version operator="pattern match">^3.S</version>
      </data>
    </rpminfo_test>
    <file_test id="wft-246" comment="the version of netlogon.dll is less than 4.0.1381.7092" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\netlogon.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>4</major>
          <minor>0</minor>
          <build>1381</build>
          <private>7092</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-245" comment="the version of smss.exe is less than 4.0.1381.7152" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\smss.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>4</major>
          <minor>0</minor>
          <build>1381</build>
          <private>7152</private>
        </version>
      </data>
    </file_test>
    <patch_test id="spt-227" comment="Patch 108117-06 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">108117</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">6</version>
      </data>
    </patch_test>
    <inetlisteningservers_test id="rlt-202" comment="httpd listening on the network" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <program_name datatype="string" operator="pattern match">^.*httpd.*</program_name>
      </object>
    </inetlisteningservers_test>
    <rpmversioncompare_test id="rvt-215" comment="httpd version is less than 2.0.40-21.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">httpd</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">2.0.40</tested_version>
        <tested_release operator="equals">21.1</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <permission_test id="upt-857" comment="File xfs executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/openwin/bin/xfs</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-856" comment="File xfs executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/openwin/bin/xfs</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-855" comment="File xfs executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/openwin/bin/xfs</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-267" comment="File xfs executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-855"/>
      <subtest negate="false" test_ref="upt-856"/>
      <subtest negate="false" test_ref="upt-857"/>
    </compound_test>
    <inetd_test id="sit-207" comment="inetd.conf contains fs.auto" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <server_program operator="equals">/usr/openwin/lib/fs.auto</server_program>
      </object>
    </inetd_test>
    <patch_test id="spt-226" comment="Patch 109862-03 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">109862</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">3</version>
      </data>
    </patch_test>
    <file_test id="uft-22" comment="File xfs exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/openwin/bin/xfs</component>
        </path>
      </object>
    </file_test>
    <file_test id="uft-21" comment="File fs.auto exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/openwin/lib/fs.auto</component>
        </path>
      </object>
    </file_test>
    <permission_test id="upt-76" comment="/usr/bin/evolution is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/evolution</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-75" comment="/usr/bin/evolution is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/evolution</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-74" comment="/usr/bin/evolution is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/evolution</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-266" comment="/usr/bin/evolution is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-74"/>
      <subtest negate="false" test_ref="upt-75"/>
      <subtest negate="false" test_ref="upt-76"/>
    </compound_test>
    <rpmversioncompare_test id="rvt-214" comment="gtkhtml version is less than 1.1.9-0.9.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">gtkhtml</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">1.1.9</tested_version>
        <tested_release operator="equals">0.9.1</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <file_test id="wft-244" comment="the version of shell32.dll is less than 5.0.3502.4718" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\shell32.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>3502</build>
          <private>4718</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-566" comment="The version of srv.sys is less than 4.0.1381.7214" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\Drivers\SRV.SYS</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>4</major>
          <minor>0</minor>
          <build>1381</build>
          <private>7214</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-569" comment="Patch Q817606 Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q817606</key>
        <name>Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <registry_test id="wrt-287" comment="Patch Q312895 Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q312895</key>
        <name>Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-243" comment="the version of mup.sys is less than 4.0.1381.7125" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\drivers\mup.sys</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>4</major>
          <minor>0</minor>
          <build>1381</build>
          <private>7125</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-242" comment="the version of snmp.exe is less than 5.0.2195.4919" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\snmp.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>2195</build>
          <private>4919</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-241" comment="the version of mshtml.dll is less than 6.0.2722.900" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mshtml.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>2722</build>
          <private>900</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-478" comment="the patch Q811493 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q811493</key>
        <name>Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-436" comment="The version of Ntoskrnl.exe is less than 4.0.1381.7203" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\System32\Ntoskrnl.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>4</major>
          <minor>0</minor>
          <build>1381</build>
          <private>7203</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-536" comment="Windows NT Service Pack 6a is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q246009</key>
        <name>Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <registry_test id="wrt-191" comment="file downloads are enabled for the current user" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_CURRENT_USER</hive>
        <key operator="pattern match">^SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\[0-4]$</key>
        <name>1803</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="not equal">3</value>
      </data>
    </registry_test>
    <compound_test id="cmp-109" comment="local machine settings are being used and file downloads are enabled" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-30"/>
      <subtest negate="false" test_ref="wrt-191"/>
    </compound_test>
    <registry_test id="wrt-286" comment="file downloads are enabled for the local machine" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="pattern match">^SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\[0-4]$</key>
        <name>1803</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="not equal">3</value>
      </data>
    </registry_test>
    <compound_test id="cmp-108" comment="current user settings are being used and file downloads are enabled" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="true" test_ref="wrt-30"/>
      <subtest negate="false" test_ref="wrt-286"/>
    </compound_test>
    <compound_test id="cmp-265" comment="file downloads are enabled" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-108"/>
      <subtest negate="false" test_ref="cmp-109"/>
    </compound_test>
    <registry_test id="wrt-285" comment="the patch q295106 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Active Setup\Installed Components\{754D29C1-0C97-405F-98D0-21B212CA7FF1}</key>
        <name>IsInstalled</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <registry_test id="wrt-284" comment="the patch q290108 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Active Setup\Installed Components\{90A2A715-D986-4EAB-8C73-4D06114EF760}</key>
        <name>IsInstalled</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-240" comment="File %windir%\system32\shdocvw.dll version is less than 5.0.3214.2000" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\shdocvw.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>3214</build>
          <private>2000</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-264" comment="Internet Explorer 5.01 Installed" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-230"/>
      <subtest negate="false" test_ref="wrt-231"/>
      <subtest negate="false" test_ref="wrt-232"/>
      <subtest negate="false" test_ref="wrt-233"/>
      <subtest negate="false" test_ref="wrt-234"/>
      <subtest negate="false" test_ref="wrt-235"/>
    </compound_test>
    <registry_test id="wrt-455" comment="MTS Enabled" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Transaction Server\Packages</key>
        <name>Start</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="not equal">4</value>
      </data>
    </registry_test>
    <registry_test id="wrt-454" comment="Patch Q265714 Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q265714</key>
        <name>Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-415" comment="File %windir%\system32\tcpcfg.dll version is less than 4.0.1381.7097" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\tcpcfg.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>4</major>
          <minor>0</minor>
          <build>1381</build>
          <private>7097</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-1012" comment="For Terminal Server" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-43"/>
      <subtest negate="false" test_ref="wft-415"/>
    </compound_test>
    <file_test id="wft-414" comment="File %windir%\system32\tcpcfg.dll version is less than 4.0.1381.7064" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\tcpcfg.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>4</major>
          <minor>0</minor>
          <build>1381</build>
          <private>7064</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-1011" comment="For Windows NT 4.0 Workstation, Server and Enterprise Edition" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wft-414"/>
      <subtest negate="true" test_ref="wrt-243"/>
    </compound_test>
    <rpmversioncompare_test id="rvt-213" comment="gtkhtml version is less than 1.1.9-0.9" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">gtkhtml</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">1.1.9</tested_version>
        <tested_release operator="equals">0.9</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <file_test id="wft-301" comment="the version of msjava.dll is less than 5.0.3810.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\msjava.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>3810</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <permission_test id="upt-73" comment="/usr/bin/gnupg is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/gnupg</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-72" comment="/usr/bin/gnupg is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/gnupg</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-263" comment="/usr/bin/gnupg is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-72"/>
      <subtest negate="false" test_ref="upt-73"/>
    </compound_test>
    <rpmversioncompare_test id="rvt-212" comment="gnupg version is less than 1.2.1-4" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">gnupg</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">1.2.1</tested_version>
        <tested_release datatype="int" operator="equals">4</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <registry_test id="wrt-501" comment="the patch js56nen.exe (5.5.0.8513 version) is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Active Setup\Installed Components\{4f645220-306d-11d2-995d-00c04f98bbc9}</key>
        <name>Version</name>
      </object>
      <data operation="AND">
        <value>5,5,0,8513</value>
      </data>
    </registry_test>
    <registry_test id="wrt-500" comment="the patch js56nen.exe (5.1.0.8513 version) is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Active Setup\Installed Components\{4f645220-306d-11d2-995d-00c04f98bbc9}</key>
        <name>Version</name>
      </object>
      <data operation="AND">
        <value>5,1,0,8513</value>
      </data>
    </registry_test>
    <registry_test id="wrt-499" comment="the patch js56nen.exe (5.6.0.8513 version) is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Active Setup\Installed Components\{4f645220-306d-11d2-995d-00c04f98bbc9}</key>
        <name>Version</name>
      </object>
      <data operation="AND">
        <value>5,6,0,8513</value>
      </data>
    </registry_test>
    <compound_test id="cmp-1156" comment="The patch js56nen.exe is installed for version 5.1, 5.5, or 5.6" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-499"/>
      <subtest negate="false" test_ref="wrt-500"/>
      <subtest negate="false" test_ref="wrt-501"/>
    </compound_test>
    <file_test id="wft-257" comment="the version of jscript.dll is less than 5.6.0.8513" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\jscript.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>6</minor>
          <build>0</build>
          <private>8513</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-121" comment="the version of jscript.dll is less than 5.5.0.8513" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\jscript.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>5</minor>
          <build>0</build>
          <private>8513</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-120" comment="the version of jscript.dll is less than 5.1.0.8513" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\jscript.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>1</minor>
          <build>0</build>
          <private>8513</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-1157" comment="jscript.dll version is 5.1, 5.5, or 5.6 " operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wft-120"/>
      <subtest negate="false" test_ref="wft-121"/>
      <subtest negate="false" test_ref="wft-257"/>
    </compound_test>
    <permission_test id="upt-71" comment="/usr/bin/gs is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/gs</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-70" comment="/usr/bin/gs is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/gs</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-69" comment="/usr/bin/gs is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/gs</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-262" comment="/usr/bin/gs is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-69"/>
      <subtest negate="false" test_ref="upt-70"/>
      <subtest negate="false" test_ref="upt-71"/>
    </compound_test>
    <rpmversioncompare_test id="rvt-211" comment="ghostscript version is less than 7.05-32.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">ghostscript</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">7.05</tested_version>
        <tested_release operator="equals">32.1</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <patch_test id="spt-225" comment="Patch 108376-30 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">108376</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">30</version>
      </data>
    </patch_test>
    <registry_test id="wrt-283" comment="DCOM is enabled" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Ole</key>
        <name>EnableDCOM</name>
      </object>
      <data operation="AND">
        <value operator="equals">Y</value>
      </data>
    </registry_test>
    <compound_test id="cmp-7" comment="DCOM is enabled on systems with SP3 or later" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-224"/>
      <subtest negate="false" test_ref="wrt-283"/>
    </compound_test>
    <file_test id="wft-239" comment="the version of rpcrt4.dll is less than 5.0.2195.6802" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\rpcrt4.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>2195</build>
          <private>6802</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-280" comment=".hta applications are enabled" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Classes\MIME\Database\Content Type\application/hta</key>
        <name>Extension</name>
      </object>
      <data operation="AND">
        <value operator="equals">.hta</value>
      </data>
    </registry_test>
    <registry_test id="wrt-120" comment="ActiveX controls are enabled for the local machine" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key operator="pattern match">^SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\[0-4]$</key>
        <name>1200</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="not equal">3</value>
      </data>
    </registry_test>
    <compound_test id="cmp-93" comment="local machine settings are being used and ActiveX controls are enabled" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-30"/>
      <subtest negate="false" test_ref="wrt-120"/>
    </compound_test>
    <registry_test id="wrt-121" comment="ActiveX controls are enabled for the current user" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_CURRENT_USER</hive>
        <key operator="pattern match">^SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\[0-4]$</key>
        <name>1200</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="not equal">3</value>
      </data>
    </registry_test>
    <compound_test id="cmp-92" comment="current user settings are being used and ActiveX controls are enabled" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="true" test_ref="wrt-30"/>
      <subtest negate="false" test_ref="wrt-121"/>
    </compound_test>
    <compound_test id="cmp-75" comment="ActiveX controls are enabled" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-92"/>
      <subtest negate="false" test_ref="cmp-93"/>
    </compound_test>
    <file_test id="wft-238" comment="the version of mshtml.dll is less than 6.0.2800.1264" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mshtml.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>2800</build>
          <private>1264</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-50" comment="Internet Explorer 6 Service Pack 1 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Internet Explorer</key>
        <name>Version</name>
      </object>
      <data operation="AND">
        <value operator="equals">6.00.2800.1106</value>
      </data>
    </registry_test>
    <compound_test id="cmp-256" comment="Internet Explorer 6.0 or IE 6.0 SP1 is installed" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-18"/>
      <subtest negate="false" test_ref="wrt-50"/>
    </compound_test>
    <file_test id="wft-69" comment="the version of xpstar.dll is less than 2000.80.628.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
          <component type="literal">\xpstar.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>2000</major>
          <minor>80</minor>
          <build>628</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-68" comment="the version of xpweb70.dll is less than 2000.80.606.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
          <component type="literal">\xpweb70.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>2000</major>
          <minor>80</minor>
          <build>606</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-67" comment="the version of xplog70.dll is less than 2000.80.606.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
          <component type="literal">\xplog70.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>2000</major>
          <minor>80</minor>
          <build>606</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-66" comment="the version of xprepl.dll is less than 2000.80.606.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
          <component type="literal">\xprepl.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>2000</major>
          <minor>80</minor>
          <build>606</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-65" comment="the version of xpqueue.dll is less than 2000.80.606.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
          <component type="literal">\xpqueue.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>2000</major>
          <minor>80</minor>
          <build>606</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-237" comment="the version of odsole70.dll is less than 2000.80.606.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
          <component type="literal">\odsole70.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>2000</major>
          <minor>80</minor>
          <build>606</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-236" comment="the version of sqlservr.exe is less than 2000.80.608.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
          <component type="literal">\sqlservr.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>2000</major>
          <minor>80</minor>
          <build>608</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <permission_test id="upt-854" comment="File kcms_server executable and SUID or SGID" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/openwin/bin/kcms_server</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-853" comment="File kcms_server executable and SUID or SGID" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/openwin/bin/kcms_server</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-852" comment="File kcms_server executable and SUID or SGID" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/openwin/bin/kcms_server</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-255" comment="File kcms_server executable and SUID or SGID" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-852"/>
      <subtest negate="false" test_ref="upt-853"/>
      <subtest negate="false" test_ref="upt-854"/>
    </compound_test>
    <inetd_test id="sit-206" comment="inetd.conf contains kcms_server" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <server_program operator="equals">/usr/openwin/bin/kcms_server</server_program>
      </object>
    </inetd_test>
    <file_test id="uft-20" comment="File kcms_server exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/openwin/bin/kcms_server</component>
        </path>
      </object>
    </file_test>
    <registry_test id="wrt-277" comment="Patch Windows2000-KB817606-x86-ENU.exe Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB817606</key>
        <name>Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-235" comment="File %windir%\system32\Drivers\SRV.SYS is less than 5.0.2195.6699" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\Drivers\SRV.SYS</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>2195</build>
          <private>6699</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-276" comment="ISA2000-KB816456-x86.exe" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Fpc\Hotfixes\SP1\277</key>
        <name>Kbs</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">816456</value>
      </data>
    </registry_test>
    <registry_test id="wrt-105" comment="ISA Server 2000 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Microsoft ISA Server</key>
        <name>VersionMajor</name>
      </object>
      <data operation="AND">
        <value operator="equals">3</value>
      </data>
    </registry_test>
    <rpmversioncompare_test id="rvt-210" comment="gdm version is less than 2.4.1.3-5.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">gdm</name>
        <tested_epoch datatype="int" operator="equals">1</tested_epoch>
        <tested_version operator="equals">2.4.1.3</tested_version>
        <tested_release operator="equals">5.1</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <registry_test id="wrt-274" comment="the patch q815021 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q815021</key>
        <name>Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-234" comment="the version of ntdll.dll is less than 5.0.2195.6685" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\ntdll.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>2195</build>
          <private>6685</private>
        </version>
      </data>
    </file_test>
    <compound_test id="cmp-65" comment="Windows 2000 (sp3 or earlier) is installed" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-1"/>
      <subtest negate="true" test_ref="wrt-28"/>
    </compound_test>
    <rpmversioncompare_test id="rvt-209" comment="evolution version is less than 1.2.2-5" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">evolution</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">1.2.2</tested_version>
        <tested_release datatype="int" operator="equals">5</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <registry_test id="wrt-273" comment="Locator Enabled" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SYSTEM\CurrentControlSet\Services\RPCLocator</key>
        <name>Start</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="not equal">4</value>
      </data>
    </registry_test>
    <registry_test id="wrt-272" comment="Patch Q810833 Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q810833</key>
        <name>Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-233" comment="the version of locator.exe is less than 4.0.1381.7202" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\Locator.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>4</major>
          <minor>0</minor>
          <build>1381</build>
          <private>7202</private>
        </version>
      </data>
    </file_test>
    <patch_test id="spt-224" comment="Patch 111590-02 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">111590</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">2</version>
      </data>
    </patch_test>
    <registry_test id="wrt-271" comment="Gopher Enabled" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows\CurrentVersion\URL\Prefixes</key>
        <name>gopher</name>
      </object>
      <data operation="AND">
        <value operator="equals">gopher://</value>
      </data>
    </registry_test>
    <file_test id="wft-232" comment="File %windir%\system32\mshtml.dll version is less than 6.0.2719.2200" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mshtml.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>2719</build>
          <private>2200</private>
        </version>
      </data>
    </file_test>
    <patch_test id="spt-110" comment="Patch 110896-02 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">110896</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">02</version>
      </data>
    </patch_test>
    <registry_test id="wrt-194" comment="per-session cookies (not stored) are enabled for the current user" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_CURRENT_USER</hive>
        <key operator="pattern match">^SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\[0-4]$</key>
        <name>1A03</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="not equal">3</value>
      </data>
    </registry_test>
    <registry_test id="wrt-193" comment="per-session cookies (not stored) are enabled for the local machine" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="pattern match">^SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\[0-4]$</key>
        <name>1A03</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="not equal">3</value>
      </data>
    </registry_test>
    <compound_test id="cmp-111" comment="local machine settings are being used and cookies are enabled" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-30"/>
      <subtest negate="false" test_ref="wrt-193"/>
      <subtest negate="false" test_ref="wrt-194"/>
    </compound_test>
    <registry_test id="wrt-192" comment="persistent cookies that are stored on your computer are enabled for the current user" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_CURRENT_USER</hive>
        <key operator="pattern match">^SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\[0-4]$</key>
        <name>1A02</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="not equal">3</value>
      </data>
    </registry_test>
    <registry_test id="wrt-270" comment="persistent cookies that are stored on your computer are enabled for the local machine" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="pattern match">^SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\[0-4]$</key>
        <name>1A02</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="not equal">3</value>
      </data>
    </registry_test>
    <registry_test id="wrt-30" comment="use machine settings rather than individual user settings" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings</key>
        <name>Security_HKLM_only</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <compound_test id="cmp-110" comment="current user settings are being used and cookies are enabled" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="true" test_ref="wrt-30"/>
      <subtest negate="false" test_ref="wrt-270"/>
      <subtest negate="false" test_ref="wrt-192"/>
    </compound_test>
    <compound_test id="cmp-250" comment="cookies are enabled" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-110"/>
      <subtest negate="false" test_ref="cmp-111"/>
    </compound_test>
    <file_test id="wft-231" comment="the version of mshtml.dll is less than 6.0.2715.400" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mshtml.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>2715</build>
          <private>400</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-541" comment="WebDav is disabled(for iis 5.0)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key datatype="string" operator="equals">SYSTEM\CurrentControlSet\Services\W3SVC\Parameters</key>
        <name datatype="string" operator="equals">DisableWebDAV</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <registry_test id="wrt-266" comment="Patch Q291845 Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q291845</key>
        <name>Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-230" comment="File %windir%\system32\inetsrv\httpext.dll version is less than 0.9.3940.20" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\inetsrv\httpext.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>0</major>
          <minor>9</minor>
          <build>3940</build>
          <private>20</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-265" comment="Patch Q311967 Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q311967</key>
        <name>Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-229" comment="File %windir%\system32\drivers\mup.sys version is less than 5.0.2195.5080" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\drivers\mup.sys</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>2195</build>
          <private>5080</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-264" comment="the SNMP service is enabled" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SYSTEM\CurrentControlSet\Services\SNMP</key>
        <name>Start</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="not equal">4</value>
      </data>
    </registry_test>
    <registry_test id="wrt-263" comment="Patch Q314147 Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q314147</key>
        <name>Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-228" comment="the version of snmp.exe is less than 4.0.1381.7134" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\snmp.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>4</major>
          <minor>0</minor>
          <build>1381</build>
          <private>7134</private>
        </version>
      </data>
    </file_test>
    <permission_test id="upt-851" comment="File lbxproxy SGID and executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/openwin/bin/lbxproxy</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-850" comment="File lbxproxy SGID and executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/openwin/bin/lbxproxy</component>
        </path>
      </object>
      <data operation="AND">
        <sgid datatype="int" operator="equals">1</sgid>
      </data>
    </permission_test>
    <compound_test id="cmp-247" comment="File lbxproxy SGID and executable" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-850"/>
      <subtest negate="false" test_ref="upt-851"/>
    </compound_test>
    <patch_test id="spt-223" comment="Patch 108652-51 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">108652</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">51</version>
      </data>
    </patch_test>
    <file_test id="uft-19" comment="File lbxproxy exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/openwin/bin/lbxproxy</component>
        </path>
      </object>
    </file_test>
    <file_test id="wft-227" comment="File sqlservr.exe version3 less than 2000.80.428.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
          <component type="literal">\sqlservr.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>2000</major>
          <minor>80</minor>
          <build>428</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-89" comment="File sqlservr.exe version3 greater than or equal to 2000.80.384.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
          <component type="literal">\sqlservr.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="greater than or equal">
          <major>2000</major>
          <minor>80</minor>
          <build>384</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-59" comment="the version of dbmsrpcn.dll is less than 2000.80.213.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\dbmsrpcn.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>2000</major>
          <minor>80</minor>
          <build>213</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-225" comment="the version of ssmsrp70.dll is less than 2000.80.213.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
          <component type="literal">\ssmsrp70.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>2000</major>
          <minor>80</minor>
          <build>213</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <patch_test id="spt-222" comment="Patch 107893-19 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">107893</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">19</version>
      </data>
    </patch_test>
    <patch_test id="spt-221" comment="Patch 112846-01 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">112846</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">1</version>
      </data>
    </patch_test>
    <file_test id="wft-224" comment="File %windir%\system32\inetsrv\ism.dll version is less than 5.0.2195.3407" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\inetsrv\ism.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>2195</build>
          <private>3407</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-262" comment="Patch Q320206 Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q320206</key>
        <name>Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-223" comment="File %windir%\system32\smss.exe version is less than 5.0.2195.5695" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\smss.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>2195</build>
          <private>5695</private>
        </version>
      </data>
    </file_test>
    <patch_test id="spt-220" comment="Patch 106934-04 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">106934</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">4</version>
      </data>
    </patch_test>
    <registry_test id="wrt-261" comment="Mixed Mode Enabled" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\MSSQLServer\MSSQLServer</key>
        <name>LoginMode</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">2</value>
      </data>
    </registry_test>
    <file_test id="wft-222" comment="the version of sqlservr.exe is less than 2000.80.296.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe\Path</component>
          <component type="literal">\sqlservr.exe</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>2000</major>
          <minor>80</minor>
          <build>296</build>
          <private>0</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-260" comment="SQL Server 2000 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\MSSQLServer\MSSQLServer\CurrentVersion</key>
        <name>CurrentVersion</name>
      </object>
      <data operation="AND">
        <value operator="equals">8.00.194</value>
      </data>
    </registry_test>
    <permission_test id="upt-849" comment="File dtspcd executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/dt/bin/dtspcd</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-848" comment="File dtspcd executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/dt/bin/dtspcd</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-847" comment="File dtspcd executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/dt/bin/dtspcd</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-239" comment="File dtspcd executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-847"/>
      <subtest negate="false" test_ref="upt-848"/>
      <subtest negate="false" test_ref="upt-849"/>
    </compound_test>
    <inetd_test id="sit-205" comment="inetd.conf contains dtspcd" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <server_program datatype="string" operator="equals">/usr/dt/bin/dtspcd</server_program>
      </object>
    </inetd_test>
    <patch_test id="spt-219" comment="Patch 108949-07 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">108949</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">7</version>
      </data>
    </patch_test>
    <file_test id="uft-18" comment="File dtspcd exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/dt/bin/dtspcd</component>
        </path>
      </object>
    </file_test>
    <rpmversioncompare_test id="rvt-208" comment="ethereal-gnome version is less than 0.9.13-1.90.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">ethereal-gnome</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">0.9.13</tested_version>
        <tested_release operator="equals">1.90.1</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <rpmversioncompare_test id="rvt-207" comment="ethereal version is less than 0.9.13-1.90.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">ethereal</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">0.9.13</tested_version>
        <tested_release operator="equals">1.90.1</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <compound_test id="cmp-238" comment="Vulnerable Config" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="rvt-207"/>
      <subtest negate="false" test_ref="rvt-208"/>
    </compound_test>
    <patch_test id="spt-218" comment="Patch 108721-02 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">108721</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">2</version>
      </data>
    </patch_test>
    <patch_test id="spt-217" comment="Patch 110453-01 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">110453</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">1</version>
      </data>
    </patch_test>
    <file_test id="wft-221" comment="File %windir%\system32\inetsrv\asp.dll version is less than 5.0.2195.6672" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\inetsrv\asp.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>2195</build>
          <private>6672</private>
        </version>
      </data>
    </file_test>
    <patch_test id="spt-216" comment="Patch 107337-02 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">107337</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">2</version>
      </data>
    </patch_test>
    <registry_test id="wrt-259" comment="Windows 2000 Security Roll-up 1 Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\SP2SRP1</key>
        <name>Installed</name>
      </object>
      <data operation="AND">
        <value datatype="binary" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-220" comment="File %windir%\system32\netlogon.dll version is less than 5.0.893.1105" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\netlogon.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>893</build>
          <private>1105</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-219" comment="File %windir%\system32\rasman.dll version is less than 5.0.2195.4983" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\rasman.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>2195</build>
          <private>4983</private>
        </version>
      </data>
    </file_test>
    <process_test id="uct-8" comment="mibiisa running" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <command datatype="string" operator="pattern match">^.*mibiisa.*</command>
      </object>
    </process_test>
    <patch_test id="spt-215" comment="Patch 107709-19 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">107709</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">19</version>
      </data>
    </patch_test>
    <file_test id="uft-17" comment="File mibiisa exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/lib/snmp/mibiisa</component>
        </path>
      </object>
    </file_test>
    <registry_test id="wrt-258" comment="RAS Enabled" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SYSTEM\CurrentControlSet\Services\RasMan</key>
        <name>Start</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="not equal">4</value>
      </data>
    </registry_test>
    <registry_test id="wrt-257" comment="Patch Q318138 Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q318138</key>
        <name>Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-218" comment="File %windir%\system32\rasapi32.dll version is less than 4.0.1381.7140" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\rasman.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>4</major>
          <minor>0</minor>
          <build>1381</build>
          <private>7140</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-256" comment="RAS Phonebook" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Ras\CurrentVersion</key>
        <name>PathName</name>
      </object>
      <data operation="AND">
        <value operator="equals">RASPHONE.PBK</value>
      </data>
    </registry_test>
    <registry_test id="wrt-254" comment="Patch Windows2000-KB823980-x86-ENU.exe Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB823980</key>
        <name>Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <registry_test id="wrt-253" comment="Patch Q331953_W2K_SP4_X86_EN.exe Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\Q331953</key>
        <name>Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-217" comment="File %windir%\system32\rpcrt4.dll version is less than 5.0.2195.6106" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\rpcrt4.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>2195</build>
          <private>6106</private>
        </version>
      </data>
    </file_test>
    <file_test id="wft-216" comment="the version of mshtml.dll is less than 6.0.2723.2500" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mshtml.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>2723</build>
          <private>2500</private>
        </version>
      </data>
    </file_test>
    <process_test id="uct-7" comment="rpc.yppasswdd running" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <command datatype="string" operator="pattern match">^.*rpc\.yppasswdd.*</command>
      </object>
    </process_test>
    <patch_test id="spt-214" comment="Patch 111596-02 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">111596</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">2</version>
      </data>
    </patch_test>
    <file_test id="uft-16" comment="File rpc.yppasswdd exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/lib/netsvc/rpc.yppasswdd</component>
        </path>
      </object>
    </file_test>
    <rpmversioncompare_test id="rvt-206" comment="ethereal version is less than 0.9.11-0.90.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">ethereal</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">0.9.11</tested_version>
        <tested_release operator="equals">0.90.1</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <permission_test id="upt-68" comment="eog is owner-executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/eog</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <permission_test id="upt-67" comment="eog is group-executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/eog</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-66" comment="eog is world-executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/eog</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <compound_test id="cmp-232" comment="eog is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-66"/>
      <subtest negate="false" test_ref="upt-67"/>
      <subtest negate="false" test_ref="upt-68"/>
    </compound_test>
    <rpmversioncompare_test id="rvt-205" comment="eog version is less than 2.2.0-2" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">eog</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">2.2.0</tested_version>
        <tested_release datatype="int" operator="equals">2</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <file_test id="wft-215" comment="the version of mshtml.dll is less than 5.0.3502.4856" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mshtml.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>3502</build>
          <private>4856</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-252" comment="the patch q813489 is installed (Installed Components key)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Active Setup\Installed Components\{F9C174E3-3E87-40bc-AA94-B8974F2B9222}</key>
        <name>Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-214" comment="File %windir%\system32\mshtml.dll version is less than 5.0.3513.900" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mshtml.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>3513</build>
          <private>900</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-55" comment="Internet Explorer 5.01 Service Pack 3 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Internet Explorer</key>
        <name>Version</name>
      </object>
      <data operation="AND">
        <value operator="equals">5.00.3502.1000</value>
      </data>
    </registry_test>
    <compound_test id="cmp-230" comment="Internet Explorer 5.01 Installed" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-230"/>
      <subtest negate="false" test_ref="wrt-231"/>
      <subtest negate="false" test_ref="wrt-232"/>
      <subtest negate="false" test_ref="wrt-233"/>
      <subtest negate="false" test_ref="wrt-234"/>
      <subtest negate="false" test_ref="wrt-235"/>
      <subtest negate="false" test_ref="wrt-236"/>
      <subtest negate="false" test_ref="wrt-56"/>
      <subtest negate="false" test_ref="wrt-55"/>
    </compound_test>
    <permission_test id="upt-846" comment="File admintool SUID and executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">^.*/bin/admintool</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-845" comment="File admintool SUID and executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">^.*/bin/admintool</component>
        </path>
      </object>
      <data operation="AND">
        <suid datatype="int" operator="equals">1</suid>
      </data>
    </permission_test>
    <compound_test id="cmp-229" comment="File admintool SUID and executable" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-845"/>
      <subtest negate="false" test_ref="upt-846"/>
    </compound_test>
    <file_test id="uft-15" comment="File admintool exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="pattern match">
          <component type="literal">^.*/bin/admintool$</component>
        </path>
      </object>
    </file_test>
    <patch_test id="spt-213" comment="Patch 111826-01 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">111826</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">1</version>
      </data>
    </patch_test>
    <registry_test id="wrt-250" comment="Win2K/XP/2003 service pack 2 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion</key>
        <name>CSDVersion</name>
      </object>
      <data operation="AND">
        <value operator="equals">Service Pack 2</value>
      </data>
    </registry_test>
    <registry_test id="wrt-249" comment="Patch Q293826 Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q293826</key>
        <name>Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <registry_test id="wrt-248" comment="Patch Q277873 Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q277873</key>
        <name>Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <registry_test id="wrt-247" comment="Patch Q269862 Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q269862</key>
        <name>Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-213" comment="File %windir%\system32\inetsrv\w3svc.dll version is less than 5.0.2195.2103" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\inetsrv\w3svc.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>2195</build>
          <private>2103</private>
        </version>
      </data>
    </file_test>
    <patch_test id="spt-109" comment="Patch 108800-02 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">108800</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">02</version>
      </data>
    </patch_test>
    <patch_test id="spt-212" comment="Patch 108541-06 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">108541</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">6</version>
      </data>
    </patch_test>
    <patch_test id="spt-211" comment="Patch 106942-22 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">106942</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">22</version>
      </data>
    </patch_test>
    <compound_test id="cmp-223" comment="Patches 106942-22 and 108451-06" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="spt-211"/>
      <subtest negate="false" test_ref="spt-212"/>
    </compound_test>
    <permission_test id="upt-844" comment="File rpc.rwalld executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/lib/netsvc/rwall/rpc.rwalld</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-843" comment="File rpc.rwalld executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/lib/netsvc/rwall/rpc.rwalld</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-842" comment="File rpc.rwalld executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/lib/netsvc/rwall/rpc.rwalld</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-221" comment="File rpc.rwalld executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-842"/>
      <subtest negate="false" test_ref="upt-843"/>
      <subtest negate="false" test_ref="upt-844"/>
    </compound_test>
    <inetd_test id="sit-204" comment="inetd.conf contains rpc.rwalld" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <server_program datatype="string" operator="equals">/usr/lib/netsvc/rwall/rpc.rwalld</server_program>
      </object>
    </inetd_test>
    <patch_test id="spt-210" comment="Patch 112899-01 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">112899</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">1</version>
      </data>
    </patch_test>
    <file_test id="uft-14" comment="File rpc.rwalld exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/lib/netsvc/rwall/rpc.rwalld</component>
        </path>
      </object>
    </file_test>
    <registry_test id="wrt-246" comment="Patch Q318593 Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q318593</key>
        <name>Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-212" comment="the version of srvsvc.dll is less than 5.0.2195.4980" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\srvsvc.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>2195</build>
          <private>4980</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-42" comment="this is an NT Server (domain controller)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SYSTEM\CurrentControlSet\Control\Product\Options</key>
        <name>ProductType</name>
      </object>
      <data operation="AND">
        <value operator="pattern match">^.*LanmanNT.*$</value>
      </data>
    </registry_test>
    <compound_test id="cmp-220" comment="Windows 2000 (domain controller) is installed" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-1"/>
      <subtest negate="false" test_ref="wrt-42"/>
    </compound_test>
    <registry_test id="wrt-243" comment="Windows NT 4.0 Security Roll-up Package" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q299444</key>
        <name>Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <registry_test id="wrt-242" comment="Patch Q301625 Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q301625</key>
        <name>Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <registry_test id="wrt-241" comment="Patch Q295534 Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q295534</key>
        <name>Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-211" comment="File %windir%\system32\inetsrv\ism.dll version is less than 4.2.764.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\inetsrv\ism.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>4</major>
          <minor>2</minor>
          <build>764</build>
          <private>1</private>
        </version>
      </data>
    </file_test>
    <permission_test id="upt-841" comment="File whodo SUID and executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">^/usr/sbin/sparcv./whodo</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-840" comment="File whodo SUID and executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">^/usr/sbin/sparcv./whodo</component>
        </path>
      </object>
      <data operation="AND">
        <suid datatype="int" operator="equals">1</suid>
      </data>
    </permission_test>
    <compound_test id="cmp-219" comment="File whodo SUID and executable" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-840"/>
      <subtest negate="false" test_ref="upt-841"/>
    </compound_test>
    <patch_test id="spt-209" comment="Patch 111600-01 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">111600</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">1</version>
      </data>
    </patch_test>
    <file_test id="uft-13" comment="File whodo exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="pattern match">
          <component type="literal">^/usr/sbin/sparcv./whodo$</component>
        </path>
      </object>
    </file_test>
    <patch_test id="spt-208" comment="Patch 108376-38 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">108376</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">38</version>
      </data>
    </patch_test>
    <uname_test id="uut-5" comment="Solaris 7 Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <data operation="AND">
        <os_name operator="equals">SunOS</os_name>
        <os_release operator="equals">5.7</os_release>
      </data>
    </uname_test>
    <permission_test id="upt-839" comment="File cachefsd executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component">
          <component type="literal">/usr/lib/fs/cachefs/cachefsd</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-838" comment="File cachefsd executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component">
          <component type="literal">/usr/lib/fs/cachefs/cachefsd</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-837" comment="File cachefsd executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component">
          <component type="literal">/usr/lib/fs/cachefs/cachefsd</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-217" comment="File cachefsd executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-837"/>
      <subtest negate="false" test_ref="upt-838"/>
      <subtest negate="false" test_ref="upt-839"/>
    </compound_test>
    <inetd_test id="sit-203" comment="inetd.conf contains cachefsd" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <server_program operator="equals">/usr/lib/fs/cachefs/cachefsd</server_program>
      </object>
    </inetd_test>
    <patch_test id="spt-111" comment="Patch 114008-01 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">114008</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">01</version>
      </data>
    </patch_test>
    <uname_test id="uut-6" comment="Solaris 9 Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <data operation="AND">
        <os_name operator="equals">SunOS</os_name>
        <os_release operator="equals">5.9</os_release>
      </data>
    </uname_test>
    <compound_test id="cmp-1081" comment="Solaris 8 or 9 installed" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="uut-4"/>
      <subtest negate="false" test_ref="uut-6"/>
    </compound_test>
    <patch_test id="spt-207" comment="Patch 110896-02 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">110896</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">2</version>
      </data>
    </patch_test>
    <file_test id="uft-12" comment="File cachefsd exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component">
          <component type="literal">/usr/lib/fs/cachefs/cachefsd</component>
        </path>
      </object>
    </file_test>
    <registry_test id="wrt-240" comment="SMTP Enabled" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key datatype="string" operator="equals">SYSTEM\CurrentControlSet\Services\SMTPSVC</key>
        <name datatype="string" operator="equals">Start</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="not equal">4</value>
      </data>
    </registry_test>
    <registry_test id="wrt-239" comment="Patch Q313450" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q313450</key>
        <name>Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-210" comment="File %windir%\system32\inetsrv\smtpsvc.dll version is less than 5.0.2195.4905" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\inetsrv\smtpsvc.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>2195</build>
          <private>4905</private>
        </version>
      </data>
    </file_test>
    <metabase_test id="wmt-203" comment="ism.dll mapping exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <key datatype="string" operator="equals">LM\W3SVC</key>
        <id datatype="int" operator="equals">6014</id>
      </object>
      <data operation="AND">
        <data operator="pattern match">^.*ism\.dll.*$</data>
      </data>
    </metabase_test>
    <registry_test id="wrt-238" comment="Patch Q321599 Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Updates\Windows 2000\SP4\Q321599</key>
        <name>Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-209" comment="File %windir%\system32\inetsrv\ism.dll version is less than 5.0.2195.5671" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\inetsrv\ism.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>2195</build>
          <private>5671</private>
        </version>
      </data>
    </file_test>
    <rpmversioncompare_test id="rvt-204" comment="ddskk-xemacs version is less than 11.6.0-11.90" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">ddskk-xemacs</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">11.6.0</tested_version>
        <tested_release operator="equals">11.90</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <rpmversioncompare_test id="rvt-203" comment="ddskk version is less than 11.6.0-11.90" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">ddskk</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">11.6.0</tested_version>
        <tested_release operator="equals">11.90</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <compound_test id="cmp-216" comment="Vulnerable config" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="rvt-203"/>
      <subtest negate="false" test_ref="rvt-204"/>
    </compound_test>
    <compound_test id="cmp-215" comment="Windows 2000 Service Pack 4 (or later) is installed" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-1"/>
      <subtest negate="false" test_ref="wrt-222"/>
    </compound_test>
    <file_test id="wft-208" comment="the version of mshtml.dll is less than 5.0.3504.2500" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mshtml.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>3504</build>
          <private>2500</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-56" comment="Internet Explorer 5.01 Service Pack 2 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Internet Explorer</key>
        <name>Version</name>
      </object>
      <data operation="AND">
        <value operator="equals">5.00.3315.1000</value>
      </data>
    </registry_test>
    <registry_test id="wrt-236" comment="Internet Explorer 5.01 Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Internet Explorer</key>
        <name>Version</name>
      </object>
      <data operation="AND">
        <value operator="equals">5.00.3314.2101</value>
      </data>
    </registry_test>
    <registry_test id="wrt-235" comment="Internet Explorer 5.01 Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Internet Explorer</key>
        <name>Version</name>
      </object>
      <data operation="AND">
        <value operator="equals">5.00.3105.0106</value>
      </data>
    </registry_test>
    <registry_test id="wrt-234" comment="Internet Explorer 5.01 Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Internet Explorer</key>
        <name>Version</name>
      </object>
      <data operation="AND">
        <value operator="equals">5.00.3103.1000</value>
      </data>
    </registry_test>
    <registry_test id="wrt-233" comment="Internet Explorer 5.01 Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Internet Explorer</key>
        <name>Version</name>
      </object>
      <data operation="AND">
        <value operator="equals">5.00.2920.0000</value>
      </data>
    </registry_test>
    <registry_test id="wrt-232" comment="Internet Explorer 5.01 Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Internet Explorer</key>
        <name>Version</name>
      </object>
      <data operation="AND">
        <value operator="equals">5.00.2919.6307</value>
      </data>
    </registry_test>
    <registry_test id="wrt-231" comment="Internet Explorer 5.01 Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Internet Explorer</key>
        <name>Version</name>
      </object>
      <data operation="AND">
        <value operator="equals">5.00.2919.3800</value>
      </data>
    </registry_test>
    <registry_test id="wrt-230" comment="Internet Explorer 5.01 Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Internet Explorer</key>
        <name>Version</name>
      </object>
      <data operation="AND">
        <value operator="equals">5.00.2919.800</value>
      </data>
    </registry_test>
    <compound_test id="cmp-214" comment="Internet Explorer 5.01 Installed" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-230"/>
      <subtest negate="false" test_ref="wrt-231"/>
      <subtest negate="false" test_ref="wrt-232"/>
      <subtest negate="false" test_ref="wrt-233"/>
      <subtest negate="false" test_ref="wrt-234"/>
      <subtest negate="false" test_ref="wrt-235"/>
      <subtest negate="false" test_ref="wrt-236"/>
      <subtest negate="false" test_ref="wrt-56"/>
    </compound_test>
    <registry_test id="wrt-229" comment="Patch Q326886 Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q326886</key>
        <name>Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-207" comment="the version of netman.dll is less than 5.0.2195.5974" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\netman.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>2195</build>
          <private>5974</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-222" comment="SP4 or later Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key operator="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion</key>
        <name operator="equals">CSDVersion</name>
      </object>
      <data operation="AND">
        <value operator="pattern match">^Service Pack [4-9]|\d{2,}$</value>
      </data>
    </registry_test>
    <metabase_test id="wmt-202" comment="FTP Enabled" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <key datatype="string" operator="pattern match">^LM\\MSFTPSVC\\.*$</key>
        <id datatype="int" operator="equals">1016</id>
      </object>
      <data operation="AND">
        <data datatype="int" operator="not equal">4</data>
      </data>
    </metabase_test>
    <file_test id="wft-206" comment="the version of mshtml.dll is less than 5.50.4725.2100" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mshtml.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>50</minor>
          <build>4725</build>
          <private>2100</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-227" comment="Internet Explorer 5.5 Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Internet Explorer</key>
        <name>Version</name>
      </object>
      <data operation="AND">
        <value operator="equals">5.50.4522.1800</value>
      </data>
    </registry_test>
    <registry_test id="wrt-226" comment="Internet Explorer 5.5 Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Internet Explorer</key>
        <name>Version</name>
      </object>
      <data operation="AND">
        <value operator="equals">5.50.4134.0600</value>
      </data>
    </registry_test>
    <registry_test id="wrt-225" comment="Internet Explorer 5.5 Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Internet Explorer</key>
        <name>Version</name>
      </object>
      <data operation="AND">
        <value operator="equals">5.50.4134.0100</value>
      </data>
    </registry_test>
    <compound_test id="cmp-213" comment="Internet Explorer 5.5 Installed" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-225"/>
      <subtest negate="false" test_ref="wrt-226"/>
      <subtest negate="false" test_ref="wrt-227"/>
    </compound_test>
    <registry_test id="wrt-224" comment="Win2K/XP/2003 service pack 3 (or later) is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion</key>
        <name>CSDVersion</name>
      </object>
      <data operation="AND">
        <value operator="pattern match">^Service Pack [3-9]|\d{2,}$</value>
      </data>
    </registry_test>
    <file_test id="wft-205" comment="the version of w3svc.dll is less than 5.0.2195.5269" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\inetsrv\w3svc.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>2195</build>
          <private>5269</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-223" comment="IIS major version equals 5" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\INetStp</key>
        <name>MajorVersion</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">5</value>
      </data>
    </registry_test>
    <registry_test id="wrt-281" comment="the patch kb824146 is installed (Hotfix key)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB824146</key>
        <name>Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-568" comment="the version of rpcss.dll is less than 5.0.2195.6810" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\rpcss.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>0</minor>
          <build>2195</build>
          <private>6810</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-28" comment="Win2K/XP/2003 service pack 4 (or later) is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion</key>
        <name>CSDVersion</name>
      </object>
      <data operation="AND">
        <value operator="pattern match">^Service Pack [4-9]|\d{2,}$</value>
      </data>
    </registry_test>
    <registry_test id="wrt-1" comment="Windows 2000 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion</key>
        <name>CurrentVersion</name>
      </object>
      <data operation="AND">
        <value operator="equals">5.0</value>
      </data>
    </registry_test>
    <compound_test id="cmp-212" comment="Windows 2000 Service Pack 4 (or later) is installed" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="wrt-1"/>
      <subtest negate="false" test_ref="wrt-28"/>
    </compound_test>
    <file_test id="wft-204" comment="the version of mshtml.dll is less than 6.0.2716.2200" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mshtml.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>2716</build>
          <private>2200</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-288" comment="Patch Q313829 Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q313829</key>
        <name>Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-490" comment="the version of shell32.dll is less than 4.0.1381.7116" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\shell32.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>4</major>
          <minor>0</minor>
          <build>1381</build>
          <private>7116</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-77" comment="Windows NT 4.0 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion</key>
        <name>CurrentVersion</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">4.0</value>
      </data>
    </registry_test>
    <registry_test id="wrt-18" comment="Internet Explorer 6 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key datatype="string" operator="equals">SOFTWARE\Microsoft\Internet Explorer</key>
        <name datatype="string" operator="equals">Version</name>
      </object>
      <data operation="AND">
        <value datatype="string" operator="pattern match">^6\.0+\.2600\.0+$</value>
      </data>
    </registry_test>
    <file_test id="wft-203" comment="the version of mshtml.dll is less than 6.0.2713.1100" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mshtml.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>6</major>
          <minor>0</minor>
          <build>2713</build>
          <private>1100</private>
        </version>
      </data>
    </file_test>
    <metabase_test id="wmt-201" comment="asp.dll mapping exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <key datatype="string" operator="equals">LM\W3SVC</key>
        <id datatype="int" operator="equals">6014</id>
      </object>
      <data operation="AND">
        <data operator="pattern match">^.*asp\.dll.*$</data>
      </data>
    </metabase_test>
    <registry_test id="wrt-219" comment="Patch Q811114 Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q811114</key>
        <name>Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <registry_test id="wrt-218" comment="Patch Q327696 Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q327696</key>
        <name>Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <registry_test id="wrt-217" comment="Patch Q319733 Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q319733</key>
        <name>Installed</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-202" comment="the version of w3svc.dll is less than 4.2.775.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\inetsrv\w3svc.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>4</major>
          <minor>2</minor>
          <build>775</build>
          <private>1</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-43" comment="this is an NT Terminal Server" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SYSTEM\CurrentControlSet\Control\ProductOptions</key>
        <name>ProductSuite</name>
      </object>
      <data operation="AND">
        <value operator="equals">Terminal Server</value>
      </data>
    </registry_test>
    <registry_test id="wrt-215" comment="IIS minor version equals 0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\INetStp</key>
        <name>MinorVersion</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">0</value>
      </data>
    </registry_test>
    <registry_test id="wrt-214" comment="IIS 4.0 Major Version" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\INetStp</key>
        <name>MajorVersion</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">4</value>
      </data>
    </registry_test>
    <permission_test id="upt-836" comment="File rpc.ttdbserverd executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/dt/bin/rpc.ttdbserverd</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-835" comment="File rpc.ttdbserverd executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/dt/bin/rpc.ttdbserverd</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-834" comment="File rpc.ttdbserverd executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/dt/bin/rpc.ttdbserverd</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-211" comment="File rpc.ttdbserverd executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-834"/>
      <subtest negate="false" test_ref="upt-835"/>
      <subtest negate="false" test_ref="upt-836"/>
    </compound_test>
    <inetd_test id="sit-202" comment="inetd.conf contains rpc.ttdbserverd" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <server_program operator="equals">/usr/dt/bin/rpc.ttdbserverd</server_program>
      </object>
    </inetd_test>
    <patch_test id="spt-206" comment="Patch 110286-09 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">110286</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">9</version>
      </data>
    </patch_test>
    <file_test id="uft-11" comment="File rpc.ttdbserverd exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/dt/bin/rpc.ttdbserverd</component>
        </path>
      </object>
    </file_test>
    <permission_test id="upt-833" comment="File Xsun SGID and executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/openwin/bin/Xsun</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-832" comment="File Xsun SGID and executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/openwin/bin/Xsun</component>
        </path>
      </object>
      <data operation="AND">
        <sgid datatype="int" operator="equals">1</sgid>
      </data>
    </permission_test>
    <compound_test id="cmp-210" comment="File Xsun SGID and executable" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-832"/>
      <subtest negate="false" test_ref="upt-833"/>
    </compound_test>
    <patch_test id="spt-205" comment="Patch 108652-52 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">108652</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">52</version>
      </data>
    </patch_test>
    <file_test id="uft-10" comment="File Xsun exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/openwin/bin/Xsun</component>
        </path>
      </object>
    </file_test>
    <registry_test id="wrt-19" comment="the patch q824145 is installed (Installed Components key)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Active Setup\Installed Components\{057997dd-71e4-43cc-b161-3f8180691a9e}</key>
        <name>IsInstalled</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <registry_test id="wrt-212" comment="the patch q828750 is installed (Installed Components key)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Active Setup\Installed Components\{96543d59-497a-4801-a1f3-5936aacaf7b1}</key>
        <name>IsInstalled</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <registry_test id="wrt-211" comment="the patch q822925 is installed (Installed Components key)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Active Setup\Installed Components\{377483c2-e4b4-4ee8-b577-9aed264c8735}</key>
        <name>IsInstalled</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <registry_test id="wrt-210" comment="the patch q818529 is installed (Installed Components key)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Active Setup\Installed Components\{f5de1b93-9d38-416b-b09e-aa85a8e84309}</key>
        <name>IsInstalled</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <registry_test id="wrt-209" comment="the patch q813489 is installed (Installed Components key)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Active Setup\Installed Components\{F9C174E3-3E87-40bc-AA94-B8974F2B9222}</key>
        <name>IsInstalled</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <registry_test id="wrt-208" comment="the patch q810847 is installed (Installed Components key)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Active Setup\Installed Components\{C34F4917-ED43-439f-9023-97B0024A2B3B}</key>
        <name>IsInstalled</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <registry_test id="wrt-207" comment="the patch q324929 is installed (Installed Components key)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Active Setup\Installed Components\{2757B1D6-0367-4663-877C-93ECC5C01BF6}</key>
        <name>IsInstalled</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <registry_test id="wrt-206" comment="the patch q328970 is installed (Installed Components key)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Active Setup\Installed Components\{FF4DD9CD-F25E-425a-8B5C-A2D062781FBB}</key>
        <name>IsInstalled</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <registry_test id="wrt-205" comment="the patch q323759 is installed (Installed Components key)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Active Setup\Installed Components\{61E6EAE5-7821-4AC1-9BBD-AED032A8E273}</key>
        <name>IsInstalled</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <registry_test id="wrt-204" comment="the patch q321232 is installed (Installed Components key)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Active Setup\Installed Components\{D7B44F3E-77D3-44C5-8E03-4222D9A18B7B}</key>
        <name>IsInstalled</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <registry_test id="wrt-203" comment="the patch q319282 is installed (Installed Components key)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Active Setup\Installed Components\{2D5974C5-5185-4f5b-80B6-28015ACDD74C}</key>
        <name>IsInstalled</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <registry_test id="wrt-202" comment="the patch q316059 is installed (Installed Components key)" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive datatype="string" operator="equals">HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Active Setup\Installed Components\{E81659DF-28E1-4C60-B4B9-00A4BC5FA76D}</key>
        <name>IsInstalled</name>
      </object>
      <data operation="AND">
        <value datatype="int" operator="equals">1</value>
      </data>
    </registry_test>
    <file_test id="wft-201" comment="the version of mshtml.dll is less than 5.50.4913.1100" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <path datatype="component" operator="equals">
          <component type="registry_value">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot</component>
          <component type="literal">\system32\mshtml.dll</component>
        </path>
      </object>
      <data operation="AND">
        <version datatype="version" operator="less than">
          <major>5</major>
          <minor>50</minor>
          <build>4913</build>
          <private>1100</private>
        </version>
      </data>
    </file_test>
    <registry_test id="wrt-53" comment="Internet Explorer 5.5 Service Pack 2 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Internet Explorer</key>
        <name>Version</name>
      </object>
      <data operation="AND">
        <value operator="equals">5.50.4807.2300</value>
      </data>
    </registry_test>
    <process_test id="uct-6" comment="snmpdx running" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <command operator="pattern match">^.*snmpdx.*</command>
      </object>
    </process_test>
    <patch_test id="spt-204" comment="Patch 108869-16 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">108869</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">16</version>
      </data>
    </patch_test>
    <file_test id="uft-9" comment="File snmpdx exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/lib/snmp/snmpdx</component>
        </path>
      </object>
    </file_test>
    <permission_test id="upt-831" comment="File xlock SUID and executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/openwin/bin/xlock</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-830" comment="File xlock SUID and executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/openwin/bin/xlock</component>
        </path>
      </object>
      <data operation="AND">
        <suid datatype="int" operator="equals">1</suid>
      </data>
    </permission_test>
    <compound_test id="cmp-209" comment="File xlock SUID and executable" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-830"/>
      <subtest negate="false" test_ref="upt-831"/>
    </compound_test>
    <patch_test id="spt-203" comment="Patch 108652-38 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">108652</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">38</version>
      </data>
    </patch_test>
    <file_test id="uft-8" comment="File xlock exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/openwin/bin/xlock</component>
        </path>
      </object>
    </file_test>
    <process_test id="uct-5" comment="dmispd running" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <command datatype="string" operator="pattern match">^.*dmispd.*</command>
      </object>
    </process_test>
    <permission_test id="upt-829" comment="File rpc.cmsd executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/dt/bin/rpc.cmsd</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-828" comment="File rpc.cmsd executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/dt/bin/rpc.cmsd</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-827" comment="File rpc.cmsd executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/dt/bin/rpc.cmsd</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-208" comment="File rpc.cmsd executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-827"/>
      <subtest negate="false" test_ref="upt-828"/>
      <subtest negate="false" test_ref="upt-829"/>
    </compound_test>
    <process_test id="uct-4" comment="inetd running" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <command operator="pattern match">^.*inetd.*</command>
      </object>
      <data operation="AND">
        <user_id operator="equals">root</user_id>
      </data>
    </process_test>
    <inetd_test id="sit-201" comment="inetd.conf contains rpc.cmsd" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <server_program datatype="string" operator="equals">/usr/dt/bin/rpc.cmsd</server_program>
      </object>
    </inetd_test>
    <compound_test id="cmp-207" comment="rpc.cmsd enabled" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="sit-201"/>
      <subtest negate="false" test_ref="uct-4"/>
      <subtest negate="false" test_ref="cmp-208"/>
    </compound_test>
    <compound_test id="cmp-206" comment="rpc.cmsd enabled OR dmispd running" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="cmp-207"/>
      <subtest negate="false" test_ref="uct-5"/>
    </compound_test>
    <patch_test id="spt-202" comment="Patch 108901-06 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">108901</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">6</version>
      </data>
    </patch_test>
    <patch_test id="spt-201" comment="Patch 108827-30 or later installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#solaris">
      <object>
        <base datatype="int" operator="equals">108827</base>
      </object>
      <data operation="AND">
        <version datatype="int" operator="greater than or equal">30</version>
      </data>
    </patch_test>
    <compound_test id="cmp-205" comment="Patches 108827-30 and 108901-06" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="spt-201"/>
      <subtest negate="false" test_ref="spt-202"/>
    </compound_test>
    <file_test id="uft-7" comment="File dmispd exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/lib/dmi/dmispd</component>
        </path>
      </object>
    </file_test>
    <file_test id="uft-6" comment="File rpc.cmsd exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/dt/bin/rpc.cmsd</component>
        </path>
      </object>
    </file_test>
    <compound_test id="cmp-204" comment="rpc.cmsd or dmispd exist" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="uft-6"/>
      <subtest negate="false" test_ref="uft-7"/>
    </compound_test>
    <permission_test id="upt-826" comment="File kcms_configure executable and SUID or SGID" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/openwin/bin/kcms_configure</component>
        </path>
      </object>
      <data operation="AND">
        <sgid datatype="int" operator="equals">1</sgid>
      </data>
    </permission_test>
    <permission_test id="upt-825" comment="File kcms_configure executable and SUID or SGID" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/openwin/bin/kcms_configure</component>
        </path>
      </object>
      <data operation="AND">
        <suid datatype="int" operator="equals">1</suid>
      </data>
    </permission_test>
    <compound_test id="cmp-203" comment="File kcms_configure executable and SUID or SGID" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-825"/>
      <subtest negate="false" test_ref="upt-826"/>
    </compound_test>
    <permission_test id="upt-824" comment="File kcms_configure executable and SUID or SGID" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/openwin/bin/kcms_configure</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <compound_test id="cmp-202" comment="File kcms_configure executable and SUID or SGID" operation="AND" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-824"/>
      <subtest negate="false" test_ref="cmp-203"/>
    </compound_test>
    <file_test id="uft-5" comment="File kcms_configure exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/openwin/bin/kcms_configure</component>
        </path>
      </object>
    </file_test>
    <uname_test id="uut-4" comment="Solaris 8 Installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <data operation="AND">
        <os_name operator="equals">SunOS</os_name>
        <os_release operator="equals">5.8</os_release>
      </data>
    </uname_test>
    <inetlisteningservers_test id="rlt-201" comment="cupsd listens on the network" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <program_name datatype="string" operator="pattern match">^.*cupsd.*</program_name>
      </object>
    </inetlisteningservers_test>
    <rpmversioncompare_test id="rvt-202" comment="cups version is less than 1.1.17-13.3" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">cups</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">1.1.17</tested_version>
        <tested_release operator="equals">13.3</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <activedirectory_test id="wat-1" comment="The exadmin HTTP virtual directory only allows Integrated Windows Authentication" check="none exist" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <naming_context operator="equals">configuration</naming_context>
        <relative_dn operator="pattern match">^CN=Exadmin,CN=[^,]+,CN=HTTP,CN=Protocols,CN=[^,]+,CN=Servers,CN=[^,]+,CN=Administrative Groups,CN=[^,]+,CN=Microsoft Exchange,CN=Services</relative_dn>
        <attribute operator="equals">msExchAuthenticationFlags</attribute>
      </object>
      <data operation="AND">
        <value operator="not equal">4</value>
      </data>
    </activedirectory_test>
    <registry_test id="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval#windows">
      <object>
        <hive>HKEY_LOCAL_MACHINE</hive>
        <key>SOFTWARE\Microsoft\Exchange\Setup</key>
        <name>Services Version</name>
      </object>
      <data>
        <value operator="equals">65</value>
      </data>
    </registry_test>
    <permission_test id="upt-65" comment="/usr/bin/balsa is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/balsa</component>
        </path>
      </object>
      <data operation="AND">
        <oexec datatype="int" operator="equals">1</oexec>
      </data>
    </permission_test>
    <permission_test id="upt-64" comment="/usr/bin/balsa is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/balsa</component>
        </path>
      </object>
      <data operation="AND">
        <gexec datatype="int" operator="equals">1</gexec>
      </data>
    </permission_test>
    <permission_test id="upt-63" comment="/usr/bin/balsa is executable" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <object>
        <path datatype="component" operator="equals">
          <component type="literal">/usr/bin/balsa</component>
        </path>
      </object>
      <data operation="AND">
        <uexec datatype="int" operator="equals">1</uexec>
      </data>
    </permission_test>
    <compound_test id="cmp-201" comment="/usr/bin/balsa is executable" operation="OR" xmlns="http://oval.mitre.org/XMLSchema/oval#independent">
      <subtest negate="false" test_ref="upt-63"/>
      <subtest negate="false" test_ref="upt-64"/>
      <subtest negate="false" test_ref="upt-65"/>
    </compound_test>
    <rpmversioncompare_test id="rvt-201" comment="balsa version is less than 2.0.6-2" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">balsa</name>
        <tested_epoch operator="equals">0</tested_epoch>
        <tested_version operator="equals">2.0.6</tested_version>
        <tested_release datatype="int" operator="equals">2</tested_release>
      </object>
      <data operation="AND">
        <installed_version operator="equals">earlier</installed_version>
      </data>
    </rpmversioncompare_test>
    <uname_test id="uut-1" comment="ix86 architecture" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#unix">
      <data operation="AND">
        <machine_class datatype="string" operator="pattern match">^i.*86</machine_class>
      </data>
    </uname_test>
    <rpminfo_test id="rrt-201" comment="Red Hat 9 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval#redhat">
      <object>
        <name datatype="string" operator="equals">redhat-release</name>
      </object>
      <data operation="AND">
        <version datatype="int" operator="equals">9</version>
      </data>
    </rpminfo_test>
  </tests>
</oval>